TPM-Based Geographic Location Attestation for Cloud Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing raises security concerns regarding data and computation resource location, as users have limited means to ensure confidentiality, integrity, and compliance with geographical location requirements, particularly in cloud environments where data and resource location are often unknown.

Innovation Solution

Systems and methods utilize Hardware Security Modules like Trusted Platform Modules (TPMs) to securely store and attest the physical geographic location of cloud infrastructure elements, integrating GPS and time information to determine and verify the trusted location of physical and virtual assets, ensuring accurate geographic location provisioning and compliance with geo-fencing policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud computing services are provided without geographic location tracking, then service flexibility and ease of operation are improved, but security and compliance with geographical location requirements deteriorate

Engineering Contradiction:
Improveservice flexibilityVSAvoidsecurity and compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces Hardware Security Modules (HSMs) and Trusted Platform Modules (TPMs) as intermediary components between the cloud infrastructure and the geographic location verification system. These modules securely store cryptographic keys and attest the geographic location of physical infrastructure elements without requiring changes to the core cloud service operations, thus maintaining service flexibility while enabling security and compliance verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary geographic location attestation by provisioning HSMs/TPMs with geographic location information before cloud services are deployed. This advance verification ensures that infrastructure elements are located in compliant jurisdictions before any data or computation resources are allocated, preventing compliance violations rather than detecting them afterward

Inventive Principle:
Principle #10Preliminary action

2Reliability

If Hardware Security Modules are deployed to securely store geographic location data, then security and trust are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity and trustVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages existing HSMs and TPMs that are already deployed in cloud infrastructure for their primary security functions (key management, cryptographic operations) and extends their functionality to also store and attest geographic location information. This multi-functional use of existing security hardware avoids adding separate dedicated devices, thereby limiting the increase in infrastructure complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The geographic location attestation capability is nested within the existing HSM/TPM security infrastructure. The location verification functionality is embedded as an additional feature within these modules rather than being implemented as a separate external system, allowing the complex security requirements to be met while minimizing additional hardware complexity

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If geographic location is accurately determined and provisioned, then compliance with legal requirements is improved, but measurement precision requirements increase system complexity

Engineering Contradiction:
Improvecompliance assuranceVSAvoidgeographic location accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system implements geographic location attestation at the level of physical infrastructure elements (data centers, host machines) rather than requiring precise tracking of individual virtual machines or data packets. This partial measurement approach provides sufficient compliance assurance for most legal and regulatory requirements without the excessive complexity of tracking every individual computational resource's precise location in real-time

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9960921B2Systems and methods for securely provisioning the geographic location of physical infrastructure elements in cloud computing environments
Publication Date: 2018.05.01 EMC IP HLDG CO LLC
  • US9960921B2 patent drawing
  • US9960921B2 patent drawing
  • US9960921B2 patent drawing

AI summary

Systems and methods relating to improved security in cloud computing environments are disclosed. According to one illustrative implementation, a method for provisioning physical geographic location of a physical infrastructure device associated with a hypervisor host is provided. Further, the method may include performing processing to obtain initial geo location data of the device, determining verified geo location data of the device by performing validation, via an attestation service component, of the initial geo location data to provide verified geo location data, and writing the verified geo location data into HSM or TPM space of the hypervisor host.