TPM-Based Virtual Machine Measurement for Remote Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack a reliable method for verifying the security and integrity of virtual machines instantiated on host computing devices, particularly in shared environments where the host system's security cannot be trusted without direct verification.
Innovation Solution
Implementing a trusted platform module (TPM) with secured memory to store measurements of virtual machine characteristics, allowing remote verification of the virtual machine's integrity by storing these measurements securely and inaccessible to the host system, ensuring that the virtual machine has not been tampered with during instantiation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtual machines are instantiated on shared host systems, then computing resource utilization is improved, but security and integrity verification becomes problematic
Solution Approach 1:
The system segments the verification process by separating the measurement function (performed by the host system on the virtual machine) from the storage function (performed by the remote verifier in secured memory). This segmentation allows the host system to continue providing computing resources while a trusted remote entity performs independent verification, resolving the contradiction between resource utilization and security verification.
Solution Approach 2:
The patent introduces a remote verifier as an intermediary between the host system and the virtual machine. This intermediary captures measurements directly from the virtual machine instance and stores them in secured memory, enabling security verification without requiring the host system to trust the virtual machine's integrity claims. The intermediary resolves the contradiction by providing an independent verification mechanism that doesn't compromise resource utilization.
2Measurement precision
If the host system stores virtual machine measurements, then verification capability is improved, but trust in the host system is reduced
Solution Approach 1:
The patent extracts the measurement storage function from the host system and places it in a remote verifier's secured memory. By taking out the storage capability from the potentially untrusted host system and placing it in a remotely accessible secure location, the system maintains verification capability while eliminating reliance on host system trust. The host system can still perform measurements, but the critical storage and verification functions are separated.
Solution Approach 2:
The patent moves the measurement storage from the local host system dimension to a remote verifier dimension. By storing measurements in a location that is remotely accessible and secured against host system access, the system creates a new dimensional space for verification that is independent of host system trust. This dimensional change allows verification capability to be maintained while host system trust requirements are reduced.
3Reliability
If secured memory is used to store measurements, then security is improved, but device complexity increases
Solution Approach 1:
The remote verifier performs self-service by maintaining its own secured memory and verification processes independently of the host system. Rather than requiring the host system to provide security services, the remote verifier autonomously captures measurements, stores them securely, and performs verification. This self-service approach improves security while avoiding the complexity of integrating security infrastructure into the host system.
Solution Approach 2:
The remote verifier serves multiple functions: it acts as a measurement capturer, a secure storage system, and a verification authority. By consolidating these functions in a single remote entity with secured memory, the system achieves high security without distributing complexity across multiple components. The multi-functional remote verifier provides security improvements while maintaining relatively simple system architecture.
Data Source
AI summary
A security verification system may acquire first authorization information, wherein the first authorization information defines an access right to store data in a trusted platform module (TPM) of the computing device. A system may generate an index of an allocated memory location of the TPM and second authorization information using the first authorization information, wherein the second authorization information defines an access right associated with the index. A system may receive a request from a hypervisor to initiate a virtual machine. A system may transmit the second authorization information to the hypervisor. A system may store an initial state of the virtual machine at the index using the second authorization information.


