TPM-Based Virtual Machine Measurement for Remote Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack a reliable method for verifying the security and integrity of virtual machines instantiated on host computing devices, particularly in shared environments where the host system's security cannot be trusted without direct verification.

Innovation Solution

Implementing a trusted platform module (TPM) with secured memory to store measurements of virtual machine characteristics, allowing remote verification of the virtual machine's integrity by storing these measurements securely and inaccessible to the host system, ensuring that the virtual machine has not been tampered with during instantiation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machines are instantiated on shared host systems, then computing resource utilization is improved, but security and integrity verification becomes problematic

Engineering Contradiction:
Improvecomputing resource utilizationVSAvoidsecurity verification
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the verification process by separating the measurement function (performed by the host system on the virtual machine) from the storage function (performed by the remote verifier in secured memory). This segmentation allows the host system to continue providing computing resources while a trusted remote entity performs independent verification, resolving the contradiction between resource utilization and security verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a remote verifier as an intermediary between the host system and the virtual machine. This intermediary captures measurements directly from the virtual machine instance and stores them in secured memory, enabling security verification without requiring the host system to trust the virtual machine's integrity claims. The intermediary resolves the contradiction by providing an independent verification mechanism that doesn't compromise resource utilization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the host system stores virtual machine measurements, then verification capability is improved, but trust in the host system is reduced

Engineering Contradiction:
Improveverification capabilityVSAvoidhost system trust
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent extracts the measurement storage function from the host system and places it in a remote verifier's secured memory. By taking out the storage capability from the potentially untrusted host system and placing it in a remotely accessible secure location, the system maintains verification capability while eliminating reliance on host system trust. The host system can still perform measurements, but the critical storage and verification functions are separated.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent moves the measurement storage from the local host system dimension to a remote verifier dimension. By storing measurements in a location that is remotely accessible and secured against host system access, the system creates a new dimensional space for verification that is independent of host system trust. This dimensional change allows verification capability to be maintained while host system trust requirements are reduced.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If secured memory is used to store measurements, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The remote verifier performs self-service by maintaining its own secured memory and verification processes independently of the host system. Rather than requiring the host system to provide security services, the remote verifier autonomously captures measurements, stores them securely, and performs verification. This self-service approach improves security while avoiding the complexity of integrating security infrastructure into the host system.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The remote verifier serves multiple functions: it acts as a measurement capturer, a secure storage system, and a verification authority. By consolidating these functions in a single remote entity with secured memory, the system achieves high security without distributing complexity across multiple components. The multi-functional remote verifier provides security improvements while maintaining relatively simple system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12524260B2Measurements of virtual machines
Publication Date: 2026.01.13 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US12524260B2 patent drawing
  • US12524260B2 patent drawing
  • US12524260B2 patent drawing

AI summary

A security verification system may acquire first authorization information, wherein the first authorization information defines an access right to store data in a trusted platform module (TPM) of the computing device. A system may generate an index of an allocated memory location of the TPM and second authorization information using the first authorization information, wherein the second authorization information defines an access right associated with the index. A system may receive a request from a hypervisor to initiate a virtual machine. A system may transmit the second authorization information to the hypervisor. A system may store an initial state of the virtual machine at the index using the second authorization information.