Trusted Computing Host for Secure VM Key Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, conventional security approaches fail to effectively isolate and manage cryptographic keys and security attributes across multiple virtual machines hosted on shared resources, leading to potential compromise in case of virtual machine escape or migration, and lack of secure key transfer during virtual machine migration.

Innovation Solution

A trusted computing host is implemented to manage cryptographic keys and security attributes in isolated partitions, providing security functions such as boot firmware measurement, remote attestation, and forensic analysis, ensuring secure communication and key management across virtual machines, even during migration, using cryptographic co-processors and secure storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cryptographic keys and security attributes are stored in shared cloud resources, then resource utilization is improved, but security reliability deteriorates due to potential compromise from virtual machine escape or migration

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the cloud computing environment by introducing a dedicated trusted computing host separate from the virtualization host. This segmentation isolates cryptographic key management and security attribute storage from the shared resources, allowing multiple virtual machines to utilize cloud resources while maintaining independent security boundaries that prevent compromise propagation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted computing host acts as an intermediary between the virtualization host and the cryptographic key management functions. It provides secure key storage, generates cryptographic keys, and performs remote attestation on behalf of virtual machines, mediating security functions without requiring direct access to the shared cloud resources or the virtual machine guest operating systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cryptographic services are shared across multiple virtual machines, then service efficiency is improved, but security isolation deteriorates making the system vulnerable to malicious users

Engineering Contradiction:
Improveservice efficiencyVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent creates logical segmentation of cryptographic services by providing dedicated key management instances for each virtual machine through the trusted computing host. While the physical infrastructure is shared, each virtual machine's cryptographic keys and security attributes are isolated in separate secure storage partitions, preventing malicious users from accessing other tenants' cryptographic materials even in multitenant environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted computing host implements local quality by providing customized security attributes and cryptographic key management tailored to each virtual machine's specific requirements. Each virtual machine receives security services adapted to its workload characteristics while maintaining uniform security isolation boundaries, allowing efficient service delivery without compromising security.

Inventive Principle:
Principle #3Local quality

3Speed

If security attributes are stored on the host computing device, then access speed is improved, but security isolation deteriorates during virtual machine migration

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity isolation
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The trusted computing host serves as an intermediary that maintains security attributes in a location accessible during virtual machine migration. When a virtual machine migrates between host computing devices, the security attributes remain stored in the trusted computing host's secure storage, and the migrating virtual machine can access them through secure communication channels, ensuring both continuity of access and maintenance of security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the dimensional relationship between security attribute storage and virtual machine execution by separating them into different computational dimensions. Security attributes are stored in the trusted computing host's secure storage subsystem, while virtual machines execute on separate virtualization hosts. This dimensional separation allows independent management of security attributes during migration events while maintaining fast access through optimized retrieval protocols.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10409985B2Trusted computing host
Publication Date: 2019.09.10 AMAZON TECH INC
  • US10409985B2 patent drawing
  • US10409985B2 patent drawing
  • US10409985B2 patent drawing

AI summary

A trusted computing host is described that provides various security computations and other functions in a distributed multitenant and/or virtualized computing environment. The trusted host computing device can communicate with one or more host computing devices that host virtual machines to provide a number of security-related functions, including but not limited to boot firmware measurement, cryptographic key management, remote attestation, as well as security and forensics management. The trusted computing host maintains an isolated partition for each host computing device in the environment and communicates with peripheral cards on host computing devices in order to provide one or more security functions.