Trusted Computing Host for Secure VM Key Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing environments, conventional security approaches fail to effectively isolate and manage cryptographic keys and security attributes across multiple virtual machines hosted on shared resources, leading to potential compromise in case of virtual machine escape or migration, and lack of secure key transfer during virtual machine migration.
Innovation Solution
A trusted computing host is implemented to manage cryptographic keys and security attributes in isolated partitions, providing security functions such as boot firmware measurement, remote attestation, and forensic analysis, ensuring secure communication and key management across virtual machines, even during migration, using cryptographic co-processors and secure storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cryptographic keys and security attributes are stored in shared cloud resources, then resource utilization is improved, but security reliability deteriorates due to potential compromise from virtual machine escape or migration
Solution Approach 1:
The patent segments the cloud computing environment by introducing a dedicated trusted computing host separate from the virtualization host. This segmentation isolates cryptographic key management and security attribute storage from the shared resources, allowing multiple virtual machines to utilize cloud resources while maintaining independent security boundaries that prevent compromise propagation.
Solution Approach 2:
The trusted computing host acts as an intermediary between the virtualization host and the cryptographic key management functions. It provides secure key storage, generates cryptographic keys, and performs remote attestation on behalf of virtual machines, mediating security functions without requiring direct access to the shared cloud resources or the virtual machine guest operating systems.
2Productivity
If cryptographic services are shared across multiple virtual machines, then service efficiency is improved, but security isolation deteriorates making the system vulnerable to malicious users
Solution Approach 1:
The patent creates logical segmentation of cryptographic services by providing dedicated key management instances for each virtual machine through the trusted computing host. While the physical infrastructure is shared, each virtual machine's cryptographic keys and security attributes are isolated in separate secure storage partitions, preventing malicious users from accessing other tenants' cryptographic materials even in multitenant environments.
Solution Approach 2:
The trusted computing host implements local quality by providing customized security attributes and cryptographic key management tailored to each virtual machine's specific requirements. Each virtual machine receives security services adapted to its workload characteristics while maintaining uniform security isolation boundaries, allowing efficient service delivery without compromising security.
3Speed
If security attributes are stored on the host computing device, then access speed is improved, but security isolation deteriorates during virtual machine migration
Solution Approach 1:
The trusted computing host serves as an intermediary that maintains security attributes in a location accessible during virtual machine migration. When a virtual machine migrates between host computing devices, the security attributes remain stored in the trusted computing host's secure storage, and the migrating virtual machine can access them through secure communication channels, ensuring both continuity of access and maintenance of security isolation.
Solution Approach 2:
The patent changes the dimensional relationship between security attribute storage and virtual machine execution by separating them into different computational dimensions. Security attributes are stored in the trusted computing host's secure storage subsystem, while virtual machines execute on separate virtualization hosts. This dimensional separation allows independent management of security attributes during migration events while maintaining fast access through optimized retrieval protocols.
Data Source
AI summary
A trusted computing host is described that provides various security computations and other functions in a distributed multitenant and/or virtualized computing environment. The trusted host computing device can communicate with one or more host computing devices that host virtual machines to provide a number of security-related functions, including but not limited to boot firmware measurement, cryptographic key management, remote attestation, as well as security and forensics management. The trusted computing host maintains an isolated partition for each host computing device in the environment and communicates with peripheral cards on host computing devices in order to provide one or more security functions.


