Virtual Machine OS Disk Integrity via Firmware PCR Measurement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for verifying the integrity of an operating system (OS) disk in virtual machines (VMs) do not provide comprehensive protection, as they require rebuilding and resigning the initial ramdisk (initrd) and universal kernel image (UKI) upon changes, lacking integrity verification for the OS disk itself.
Innovation Solution
A method and device for verifying OS disk integrity in VMs by measuring components, including the bootloader, kernel, and OS disk components into a platform configuration register (PCR) using an initial firmware, without requiring changes to the initrd, allowing for attestation of the OS disk integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If OS disk integrity verification is added to the measured boot process, then integrity protection is improved, but device complexity increases
Solution Approach 1:
The patent segments the integrity verification process by measuring individual OS disk components (bootloader, kernel, initrd, filesystem) separately into different PCR registers. This allows each component to be verified independently without requiring complete reconstruction of the entire boot process, thus improving integrity protection while managing complexity through modular measurement.
Solution Approach 2:
The patent introduces an intermediary measurement mechanism where the firmware acts as a mediator between the OS disk components and the PCR registers. The firmware measures each component and stores hash values in PCRs, providing an intermediate layer that enables integrity verification without directly modifying the boot components themselves, thus resolving the complexity issue.
2Reliability
If initrd is rebuilt and resigned to include OS disk information, then integrity verification capability is improved, but manufacturing complexity and time increase
Solution Approach 1:
The patent applies preliminary action by measuring the OS disk components into PCRs during the boot process before the initrd needs to be rebuilt. This allows integrity verification to be established in advance through firmware measurements, eliminating the need for subsequent initrd reconstruction and resigning operations.
Solution Approach 2:
The patent extracts the integrity verification function from the initrd itself and places it in the firmware layer. Instead of embedding verification logic and OS disk information within the initrd (which would require rebuilding), the firmware independently measures components and stores measurements in PCRs, separating the verification mechanism from the initrd configuration.
3Measurement precision
If universal kernel image is rebuilt and resigned for initrd changes, then attestation accuracy is improved, but productivity decreases
Solution Approach 1:
The patent segments the attestation process by measuring the UKI, initrd, and OS disk components separately into different PCR registers. This segmentation allows each component to be verified independently with high precision without requiring complete UKI reconstruction, thus maintaining attestation accuracy while improving boot process efficiency.
Solution Approach 2:
The patent enhances the universality of the UKI by designing it to work with the firmware-based measurement mechanism that measures multiple components (UKI itself, initrd, and OS disk components) into separate PCRs. This universal measurement approach provides accurate attestation for all components without requiring UKI resigning when initrd or OS disk changes occur.
Data Source
AI summary
Described are examples for verifying integrity of an operating system (OS) disk of a virtual machine including initializing the virtual machine including performing, by an initial firmware, a measured boot to measure each of a bootloader and a kernel into a platform configuration register (PCR), measuring, during the measured boot, a component of the OS disk of the virtual machine into the PCR, and providing, based on a received request, a value in the PCR for verifying integrity of the virtual machine.


