Virtual Static PCR Segmentation for Virtualized TPM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtual machine computing platforms, data collisions occur when multiple entities attempt to write to the platform configuration register (PCR) set, leading to ambiguity and conflicts over the source of PCR contents.
Innovation Solution
The implementation of a virtualized trusted platform module (TPM) with a virtual machine monitor (VMM) that manages requests for TPM resources by redirecting them to separate virtual static PCR (VS-PCR) sets, each associated with a specific guest operating system or application, thereby avoiding collisions and ensuring each entity operates as if it has sole control over the resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple entities share a single PCR set in a virtualized environment, then resource utilization is improved, but data collision and ambiguity occur
Solution Approach 1:
The patent divides the single shared PCR set into multiple separate PCR sets, with each PCR set dedicated to a specific virtual machine or entity. This segmentation eliminates data collisions while maintaining resource isolation, allowing each entity to have its own secure measurement space without interfering with others.
Solution Approach 2:
The patent introduces a virtualization layer (hypervisor or VMM) as an intermediary between multiple entities and the TPM. This intermediary manages and allocates PCR sets to different virtual machines, coordinating access and ensuring that each entity operates with its own dedicated PCR set while still utilizing the underlying TPM hardware resources.
2Adaptability or versatility
If multiple entities write to the same PCR set, then resource sharing is improved, but source ambiguity and conflicts arise
Solution Approach 1:
By segmenting the single PCR set into multiple separate PCR sets assigned to different virtual machines, the patent ensures that each entity's measurements are stored in its own dedicated space. This eliminates source ambiguity because each PCR set is exclusively associated with one entity, making it clear which entity produced which measurements.
Solution Approach 2:
The patent applies local quality by giving each virtual machine its own specific PCR set with unique characteristics and ownership. Each PCR set is tailored to its associated entity's needs, ensuring that measurements from different sources remain distinct and identifiable without mixing or confusion.
3Productivity
If a single PCR set is used for multiple virtual machines, then hardware resource efficiency is improved, but operational conflicts increase
Solution Approach 1:
The patent segments the PCR set resource into multiple isolated instances, one for each virtual machine. This allows the TPM hardware to efficiently serve multiple VMs simultaneously without operational conflicts, as each VM has its own dedicated PCR set that it can access independently without interfering with other VMs.
Solution Approach 2:
The patent creates multiple copies of the PCR set structure, with each copy assigned to a specific virtual machine. These copies maintain the same functional characteristics as the original PCR set but operate independently, allowing efficient hardware utilization while eliminating conflicts through duplication of the measurement storage structure.
Data Source
AI summary
Apparatus and systems, as well as methods and articles, may operate to intercept a first request to use a platform configuration register (PCR) directed to a first trusted platform module (TPM) port, a second request to use the PCR directed to the first TPM port, or both, and to re-direct the first and second requests to use the PCR to a second TPM port capable of accessing a first virtual static platform configuration register (VS-PCR) set and a second VS-PCR set.


