Virtual TPM Emulation for Encrypted Blade Server Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The migration of data between blade servers, especially when using full disk encryption and Trusted Platform Module (TPM) technology, is hindered by the immutability of keys and the need for decryption and re-encryption, leading to slow data transfer and complications in maintaining security and integrity across different hardware platforms.
Innovation Solution
The implementation of a chassis management module that creates virtual security hardware instances, allowing for the emulation of TPM functionality and key management, enabling the migration of encrypted data and security keys across blade servers without the need for physical TPMs, using out-of-band communication channels to manage and transfer virtual partitions and processor states.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full disk encryption is used to protect sensitive data on blade servers, then data security is improved, but data migration speed deteriorates due to decryption and re-encryption requirements
Solution Approach 1:
The system separates encryption keys from individual blade servers and stores them in a centralized key management server. This segmentation allows data to remain encrypted on disk while keys are managed separately, enabling fast migration by transferring only data ciphertext without requiring decryption and re-encryption operations at each blade server.
Solution Approach 2:
A centralized key management server acts as an intermediary between blade servers and encrypted data. This mediator manages encryption keys centrally, allowing blade servers to access decrypted data through the intermediary without performing local decryption/re-encryption during migration, thus maintaining security while improving migration speed.
2Reliability
If TPM technology is used to provide security hardware protection, then data protection is improved, but key migratability deteriorates due to immutable key binding to hardware
Solution Approach 1:
Instead of relying on immutable physical TPM hardware keys, the system creates virtual security hardware instances that can be copied and migrated along with the virtual machine. These virtual keys are stored in the centralized key management server and can be transferred to new blade servers, maintaining security protection while enabling key migratability.
Solution Approach 2:
The patent replaces physical TPM hardware with virtual security hardware instances implemented through software. This substitution allows the security functionality to be decoupled from specific physical hardware, enabling keys to be migrated virtually while maintaining the security properties that TPM technology provides.
3Adaptability or versatility
If data is transferred from one blade server to another, then migration capability is improved, but migration time increases due to large data volumes and bandwidth requirements
Solution Approach 1:
The system extracts encryption keys from the data storage location and manages them separately in a centralized key management server. During migration, only the data ciphertext needs to be transferred between blade servers, while key access is handled by the centralized server. This extraction of key management functionality reduces the time-critical decryption operations during data transfer.
4Reliability
If decryption and re-encryption processes are performed during migration, then security is maintained, but processing overhead increases and slows down migration
Solution Approach 1:
The system merges key management functionality into a centralized key management server that serves all blade servers. Instead of each blade server performing independent decryption and re-encryption operations during migration, the centralized server handles key management for the entire system, consolidating processing overhead and enabling parallel migration operations.
Data Source
AI summary
A method, system and computer-readable storage medium with instructions to migrate full-disk encrypted virtual storage between blade servers. A key is obtained to perform an operation on a first blade server. The key is obtained from a virtual security hardware instance and provided to the first blade server via a secure out-of-band communication channel. The key is migrated from the first blade server to a second blade server. The key is used to perform hardware encryption of data stored on the first blade server. The data are migrated to the second blade server without decrypting the data at the first blade server, and the second blade server uses the key to access the data. Other embodiments are described and claimed.


