Virtual TPM Emulation for Encrypted Blade Server Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The migration of data between blade servers, especially when using full disk encryption and Trusted Platform Module (TPM) technology, is hindered by the immutability of keys and the need for decryption and re-encryption, leading to slow data transfer and complications in maintaining security and integrity across different hardware platforms.

Innovation Solution

The implementation of a chassis management module that creates virtual security hardware instances, allowing for the emulation of TPM functionality and key management, enabling the migration of encrypted data and security keys across blade servers without the need for physical TPMs, using out-of-band communication channels to manage and transfer virtual partitions and processor states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full disk encryption is used to protect sensitive data on blade servers, then data security is improved, but data migration speed deteriorates due to decryption and re-encryption requirements

Engineering Contradiction:
Improvedata securityVSAvoiddata migration speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system separates encryption keys from individual blade servers and stores them in a centralized key management server. This segmentation allows data to remain encrypted on disk while keys are managed separately, enabling fast migration by transferring only data ciphertext without requiring decryption and re-encryption operations at each blade server.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized key management server acts as an intermediary between blade servers and encrypted data. This mediator manages encryption keys centrally, allowing blade servers to access decrypted data through the intermediary without performing local decryption/re-encryption during migration, thus maintaining security while improving migration speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If TPM technology is used to provide security hardware protection, then data protection is improved, but key migratability deteriorates due to immutable key binding to hardware

Engineering Contradiction:
Improvedata protectionVSAvoidkey migratability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of relying on immutable physical TPM hardware keys, the system creates virtual security hardware instances that can be copied and migrated along with the virtual machine. These virtual keys are stored in the centralized key management server and can be transferred to new blade servers, maintaining security protection while enabling key migratability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces physical TPM hardware with virtual security hardware instances implemented through software. This substitution allows the security functionality to be decoupled from specific physical hardware, enabling keys to be migrated virtually while maintaining the security properties that TPM technology provides.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If data is transferred from one blade server to another, then migration capability is improved, but migration time increases due to large data volumes and bandwidth requirements

Engineering Contradiction:
Improvemigration capabilityVSAvoidmigration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system extracts encryption keys from the data storage location and manages them separately in a centralized key management server. During migration, only the data ciphertext needs to be transferred between blade servers, while key access is handled by the centralized server. This extraction of key management functionality reduces the time-critical decryption operations during data transfer.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If decryption and re-encryption processes are performed during migration, then security is maintained, but processing overhead increases and slows down migration

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges key management functionality into a centralized key management server that serves all blade servers. Instead of each blade server performing independent decryption and re-encryption operations during migration, the centralized server handles key management for the entire system, consolidating processing overhead and enabling parallel migration operations.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9047468B2Migration of full-disk encrypted virtualized storage between blade servers
Publication Date: 2015.06.02 INTEL CORP
  • US9047468B2 patent drawing
  • US9047468B2 patent drawing
  • US9047468B2 patent drawing

AI summary

A method, system and computer-readable storage medium with instructions to migrate full-disk encrypted virtual storage between blade servers. A key is obtained to perform an operation on a first blade server. The key is obtained from a virtual security hardware instance and provided to the first blade server via a secure out-of-band communication channel. The key is migrated from the first blade server to a second blade server. The key is used to perform hardware encryption of data stored on the first blade server. The data are migrated to the second blade server without decrypting the data at the first blade server, and the second blade server uses the key to access the data. Other embodiments are described and claimed.