Virtual TPM Emulation for VM State Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In computer systems using hypervisors and virtual machines, the Trusted Platform Module (TPM) is generally inaccessible to virtual machines, leading to challenges in reflecting the virtual machine state in hardware-based platform configuration registers, which affects trust and security functions.
Innovation Solution
A system and method that initializes multiple platform configuration registers in a hardware-based TPM during the start sequence, calculates and compares PCR values for software modules, including the hypervisor, to create a virtual trust platform module (vTPM) that emulates TPM functions for virtual machines, ensuring secure execution and migration based on predefined rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a hypervisor is used to provide virtual machines on a host computer system with a TPM, then virtualization and multi-OS support are enabled, but the TPM becomes inaccessible from the virtual machines and cannot reflect VM state in hardware-based platform configuration registers
Solution Approach 1:
The patent introduces a virtual TPM (vTPM) as an intermediary component that sits between the virtual machines and the physical TPM. The vTPM captures VM state information and translates it into TPM-compatible formats, enabling VMs to access TPM functions through the hypervisor without direct hardware access. This mediator resolves the contradiction by providing TPM functionality to virtualized environments while maintaining the hypervisor's abstraction layer.
Solution Approach 2:
The patent creates a virtual copy of the TPM functionality within the virtualized environment. Instead of giving direct access to the physical TPM, the system creates a virtual TPM instance that replicates TPM operations and maintains VM-specific state information. This copying approach allows multiple VMs to have isolated TPM instances, each reflecting its own state, while the underlying physical TPM remains protected and inaccessible directly to VMs.
2Reliability
If the hypervisor passes TPM requests from virtual machines to the physical TPM, then TPM functionality is available to VMs, but the hardware-based platform configuration registers do not reflect the virtual machine state differences
Solution Approach 1:
The patent segments the TPM functionality into multiple virtual TPM instances, each associated with a specific virtual machine. Each vTPM maintains its own platform configuration registers (PCRs) that are specific to that VM's state. This segmentation allows each VM to have accurate state reflection in its dedicated vTPM, while the physical TPM remains unchanged. The hypervisor manages multiple vTPM instances, each capturing and reflecting the specific state of its associated VM independently.
3Reliability
If PCR values are calculated and compared to verify hypervisor integrity, then system trust is established, but the virtual machine state differences are not captured in the hardware-based PCRs
Solution Approach 1:
The patent adds another dimension to the TPM state management by creating virtual PCRs in the vTPM that exist alongside the physical PCRs. While the physical TPM maintains its hardware-based PCRs for hypervisor and system-level trust verification, the virtual TPM introduces VM-specific PCR registers that capture virtual machine state information. This dimensional addition allows both system-wide trust (through physical PCRs) and VM-specific state tracking (through virtual PCRs) to coexist without interfering with each other.
Data Source
AI summary
A system, method, and program product is provided that executes a start sequence of an information handling system that includes a hardware based TPM. Multiple PCRs are stored in the TPM and are initialized to a predetermined state when the start sequence commences. During execution of the start sequence, software modules, including a hypervisor, are loaded the system's memory. PCR values resulting from the loading of the software modules are calculated. The resulting PCR values are compared with expected PCR values. If the PCR values match the expected PCR values, then a virtual environment is created under the hypervisor. The virtual environment includes a VM and a virtual trust platform module (vTPM) that is used by the virtual machine to satisfy the virtual machines TPM requests.


