Virtual TPM Framework for Multi-OS Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional TPMs are unable to support multiple concurrently running operating systems due to their stateful and opaque nature, lacking the ability to separately store measurements of multiple OSs, which hinders secure virtualization and attestation across virtual machines.

Innovation Solution

A generalized virtual TPM (GVTPM) framework is introduced, allowing for the creation of virtual TPMs that operate within a virtual machine monitor (VMM), providing TPM-like functionality and enabling multiple virtual machines to share a single TPM without requiring modifications to guest OSs or applications, by using protected memory and virtualization techniques to emulate hardware TPMs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional TPM is used to provide security services, then security attestation and secure storage are improved, but the system can support only one software environment at a time

Engineering Contradiction:
Improvesecurity attestationVSAvoidsoftware environment support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates virtual copies of the TPM functionality through virtual TPM instances that emulate the hardware TPM's security services. Each virtual machine receives a virtual TPM instance that copies the essential attestation and secure storage capabilities, allowing multiple software environments to simultaneously access TPM functionality without interfering with each other.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent segments the single hardware TPM's functionality into multiple virtual TPM instances, each dedicated to a specific virtual machine. This segmentation allows the system to provide TPM services to multiple software environments concurrently by dividing the monolithic TPM resource into isolated, manageable segments.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a hardware TPM is used for secure storage, then security policies and sensitive information protection are improved, but the TPM's stateful and opaque nature prevents support for multiple OSs

Engineering Contradiction:
Improvesensitive information protectionVSAvoidTPM state management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtualization layer as an intermediary between the hardware TPM and multiple operating systems. This intermediary manages the TPM's stateful nature by creating virtual instances that each appear to have exclusive access to the TPM, thereby simplifying state management while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates virtual copies of the TPM's state and functionality for each virtual machine, allowing each OS to interact with its own copy of the TPM state without conflicting with other OSs. This copying approach maintains the security properties while eliminating the complexity of managing a single shared state.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If virtualization is implemented to allow multiple OSs, then software environment versatility is improved, but the conventional TPM cannot provide separate measurements for each VM

Engineering Contradiction:
Improvemulti-OS supportVSAvoidplatform attestation
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent segments the TPM's measurement and attestation functionality into separate virtual instances, each capable of independently measuring and attesting to its associated virtual machine's platform state. This segmentation enables precise, separate measurements for each VM while maintaining the versatility of multi-OS support.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7613921B2Method and apparatus for remotely provisioning software-based security coprocessors
Publication Date: 2009.11.03 TAHOE RES LTD
  • US7613921B2 patent drawing
  • US7613921B2 patent drawing
  • US7613921B2 patent drawing

AI summary

A virtual security coprocessor is created in a first processing system. The virtual security coprocessor is then transferred to a second processing system, for use by the second processing system. For instance, the second processing system may use the virtual security coprocessor to provide attestation for the second processing system. In an alternative embodiment, a virtual security coprocessor from a first processing system is received at a second processing system. After receiving the virtual security coprocessor from the first processing system, the second processing system uses the virtual security coprocessor. Other embodiments are described and claimed.