Virtual TPM Key Hierarchies for Secure VM Booting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing environments where virtual machines are hosted on different entities' systems, there is a risk of unauthorized access to secrets and keys due to exposure on unauthorized hardware or in unauthorized regions, as existing security measures fail to ensure secure booting and cryptographic operations.

Innovation Solution

Implementing a virtual Trusted Platform Module (vTPM) that generates keys from system features to unseal and manage the state of virtual machines, ensuring secure booting and cryptographic operations by binding objects to specific security domains based on system features, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machines are hosted on different entities' systems, then resource utilization and scalability are improved, but security risk increases due to exposure of secrets and keys on unauthorized hardware

Engineering Contradiction:
Improvevirtual machine hosting flexibilityVSAvoidunauthorized access to secrets and keys
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security functionality by introducing a virtual Trusted Platform Module (vTPM) that separates key management and security operations from the general virtual machine hosting infrastructure. The vTPM creates a isolated security domain that binds cryptographic operations to specific hardware identities, allowing flexible VM hosting while maintaining security boundaries through measurement and sealing mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The vTPM acts as an intermediary between the virtual machine and the host system, mediating all cryptographic operations. It uses measured seals that bind encrypted data to specific hardware configurations, serving as a trusted mediator that prevents unauthorized access while enabling secure cross-entity virtual machine hosting.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If existing security measures are used, then implementation simplicity is maintained, but security reliability is insufficient to prevent unauthorized access

Engineering Contradiction:
Improvesecurity implementation complexityVSAvoidsecurity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing hardware identity measurements and creating measured seals before any cryptographic operations occur. The vTPM measures the host system's identity characteristics and binds this information to encrypted data in advance, ensuring that only authorized systems can access the data without requiring complex runtime security checks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent adds a new dimension to security by introducing hardware-based identity measurement and binding. Instead of relying solely on software-based authentication, the vTPM creates a hardware-rooted trust chain that measures and binds cryptographic operations to physical system characteristics, adding a hardware dimension to the security model.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250103372A1Key hierarchies for virtual trusted platform modules in computing systems
Publication Date: 2025.03.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250103372A1 patent drawing
  • US20250103372A1 patent drawing
  • US20250103372A1 patent drawing

AI summary

Systems, methods, devices, and computer readable storage media described herein provide techniques utilizing key hierarchies for virtual trusted platform modules (vTPMs). In an aspect, a system comprises a vTPM. The vTPM receives a first seed value representative of a system feature of the system. The vTPM generates the first key from the first seed value, the first key configured to unseal a sealed state of an operating system of a virtual machine. The vTPM utilizes the first key to unseal the sealed state. The vTPM provides the unsealed state to an instance of the virtual machine to cause the instance to boot the operating system based on the unsealed state. In a further aspect, the vTPM receives, from an application executed by the instance, a request to perform a cryptographic operation to modify an object utilizing the first key.