Virtual TPM Migration for Secure Multi-OS Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional TPMs are unable to support multiple concurrently running operating systems due to their stateful and opaque nature, lacking the ability to separately store measurements of multiple OSs, which hinders secure virtualization and attestation across virtual machines.
Innovation Solution
A generalized virtual TPM (GVTPM) framework is introduced, allowing for the creation of virtual TPMs that operate within a virtual machine monitor (VMM), providing TPM-like functionality and enabling secure virtualization by emulating a hardware TPM, allowing multiple virtual machines to share a single TPM without requiring modifications to guest OSs or applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a conventional TPM is used to provide security services, then security attestation and data protection are improved, but the system can support only one software environment at a time
Solution Approach 1:
The patent creates a software-based virtual TPM (vTPM) that replicates the functionality of a hardware TPM. The vTPM emulates the TPM state machine, PCR registers, and security services in software, allowing multiple virtual machines to each have their own isolated TPM instance. This copying approach enables concurrent support for multiple software environments while maintaining the security attestation capabilities of a real TPM.
Solution Approach 2:
The patent segments the single hardware TPM functionality into multiple virtual TPM instances, each dedicated to a specific virtual machine. The VMM manages multiple vTPM state machines separately, with each vTPM maintaining its own PCR values and security context. This segmentation allows each VM to have isolated TPM services while the underlying hardware TPM resources are shared through the virtualization layer.
2Reliability
If a hardware TPM is used to store sensitive information, then security and trust are improved, but the TPM's stateful and opaque nature prevents separate storage measurements for multiple OSs
Solution Approach 1:
The patent introduces a virtualization layer (VMM) as an intermediary between multiple operating systems and the hardware TPM. The VMM creates virtual TPM instances that act as intermediaries for each OS, allowing each to have its own isolated measurement storage and security context. This intermediary layer enables multiple OSs to concurrently use TPM services without interfering with each other's measurement storage.
Solution Approach 2:
The patent creates software-based copies of the TPM state machine and measurement storage for each virtual machine. Each vTPM maintains separate PCR registers and security contexts in software, replicating the hardware TPM's measurement capabilities. This allows each OS to have its own isolated measurement storage without requiring modifications to the guest OS or applications.
3Productivity
If virtualization is implemented to allow multiple OSs to run concurrently, then productivity and resource utilization are improved, but the conventional TPM cannot provide separate attestation for each VM
Solution Approach 1:
The patent segments the TPM attestation functionality into separate virtual TPM instances for each virtual machine. Each vTPM maintains its own PCR values and security context, enabling precise measurement and attestation specific to each VM's software environment. This segmentation allows the VMM to provide accurate, isolated attestation for each concurrent OS while maintaining overall system productivity.
Data Source
AI summary
A first processing system determines whether a second processing system provides a trustworthy state for supporting a virtual security coprocessor. In response to determining that the second processing system provides a trustworthy state for supporting the virtual security coprocessor, the first processing system transfers the virtual security coprocessor to the second processing system. In one embodiment, the first processing system receives a key and proof of bindings of the key from the second processing system. The first processing system may determine whether the second processing system provides a trustworthy state for migration of the virtual security coprocessor, based at least in part on the proof of bindings received from the second processing system. After the second processing system receives the virtual security coprocessor, the virtual security coprocessor may be removed from the first processing system. Other embodiments are described and claimed.


