Virtual TPM Framework for Multi-OS Secure Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional TPMs are unable to support multiple concurrently running operating systems due to their stateful and opaque nature, lacking the ability to separately store measurements of multiple OSs, which hinders secure virtualization and attestation across virtual machines.

Innovation Solution

A virtual TPM framework is implemented, allowing multiple virtual machines to share a TPM by creating a logical component that provides TPM-like functionality, enabling secure virtualization and attestation without requiring modifications to guest OSs or applications, using a VTPM framework that operates within a VMM and supports multiple VMs with independent guest OSs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional TPM is used to provide security services, then security attestation and secure storage are improved, but the system can only support one software environment at a time

Engineering Contradiction:
Improvesecurity attestationVSAvoidsoftware environment support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the TPM functionality by creating virtual TPM instances (vTPM0, vTPM1, etc.) that can be independently assigned to different virtual machines. Each vTPM maintains separate measurement registers and security state, allowing multiple software environments to concurrently access TPM security services without interfering with each other. This segmentation resolves the contradiction by enabling both secure attestation (through dedicated vTPM instances) and multi-environment support (through parallel vTPM operation).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtual machine monitor (VMM) as an intermediary layer between the physical TPM hardware and multiple guest operating systems. The VMM manages the creation and assignment of virtual TPM instances to different VMs, mediating access to TPM resources and maintaining isolation between software environments. This intermediary enables concurrent support for multiple software environments while preserving security attestation capabilities through controlled resource allocation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If a TPM stores measurements of platform configuration, then platform integrity verification is improved, but the TPM cannot separately store measurements of multiple operating systems

Engineering Contradiction:
Improveplatform configuration measurementVSAvoidmulti-OS measurement capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the measurement storage capability by providing separate measurement registers (PCR0-PCR15) to each virtual TPM instance. When vTPM0 is assigned to VM0 and vTPM1 to VM1, each vTPM independently measures and stores the configuration of its respective operating system without overwriting or interfering with the other's measurements. This segmentation enables precise measurement of each platform configuration while supporting multiple operating systems concurrently.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If virtualization products partition hardware resources to allow multiple OSs to execute concurrently, then software environment versatility is improved, but the ability to provide TPM-based security services to each VM is lost

Engineering Contradiction:
Improvesoftware environment partitioningVSAvoidTPM security service availability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates virtual copies of the TPM functionality through virtual TPM instances that emulate the behavior and interface of physical TPM hardware. Each vTPM is a software-based copy that provides the same security services (measurement, attestation, key storage) to its assigned VM as a physical TPM would. This copying approach enables versatile software environment partitioning while maintaining reliable TPM security services through accurate functional replication.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8074262B2Method and apparatus for migrating virtual trusted platform modules
Publication Date: 2011.12.06 TAHOE RES LTD
  • US8074262B2 patent drawing
  • US8074262B2 patent drawing
  • US8074262B2 patent drawing

AI summary

A first processing system determines whether a second processing system provides a trustworthy state for supporting a virtual trusted platform module (TPM), based at least in part on an assertion made by a management authority. The first processing system also determines whether the management authority is trusted. The first processing system may transfer state for the virtual TPM to the second processing system only if (a) the management authority is trusted and (b) the assertion made by the management authority indicates that the second processing system provides a trustworthy environment for supporting the virtual TPM. In one embodiment, the first processing system transfers state for the virtual TPM to the second processing system only if a trust level designation for the second processing system is equal or greater than a trust level for the first processing system. Other embodiments are described and claimed.