Virtual TPM Framework for Multi-OS Secure Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional TPMs are unable to support multiple concurrently running operating systems due to their stateful and opaque nature, lacking the ability to separately store measurements of multiple OSs, which hinders secure virtualization and attestation across virtual machines.
Innovation Solution
A virtual TPM framework is implemented, allowing multiple virtual machines to share a TPM by creating a logical component that provides TPM-like functionality, enabling secure virtualization and attestation without requiring modifications to guest OSs or applications, using a VTPM framework that operates within a VMM and supports multiple VMs with independent guest OSs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a conventional TPM is used to provide security services, then security attestation and secure storage are improved, but the system can only support one software environment at a time
Solution Approach 1:
The patent segments the TPM functionality by creating virtual TPM instances (vTPM0, vTPM1, etc.) that can be independently assigned to different virtual machines. Each vTPM maintains separate measurement registers and security state, allowing multiple software environments to concurrently access TPM security services without interfering with each other. This segmentation resolves the contradiction by enabling both secure attestation (through dedicated vTPM instances) and multi-environment support (through parallel vTPM operation).
Solution Approach 2:
The patent introduces a virtual machine monitor (VMM) as an intermediary layer between the physical TPM hardware and multiple guest operating systems. The VMM manages the creation and assignment of virtual TPM instances to different VMs, mediating access to TPM resources and maintaining isolation between software environments. This intermediary enables concurrent support for multiple software environments while preserving security attestation capabilities through controlled resource allocation.
2Measurement precision
If a TPM stores measurements of platform configuration, then platform integrity verification is improved, but the TPM cannot separately store measurements of multiple operating systems
Solution Approach 1:
The patent segments the measurement storage capability by providing separate measurement registers (PCR0-PCR15) to each virtual TPM instance. When vTPM0 is assigned to VM0 and vTPM1 to VM1, each vTPM independently measures and stores the configuration of its respective operating system without overwriting or interfering with the other's measurements. This segmentation enables precise measurement of each platform configuration while supporting multiple operating systems concurrently.
3Adaptability or versatility
If virtualization products partition hardware resources to allow multiple OSs to execute concurrently, then software environment versatility is improved, but the ability to provide TPM-based security services to each VM is lost
Solution Approach 1:
The patent creates virtual copies of the TPM functionality through virtual TPM instances that emulate the behavior and interface of physical TPM hardware. Each vTPM is a software-based copy that provides the same security services (measurement, attestation, key storage) to its assigned VM as a physical TPM would. This copying approach enables versatile software environment partitioning while maintaining reliable TPM security services through accurate functional replication.
Data Source
AI summary
A first processing system determines whether a second processing system provides a trustworthy state for supporting a virtual trusted platform module (TPM), based at least in part on an assertion made by a management authority. The first processing system also determines whether the management authority is trusted. The first processing system may transfer state for the virtual TPM to the second processing system only if (a) the management authority is trusted and (b) the assertion made by the management authority indicates that the second processing system provides a trustworthy environment for supporting the virtual TPM. In one embodiment, the first processing system transfers state for the virtual TPM to the second processing system only if a trust level designation for the second processing system is equal or greater than a trust level for the first processing system. Other embodiments are described and claimed.


