Virtual Trusted Platform Module Sharing Physical TPM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
High-performance servers with partitionable environments face challenges in certifying each partition as a trusted platform, as providing a single trusted platform module for every partition is impractical, limiting the ability to establish trust and protect sensitive data and operations.
Innovation Solution
The solution involves virtualizing trusted platform modules within a data processing system, allowing a single physical trusted platform module to be shared and function uniquely with each partition, by creating a virtual trusted platform module and virtual endorsement key anchored to the physical module, enabling transitive trust relationships and cryptographic key material instantiation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single physical trusted platform module is provided for each partition in a partitionable environment, then trust certification and data protection for each partition is improved, but device complexity and cost increase significantly
Solution Approach 1:
The patent segments the trusted platform module functionality by creating virtual TPM instances (vTPM1, vTPM2, etc.) that are logically separated and associated with specific partitions, while physically sharing the same hardware resource. Each virtual TPM maintains independent trust credentials and state, enabling individual partition certification without requiring separate physical devices.
Solution Approach 2:
The patent makes a single physical TPM device universal by enabling it to serve multiple partitions simultaneously through virtualization. The physical TPM can dynamically allocate its resources and trust functions to different partitions as needed, allowing one device to perform the roles of multiple dedicated TPMs.
2Reliability
If multiple physical trusted platform modules are deployed to support concurrent partitions, then trust establishment for each partition is improved, but loss of substance and resource waste increase
Solution Approach 1:
The patent merges multiple TPM functions into a single physical TPM device by implementing virtualization that allows multiple virtual TPM instances to share the same hardware resources. This consolidation eliminates the need for multiple separate physical devices while maintaining the trust establishment capabilities for each partition.
Solution Approach 2:
The patent introduces dynamic resource allocation where a single physical TPM can dynamically switch between serving different partitions. The virtual TPM instances can be created, activated, and deactivated as partitions are launched and terminated, allowing the hardware resources to be dynamically reused rather than statically allocated.
3Adaptability or versatility
If virtual trusted platform modules are created within a physical TPM, then adaptability and resource efficiency are improved, but manufacturing precision and security requirements increase
Solution Approach 1:
The patent introduces a hypervisor as an intermediary layer between the physical TPM and the virtual TPM instances. The hypervisor manages the virtualization process, handles the creation and management of virtual TPMs, and ensures proper isolation and security boundaries. This intermediary simplifies the implementation complexity by providing a standardized virtualization framework.
Data Source
AI summary
A method, an apparatus, a system, and a computer program product is presented for virtualizing trusted platform modules within a data processing system. A virtual trusted platform module along with a virtual endorsement key is created within a physical trusted platform module within the data processing system using a platform signing key of the physical trusted platform module, thereby providing a transitive trust relationship between the virtual trusted platform module and the core root of trust for the trusted platform. The virtual trusted platform module can be uniquely associated with a partition in a partitionable runtime environment within the data processing system.


