Virtual Trusted Platform Module Sharing Physical TPM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High-performance servers with partitionable environments face challenges in certifying each partition as a trusted platform, as providing a single trusted platform module for every partition is impractical, limiting the ability to establish trust and protect sensitive data and operations.

Innovation Solution

The solution involves virtualizing trusted platform modules within a data processing system, allowing a single physical trusted platform module to be shared and function uniquely with each partition, by creating a virtual trusted platform module and virtual endorsement key anchored to the physical module, enabling transitive trust relationships and cryptographic key material instantiation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single physical trusted platform module is provided for each partition in a partitionable environment, then trust certification and data protection for each partition is improved, but device complexity and cost increase significantly

Engineering Contradiction:
Improvetrust certificationVSAvoidhardware configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the trusted platform module functionality by creating virtual TPM instances (vTPM1, vTPM2, etc.) that are logically separated and associated with specific partitions, while physically sharing the same hardware resource. Each virtual TPM maintains independent trust credentials and state, enabling individual partition certification without requiring separate physical devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes a single physical TPM device universal by enabling it to serve multiple partitions simultaneously through virtualization. The physical TPM can dynamically allocate its resources and trust functions to different partitions as needed, allowing one device to perform the roles of multiple dedicated TPMs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple physical trusted platform modules are deployed to support concurrent partitions, then trust establishment for each partition is improved, but loss of substance and resource waste increase

Engineering Contradiction:
Improvetrust establishmentVSAvoidhardware resources
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent merges multiple TPM functions into a single physical TPM device by implementing virtualization that allows multiple virtual TPM instances to share the same hardware resources. This consolidation eliminates the need for multiple separate physical devices while maintaining the trust establishment capabilities for each partition.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces dynamic resource allocation where a single physical TPM can dynamically switch between serving different partitions. The virtual TPM instances can be created, activated, and deactivated as partitions are launched and terminated, allowing the hardware resources to be dynamically reused rather than statically allocated.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If virtual trusted platform modules are created within a physical TPM, then adaptability and resource efficiency are improved, but manufacturing precision and security requirements increase

Engineering Contradiction:
Improvepartition supportVSAvoidvirtualization implementation
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The patent introduces a hypervisor as an intermediary layer between the physical TPM and the virtual TPM instances. The hypervisor manages the virtualization process, handles the creation and management of virtual TPMs, and ensures proper isolation and security boundaries. This intermediary simplifies the implementation complexity by providing a standardized virtualization framework.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7380119B2Method and system for virtualization of trusted platform modules
Publication Date: 2008.05.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US7380119B2 patent drawing
  • US7380119B2 patent drawing
  • US7380119B2 patent drawing

AI summary

A method, an apparatus, a system, and a computer program product is presented for virtualizing trusted platform modules within a data processing system. A virtual trusted platform module along with a virtual endorsement key is created within a physical trusted platform module within the data processing system using a platform signing key of the physical trusted platform module, thereby providing a transitive trust relationship between the virtual trusted platform module and the core root of trust for the trusted platform. The virtual trusted platform module can be uniquely associated with a partition in a partitionable runtime environment within the data processing system.