Cryptographic Attestation for Virtual Machine Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud computing virtualization lacks robust cryptographic assurance for users regarding the integrity and security of virtual machines hosted on remote resources, as customers cannot physically verify if the resources have been tampered with or compromised.

Innovation Solution

Implementing a two-phase launch process for virtual machines, where cryptographic measurements of host computing resources are obtained using a Trusted Platform Module (TPM) and compared to a list of approved measurements or attested by a trusted third party, allowing users to verify the security and integrity of the hosting environment before launching the virtual machine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional virtualization is used to allow multiple users to share underlying hardware resources, then resource utilization and scalability are improved, but security assurance and integrity verification for individual users deteriorate

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity assurance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the virtualization trust model by introducing separate attestation paths for each virtual machine. Each VM gets its own cryptographic measurement and attestation certificate, allowing individual security verification without compromising the shared infrastructure. This enables multiple users to share resources while each maintains independent security assurance through separate attestation instances.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted third party (attestation authority) as an intermediary between the virtualization infrastructure and users. This mediator issues cryptographic attestation certificates that verify the integrity of hosting resources, providing users with security assurance without requiring direct physical access or trust in the cloud provider's internal security measures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic measurements are obtained and verified for each virtual machine hosting environment, then security and integrity assurance are improved, but system complexity and verification overhead increase

Engineering Contradiction:
Improveintegrity verificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal attestation framework where a single trusted third party serves multiple virtual machines and users. The attestation authority provides a standardized verification mechanism that can be applied across different VMs and hosting environments, reducing overall system complexity through reuse of the same cryptographic infrastructure and verification processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses cryptographic copying by creating attestation certificates that replicate the trust relationship. Instead of requiring direct verification of each hosting environment's physical security, the system creates cryptographic copies (certificates) of the integrity measurements that can be verified independently, simplifying the verification process while maintaining security assurance.

Inventive Principle:
Principle #26Copying

3Reliability

If users require physical access to verify resource integrity, then security assurance is improved, but cloud computing's remote access model and scalability deteriorate

Engineering Contradiction:
Improvesecurity assuranceVSAvoidremote access model
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical requirement for physical access with a cryptographic verification system. Instead of users needing to physically inspect hosting resources, the system uses cryptographic measurements and digital certificates to provide equivalent security assurance remotely, maintaining the cloud computing model while enhancing security verification capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The trusted third party acts as an intermediary that bridges the gap between physical resource integrity and remote user verification. This mediator collects cryptographic measurements from the hosting environment and provides verified attestation certificates to users, enabling security assurance without requiring physical presence or direct access to the underlying infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3017397B1Cryptographically attested resources for hosting virtual machines
Publication Date: 2021.11.17 AMAZON TECH INC
  • EP3017397B1 patent drawingFigure 1
  • EP3017397B1 patent drawingFigure 2
  • EP3017397B1 patent drawingFigure 3

AI summary

Approaches to enable the configuration of computing resources for executing virtual machines on behalf of users to be cryptographically attested to or verified. When a user requests a virtual machine to be provisioned, an operator of the virtualized computing environment can initiate a two phase launch of the virtual machine. In the first phase, the operator provisions the virtual machine on a host computing device and obtains cryptographic measurements of the software and/or hardware resources on the host computing device. The operator may then provide those cryptographic measurements to the user that requested the virtual machine. If the user approves the cryptographic measurements, the operator may proceed with the second phase and actually launch the virtual machine on the host. In some cases, operator may compare the cryptographic measurements to a list of approved measurements to determine whether the host computing device is acceptable for hosting the virtual machine.