Cryptographic Attestation for Virtual Machine Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud computing virtualization lacks robust cryptographic assurance for users regarding the integrity and security of virtual machines hosted on remote resources, as customers cannot physically verify if the resources have been tampered with or compromised.
Innovation Solution
Implementing a two-phase launch process for virtual machines, where cryptographic measurements of host computing resources are obtained using a Trusted Platform Module (TPM) and compared to a list of approved measurements or attested by a trusted third party, allowing users to verify the security and integrity of the hosting environment before launching the virtual machine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional virtualization is used to allow multiple users to share underlying hardware resources, then resource utilization and scalability are improved, but security assurance and integrity verification for individual users deteriorate
Solution Approach 1:
The patent segments the virtualization trust model by introducing separate attestation paths for each virtual machine. Each VM gets its own cryptographic measurement and attestation certificate, allowing individual security verification without compromising the shared infrastructure. This enables multiple users to share resources while each maintains independent security assurance through separate attestation instances.
Solution Approach 2:
The patent introduces a trusted third party (attestation authority) as an intermediary between the virtualization infrastructure and users. This mediator issues cryptographic attestation certificates that verify the integrity of hosting resources, providing users with security assurance without requiring direct physical access or trust in the cloud provider's internal security measures.
2Reliability
If cryptographic measurements are obtained and verified for each virtual machine hosting environment, then security and integrity assurance are improved, but system complexity and verification overhead increase
Solution Approach 1:
The patent creates a universal attestation framework where a single trusted third party serves multiple virtual machines and users. The attestation authority provides a standardized verification mechanism that can be applied across different VMs and hosting environments, reducing overall system complexity through reuse of the same cryptographic infrastructure and verification processes.
Solution Approach 2:
The patent uses cryptographic copying by creating attestation certificates that replicate the trust relationship. Instead of requiring direct verification of each hosting environment's physical security, the system creates cryptographic copies (certificates) of the integrity measurements that can be verified independently, simplifying the verification process while maintaining security assurance.
3Reliability
If users require physical access to verify resource integrity, then security assurance is improved, but cloud computing's remote access model and scalability deteriorate
Solution Approach 1:
The patent replaces the mechanical requirement for physical access with a cryptographic verification system. Instead of users needing to physically inspect hosting resources, the system uses cryptographic measurements and digital certificates to provide equivalent security assurance remotely, maintaining the cloud computing model while enhancing security verification capabilities.
Solution Approach 2:
The trusted third party acts as an intermediary that bridges the gap between physical resource integrity and remote user verification. This mediator collects cryptographic measurements from the hosting environment and provides verified attestation certificates to users, enabling security assurance without requiring physical presence or direct access to the underlying infrastructure.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Approaches to enable the configuration of computing resources for executing virtual machines on behalf of users to be cryptographically attested to or verified. When a user requests a virtual machine to be provisioned, an operator of the virtualized computing environment can initiate a two phase launch of the virtual machine. In the first phase, the operator provisions the virtual machine on a host computing device and obtains cryptographic measurements of the software and/or hardware resources on the host computing device. The operator may then provide those cryptographic measurements to the user that requested the virtual machine. If the user approves the cryptographic measurements, the operator may proceed with the second phase and actually launch the virtual machine on the host. In some cases, operator may compare the cryptographic measurements to a list of approved measurements to determine whether the host computing device is acceptable for hosting the virtual machine.