Virtual TPM Instance Communication via Dedicated Queues
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual trusted platform module (vTPM) implementations experience delays and reduced processing efficiency due to the need for transformation and processing by a security coordination processor, and require additional hardware, which increases costs and hardware volume.
Innovation Solution
The method generates vTPM instances for each virtual machine at exception level EL3 of a processor using ARM V8 architecture, with dedicated instance communication queues, allowing direct communication between virtual machines and vTPM instances without the need for hardware processors, thereby reducing delays and improving efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a security coordination processor is used to transform and process vTPM commands, then vTPM functionality can be provided to multiple VMs, but processing delay increases and efficiency decreases
Solution Approach 1:
The patent creates virtual copies of TPM functionality through vTPM instances in software, allowing multiple VMs to access TPM services without requiring a single physical security coordination processor. Each VM gets its own virtual TPM instance, eliminating the need for command transformation and processing through a shared security processor, thus reducing processing delay while maintaining functionality.
Solution Approach 2:
The patent replaces the mechanical hardware-based security coordination processor with a software-based vTPM implementation. By substituting the physical processing mechanism with virtualized software instances, the system eliminates the transformation and processing delays inherent in hardware-mediated communication, while still providing secure TPM functionality to multiple virtual machines.
2Reliability
If a hardware processor is disposed for vTPM implementation, then TPM security features can be provided, but hardware volume increases
Solution Approach 1:
The patent creates virtual replicas of TPM functionality through software-based vTPM instances, eliminating the need for additional physical hardware processors. Each virtual machine receives its own virtual TPM instance that provides full TPM security features without requiring dedicated hardware, thus maintaining reliability while reducing hardware volume.
Solution Approach 2:
The patent substitutes hardware-based TPM processors with software-based virtual TPM instances. This replacement eliminates the need for additional physical hardware components while preserving all TPM security functionalities, directly addressing the contradiction between providing reliable security features and minimizing hardware volume.
3Volume of moving object
If software-based vTPM instances are used instead of hardware processors, then hardware volume and costs are reduced, but direct communication between VM and vTPM must be established
Solution Approach 1:
The patent merges the vTPM instance with the virtual machine environment by establishing direct communication channels between them. The vTPM instances are integrated into the VM's address space and can be accessed directly without external intermediaries, simplifying the overall system architecture despite the software-based implementation.
Solution Approach 2:
The patent introduces communication queues as intermediaries that enable direct VM-to-vTPM interaction. These queues serve as simple buffers that facilitate communication without requiring complex processing or transformation, allowing the VM to directly access its dedicated vTPM instance while maintaining the software-based implementation benefits.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Embodiments of the present invention provide a virtual trusted platform module function implementation method and a management device, where the method is executed at an exception level EL3 of a processor that uses an ARM V8 architecture, and the method includes: generating, according to requirements of one or more VMs, one or more vTPM instances corresponding to each VM, and storing the generated one or more vTPM instances in preset secure space, where each vTPM instance has a dedicated instance communication queue for a VM corresponding to itself to use, and a physical address is allocated to each instance communication queue; and interacting with a VMM and the VM, so that the VM acquires a VM communication queue virtual address, in VM virtual address space, corresponding to a communication queue physical address of the vTPM instance, and the VM communicates with a vTPM instance communication queue by using the VM communication queue virtual address, thereby reducing a delay and improving processing efficiency.