Virtual TPM Instance Communication via Dedicated Queues

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual trusted platform module (vTPM) implementations experience delays and reduced processing efficiency due to the need for transformation and processing by a security coordination processor, and require additional hardware, which increases costs and hardware volume.

Innovation Solution

The method generates vTPM instances for each virtual machine at exception level EL3 of a processor using ARM V8 architecture, with dedicated instance communication queues, allowing direct communication between virtual machines and vTPM instances without the need for hardware processors, thereby reducing delays and improving efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a security coordination processor is used to transform and process vTPM commands, then vTPM functionality can be provided to multiple VMs, but processing delay increases and efficiency decreases

Engineering Contradiction:
ImprovevTPM functionality provision to multiple VMsVSAvoidprocessing delay
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent creates virtual copies of TPM functionality through vTPM instances in software, allowing multiple VMs to access TPM services without requiring a single physical security coordination processor. Each VM gets its own virtual TPM instance, eliminating the need for command transformation and processing through a shared security processor, thus reducing processing delay while maintaining functionality.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical hardware-based security coordination processor with a software-based vTPM implementation. By substituting the physical processing mechanism with virtualized software instances, the system eliminates the transformation and processing delays inherent in hardware-mediated communication, while still providing secure TPM functionality to multiple virtual machines.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a hardware processor is disposed for vTPM implementation, then TPM security features can be provided, but hardware volume increases

Engineering Contradiction:
ImproveTPM security featuresVSAvoidhardware volume
Core Design Contradiction:
ReliabilityVSVolume of moving object

Solution Approach 1:

The patent creates virtual replicas of TPM functionality through software-based vTPM instances, eliminating the need for additional physical hardware processors. Each virtual machine receives its own virtual TPM instance that provides full TPM security features without requiring dedicated hardware, thus maintaining reliability while reducing hardware volume.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes hardware-based TPM processors with software-based virtual TPM instances. This replacement eliminates the need for additional physical hardware components while preserving all TPM security functionalities, directly addressing the contradiction between providing reliable security features and minimizing hardware volume.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Volume of moving object

If software-based vTPM instances are used instead of hardware processors, then hardware volume and costs are reduced, but direct communication between VM and vTPM must be established

Engineering Contradiction:
Improvehardware volumeVSAvoidcommunication setup complexity
Core Design Contradiction:
Volume of moving objectVSDevice complexity

Solution Approach 1:

The patent merges the vTPM instance with the virtual machine environment by establishing direct communication channels between them. The vTPM instances are integrated into the VM's address space and can be accessed directly without external intermediaries, simplifying the overall system architecture despite the software-based implementation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces communication queues as intermediaries that enable direct VM-to-vTPM interaction. These queues serve as simple buffers that facilitate communication without requiring complex processing or transformation, allowing the VM to directly access its dedicated vTPM instance while maintaining the software-based implementation benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3139268B1Virtual trusted platform module function realization method and management device
Publication Date: 2021.09.15 HUAWEI TECH CO LTD
  • EP3139268B1 patent drawingFigure 1~2
  • EP3139268B1 patent drawingFigure 3
  • EP3139268B1 patent drawingFigure 4

AI summary

Embodiments of the present invention provide a virtual trusted platform module function implementation method and a management device, where the method is executed at an exception level EL3 of a processor that uses an ARM V8 architecture, and the method includes: generating, according to requirements of one or more VMs, one or more vTPM instances corresponding to each VM, and storing the generated one or more vTPM instances in preset secure space, where each vTPM instance has a dedicated instance communication queue for a VM corresponding to itself to use, and a physical address is allocated to each instance communication queue; and interacting with a VMM and the VM, so that the VM acquires a VM communication queue virtual address, in VM virtual address space, corresponding to a communication queue physical address of the vTPM instance, and the VM communicates with a vTPM instance communication queue by using the VM communication queue virtual address, thereby reducing a delay and improving processing efficiency.