Pre-boot Authentication for Virtual Machines Using vTPM Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information processing systems face challenges in implementing cloud infrastructure, particularly in providing seamless and secure authentication for virtual machines, especially in nested virtualization environments, where users must repeatedly provide credentials for each VM, leading to inefficiencies and security vulnerabilities.

Innovation Solution

The implementation of pre-boot authentication using credentials stored in virtual trusted platform modules (vTPMs), which securely store user credentials for single sign-on (SSO) authentication, allowing automatic login to guest operating systems of virtual machines without user intervention on subsequent boots.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If users manually provide credentials for each virtual machine, then authentication security can be maintained, but user efficiency and productivity deteriorate due to repeated credential entry

Engineering Contradiction:
Improveuser efficiencyVSAvoidauthentication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system enables self-service authentication by storing credentials in the vTPM and automatically retrieving them during pre-boot authentication, eliminating the need for users to manually enter credentials for each VM while maintaining security through hardware-backed credential storage

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Credentials are pre-stored in the virtual trusted platform module before VM execution, allowing the authentication process to automatically retrieve and use these credentials during pre-boot authentication without requiring user intervention at the time of access

Inventive Principle:
Principle #10Preliminary action

2Reliability

If credentials are stored in virtual trusted platform modules for automatic login, then authentication security and user experience improve, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The vTPM acts as an intermediary component that securely stores credentials and interfaces with the pre-boot authentication software, providing a standardized mechanism that works across different VM platforms without requiring changes to the underlying hypervisor or guest OS authentication systems

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If manual authentication is used for each virtual machine, then system complexity remains low, but productivity and user experience worsen due to repeated credential entry

Engineering Contradiction:
Improvesystem complexityVSAvoiduser efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system merges the authentication credential storage and retrieval functions into the pre-boot authentication process itself, combining what would otherwise be separate operations (credential storage, credential retrieval, and authentication) into a unified automated flow that occurs during VM initialization

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11829482B2Pre-boot authentication for virtual machines using credentials stored in virtual trusted platform modules
Publication Date: 2023.11.28 DELL PROD LP
  • US11829482B2 patent drawing
  • US11829482B2 patent drawing
  • US11829482B2 patent drawing

AI summary

An apparatus comprises a processing device configured to receive, at a host operating system of a virtual machine host, a request to execute a virtual machine and to obtain, from a virtual trusted platform module running on the virtual machine host, credentials for logging in to a guest operating system of the virtual machine. The processing device is further configured to provide, to pre-boot authentication software associated with the virtual machine, the credentials obtained from the virtual trusted platform module, and to automatically log in to the guest operating system of the virtual machine utilizing the pre-boot authentication software and the provided credentials.