发明名称 Trusted Computing Base Evidence Binding for a Migratable Virtual Machine
摘要 In an embodiment, at least one computer readable medium has instructions stored thereon for causing a system to cryptographically sign, at a secure platform services enclave (PSE) of a computing system and using a secure attestation key (SGX AK), a public portion of a trusted platform module attestation key (TPM AK) associated with a trusted computing base of a physical platform, to form a certified TPM AK public portion. Also included are instructions to store the certified TPM AK public portion in the PSE, and instructions to, responsive to an attestation request received from a requester at a virtual trusted platform module (vTPM) associated with a virtual machine (VM) that has migrated onto the physical platform, provide to the requester the certified TPM AK public portion stored in the PSE. Other embodiments are described and claimed.
申请公布号 US2016149912(A1) 申请公布日期 2016.05.26
申请号 US201414554467 申请日期 2014.11.26
申请人 Intel Corporation 发明人 Scott-Nash Mark E.;Dasari Annapurna;Wiseman Willard M.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. At least one computer readable medium having instructions stored thereon for causing a system to: cryptographically sign, at a secure platform services enclave (PSE) of a computing system using a secure attestation key (SGX AK), a public portion of a trusted platform module attestation key (TPM AK) that is associated with a trusted computing base of a physical platform, to form a certified TPM AK public portion; store the certified TPM AK public portion in the PSE; and responsive to an attestation request received from a requester at a virtual trusted platform module (vTPM) associated with a virtual machine (VM) that has migrated onto the physical platform, retrieve, by the vTPM, the certified TPM AK public portion stored in the PSE and provide, by the vTPM, the certified TPM AK public portion to the requester.
地址 Santa Clara CA US