发明名称 ROOTS-OF-TRUST FOR MEASUREMENT OF VIRTUAL MACHINES
摘要 Embodiments of techniques and systems associated with roots-of-trust (RTMs) for measurement of virtual machines (VMs) are disclosed. In some embodiments, a computing platform may provide a virtual machine RTM (vRTM) in a first secure enclave of the computing platform. The computing platform may be configured to perform an integrity measurement of the first secure enclave. The computing platform may provide a virtual machine trusted platform module (vTPM), for a guest VM, outside the first secure enclave of the computing platform. The computing platform may initiate a chain of integrity measurements between the vRTM and a resource of the guest VM. Other embodiments may be described and/or claimed.
申请公布号 US2015286582(A1) 申请公布日期 2015.10.08
申请号 US201514725903 申请日期 2015.05.29
申请人 INTEL CORPORATION 发明人 Scott-Nash Mark E.
分类号 G06F12/14;G06F9/455;G06F21/64 主分类号 G06F12/14
代理机构 代理人
主权项 1. An apparatus for computing, comprising: a processor; and memory coupled with the processor, with instructions stored therein, wherein the instructions are configured to be operated by the processor to cause the apparatus to: provide a management virtual machine (MVM) in a first secure enclave of the apparatus;provide a virtual machine trusted platform module (vTPM) for a guest virtual machine (VM) of the apparatus, the vTPM being provided in a second secure enclave of the apparatus different from the first secure enclave;receive, at the vTPM, a command to change a value stored in a platform configuration register (PCR) of the vTPM;receive, at the vTPM from the MVM through a secure channel, a modifier indicating that the command is allowed; andafter receiving the modifier, change the value stored in the PCR.
地址 SANTA CLARA CA US