主权项 |
1. An apparatus for computing, comprising:
a processor; and memory coupled with the processor, with instructions stored therein, wherein the instructions are configured to be operated by the processor to cause the apparatus: provide a management VM (MVM) in a first secure enclave of the apparatus; provide a virtual machine trusted platform module (vTPM) for a guest virtual machine (VM) of the apparatus, the vTPM being provided in a second secure enclave of the apparatus different from the first secure enclave; receive, at the vTPM, a command to change a value stored in a platform configuration register (PCR) of the vTPM; receive, at the vTPM from the MVM through a secure channel, a modifier indicating that the command is allowed; and after receiving the modifier, change the value stored in the PCR. |