IP Library Granted Patent US 8,953,806
Granted Patent B2
US 8,953,806 · App. 14/039,440 · Granted Feb 10, 2015

Method and apparatus for remotely provisioning software-based security coprocessors

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,953,806
App. No.
14/039,440
Granted
Feb 10, 2015
Kind
B2
Abstract

A virtual security coprocessor is created in a first processing system. The virtual security coprocessor is then transferred to a second processing system, for use by the second processing system. For instance, the second processing system may use the virtual security coprocessor to provide attestation for the second processing system. In an alternative embodiment, a virtual security coprocessor from a first processing system is received at a second processing system. After receiving the virtual security coprocessor from the first processing system, the second processing system uses the virtual security coprocessor. Other embodiments are described and claimed.

Claims (35)

1. A non-transitory machine-readable storage medium including instructions that if executed cause a processing system to:

create a virtual trusted platform module for a first server of the processing system;

generate an endorsement key for the virtual trusted platform module, and store the endorsement key on the first server; and

migrate the virtual trusted platform module to a second server of the processing system for use by the second server;

wherein the instructions to migrate include instructions to move the endorsement key to the second server.

2. The medium of claim 1 , wherein the instructions if executed further cause the processing system to:

create the virtual trusted platform module in a partition of the first server.

3. The medium of claim 1 , wherein the instructions if executed further cause the processing system to:

migrate the virtual trusted platform module to a partition of the second server.

4. The medium of claim 1 , wherein the instructions if executed further cause the processing system to:

move additional system state of the virtual trusted platform module to the second server.

5. The medium of claim 2 , wherein the partition is a virtual machine.

6. The medium of claim 3 , wherein the partition is a virtual machine.

7. The medium of claim 2 , wherein the instructions that if executed cause a processing system to create a virtual trusted platform module further comprise instructions to configure the partition with virtual trusted platform capability.

8. A system comprising:

a first server and a second server;

first firmware on the first server to support creation of one or more virtual machines on the first server;

second firmware on the second server to support creation of one or more virtual machines on the second server;

logic to create a virtual trusted platform module for the first server, and to create an endorsement key for the virtual trusted platform module; and

logic to cause migration of the endorsement key and other system state of the virtual trusted platform module from the first server to the second server.

9. The system of claim 8 , further comprising a physical trusted platform module (TPM) coupled to the first server.

10. The system of claim 8 , further comprising a physical trusted platform module (TPM) coupled to the second server.

11. The system of claim 9 , wherein the first server is to use the physical TPM to support the virtual trusted platform module.

12. The system of claim 8 , wherein the logic to create a virtual trusted platform module further comprises logic to configure a partition with virtual trusted platform capability.

13. The system of claim 12 , wherein the partition is a virtual machine.

14. The system of claim 8 , wherein the logic to cause migration further comprises logic to cause migration of the endorsement key and other system state of the virtual trusted platform module from the first server to a partition of the second server.

15. The system of claim 14 , wherein the partition of the second server is a virtual machine.

16. A method comprising

creating a virtual trusted platform module for a first server of a processing system;

generating an endorsement key for the virtual trusted platform module, and storing the endorsement key on the first server; and

migrating the virtual trusted platform module to a second server of the processing system for use by the second server, and moving the endorsement key to the second server.

17. The method of claim 16 , further comprising creating the virtual trusted platform module in a partition of the first server, wherein the partition is a virtual machine.

18. The method of claim 17 , further comprising configuring the partition with virtual trusted platform capability.

19. The method of claim 16 , further comprising migrating the virtual trusted platform module to a partition of the second server, wherein the partition is a virtual machine.

20. The method of claim 19 , further comprising moving additional system state of the virtual trusted platform module to the second server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2022
From: INTEL CORPORATION
To: TAHOE RESEARCH, LTD.
Reel/Frame 061175/0176 →