IP Library Granted Patent US 12,362,938
Granted Patent B2
US 12,362,938 · App. 17/395,053 · Granted Jul 15, 2025

Attestation of a secure guest

Inventors: Reinhard Theodor Buendgen (Baden-Wuerttemberg, DE); Jonathan D. Bradbury (Poughkeepsie, NY)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L9/3234
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,362,938
App. No.
17/395,053
Granted
Jul 15, 2025
Kind
B2
Abstract

A trusted execution environment obtains an attestation request. The attestation request includes at least an attestation key. Based on obtaining the attestation request, one or more integrity measurements are computed, and the computing uses at least the attestation key. The one or more integrity measurements are provided to an entity, and the one or more integrity measurements are to be used to verify that a secure guest has been started using a selected secure guest image and selected secure guest metadata.

Claims (45)

1. A computer program product for facilitating processing within a computing environment, the computer program product comprising:

one or more computer readable storage media and program instructions collectively stored on the one or more computer readable storage media to perform a method comprising:

obtaining, by a trusted execution environment, an attestation request to be used to verify that a secure guest that is running is a particular secure guest, the attestation request including select local data specific to the secure guest and an attestation request structure including one or more entries, wherein an entry of the one or more entries includes an attestation key, and wherein the select local data specific to the secure guest includes session information of a session to be used to connect to the secure guest to submit to the secure guest the attestation request structure to be used in the attestation request;

computing, based on obtaining the attestation request, one or more integrity measurements, the computing using at least the attestation key to compute the one or more integrity measurements representing, at least, the select local data specific to the secure guest; and

providing the one or more integrity measurements to an entity, the one or more integrity measurements to be used to verify that the secure guest is a correct secure guest that has been started using a particular secure guest image and selected secure guest metadata particular to the secure guest.

2. The computer program product of claim 1 , wherein the attestation request structure is integrity protected, the entry includes a protection indication for the attestation key, and wherein the attestation key is maintained in an encrypted portion of the attestation request structure.

3. The computer program product of claim 2 , wherein the attestation request structure is exclusively interpretable by the trusted execution environment, and wherein the method further comprises:

verifying integrity protection of the attestation request structure; and

decrypting, by the trusted execution environment based on successfully verifying the integrity protection of the attestation request structure, the encrypted portion of the attestation request structure to obtain the attestation key to be used in computing the one or more integrity measurements.

4. The computer program product of claim 1 , wherein the providing the one or more integrity measurements further comprises providing select information of the trusted execution environment to be used to verify the secure guest, the select information including runtime data of the secure guest.

5. The computer program product of claim 1 , wherein the one or more integrity measurements includes a computed verification code computed based on at least an image of the secure guest and one or more secure guest metadata.

6. The computer program product of claim 5 , wherein the computed verification code is further computed based on runtime data of the secure guest.

7. The computer program product of claim 6 , wherein the runtime data of the secure guest comprises a unique identification of a running instance of the secure guest that issued the attestation request.

8. The computer program product of claim 6 , wherein the computed verification code is further computed based on the select local data specific to the secure guest.

9. The computer program product of claim 1 , wherein the attestation request is obtained from the secure guest via a non-interceptable call to the trusted execution environment, and wherein the entity is the secure guest and the providing further includes providing to the secure guest runtime data of the secure guest, wherein the runtime data of the secure guest, the one or more integrity measurements and the select local data specific to the secure guest are to be further provided to a requesting entity to be used in verifying the secure guest.

10. The computer program product of claim 9 , wherein the select local data specific to the secure guest includes the session information of the session used by the requesting entity to connect to the secure guest to submit to the secure guest the attestation request structure to be used in the attestation request.

11. The computer program product of claim 1 , wherein the attestation request is obtained by the trusted execution environment via a non-interceptable call from the secure guest, the non-interceptable call including the attestation request structure that includes the attestation key.

12. A computer system for facilitating processing within a computing environment, the computer system comprising:

a memory; and

at least one processor in communication with the memory, wherein the computer system is configured to perform a method, said method comprising:

obtaining, by a trusted execution environment, an attestation request to be used to verify that a secure guest that is running is a particular secure guest, the attestation request including select local data specific to the secure guest and an attestation request structure including one or more entries, wherein an entry of the one or more entries includes an attestation key, and wherein the select local data specific to the secure guest includes session information of a session to be used to connect to the secure guest to submit to the secure guest the attestation request structure to be used in the attestation request;

computing, based on obtaining the attestation request, one or more integrity measurements, the computing using at least the attestation key to compute the one or more integrity measurements representing, at least, the select local data specific to the secure guest; and

providing the one or more integrity measurements to an entity, the one or more integrity measurements to be used to verify that the secure guest is a correct secure guest that has been started using a particular secure guest image and selected secure guest metadata particular to the secure guest.

13. The computer system of claim 12 , wherein the attestation request structure is integrity protected, the entry includes a protection indication for the attestation key, and wherein the attestation key is maintained in an encrypted portion of the attestation request structure.

14. The computer system of claim 12 , wherein the providing the one or more integrity measurements further comprises providing select information of the trusted execution environment to be used to verify the secure guest, the select information including runtime data of the secure guest.

15. The computer system of claim 14 , wherein the runtime data of the secure guest comprises a unique identification of a running instance of the secure guest that issued the attestation request.

16. The computer system of claim 12 , wherein the attestation request is obtained from the secure guest via a non-interceptable call to the trusted execution environment, and wherein the entity is the secure guest and the providing further includes providing to the secure guest runtime data of the secure guest, wherein the runtime data of the secure guest, the one or more integrity measurements and the select local data specific to the secure guest are to be further provided to a requesting entity to be used in verifying the secure guest.

17. A computer-implemented method of facilitating processing within a computing environment, the computer-implemented method comprising:

obtaining, by a trusted execution environment of a hardware processor, an attestation request to be used to verify that a secure guest that is running is a particular secure guest, the attestation request including select local data specific to the secure guest and an attestation request structure including one or more entries, wherein an entry of the one or more entries includes an attestation key, and wherein the select local data specific to the secure guest includes session information of a session to be used to connect to the secure guest to submit to the secure guest the attestation request structure to be used in the attestation request;

computing, based on obtaining the attestation request, one or more integrity measurements, the computing using at least the attestation key to compute the one or more integrity measurements representing, at least, the select local data specific to the secure guest; and

providing the one or more integrity measurements to an entity, the one or more integrity measurements to be used to verify that the secure guest is a correct secure guest that has been started using a particular secure guest image and selected secure guest metadata particular to the secure guest.

18. The computer-implemented method of claim 17 , wherein the attestation request structure is integrity protected, the entry includes a protection indication for the attestation key, and wherein the attestation key is maintained in an encrypted portion of the attestation request structure.

19. The computer-implemented method of claim 17 , wherein the providing the one or more integrity measurements further comprises providing select information of the trusted execution environment to be used to verify the secure guest, the select information including runtime data of the secure guest.

20. The computer-implemented method of claim 17 , wherein the attestation request is obtained from the secure guest via a non-interceptable call to the trusted execution environment, and wherein the entity is the secure guest and the providing further includes providing to the secure guest runtime data of the secure guest, wherein the runtime data of the secure guest, the one or more integrity measurements and the local data specific to the secure guest are to be further provided to a requesting entity to be used in verifying the secure guest.

21. The computer-implemented method of claim 17 , wherein the attestation request structure includes a plurality of entries, and wherein multiple entries of the plurality of entries include contents and protection indications of the contents.

22. The computer program product of claim 4 , wherein the runtime data of the secure guest comprises a unique identification of a running instance of the secure guest that issued the attestation request.

23. The computer program product of claim 1 , wherein the attestation request structure includes a plurality of entries, and wherein multiple entries of the plurality of entries include contents and protection indications of the contents.

24. The computer program product of claim 1 , wherein the one or more integrity measurements represent, at least, a combination of an image of the secure guest and the select local data specific to the secure guest.

25. A computer program product for facilitating processing within a computing environment, the computer program product comprising:

one or more computer readable storage media and program instructions collectively stored on the one or more computer readable storage media to perform a method comprising:

obtaining, by a trusted execution environment, an attestation request to be used to verify that a secure guest that is running is a particular secure guest, the attestation request including select local data specific to the secure guest and an attestation request structure including one or more entries, wherein an entry of the one or more entries includes an attestation key, and wherein the select local data specific to the secure guest includes session information of a session to be used to connect to the secure guest;

verifying integrity protection of the attestation request structure;

decrypting, by the trusted execution environment based on successfully verifying the integrity protection of the attestation request structure, an encrypted portion of the attestation request structure to obtain the attestation key to be used in computing one or more integrity measurements;

computing, based on obtaining the attestation request, the one or more integrity measurements, the computing using at least the attestation key to compute the one or more integrity measurements representing, at least, the select local data specific to the secure guest; and

providing the one or more integrity measurements to an entity, the one or more integrity measurements to be used to verify that the secure guest is a correct secure guest that has been started using a particular secure guest image and selected secure guest metadata particular to the secure guest.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2021
From: BUENDGEN, REINHARD THEODOR; BRADBURY, JONATHAN D.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 057097/0100 →
Continuity (1)
Related Publication 20230044731A1 · Feb 9, 2023
References Cited (58)
US 9477486B2 · Raj et al. · 2016 [cited by applicant]
US 10075440B1 · Arunkumar et al. · 2018 [cited by applicant]
US 10338957B2 · Scarlata et al. · 2019 [cited by applicant]
US 10341116B2 · Liu et al. · 2019 [cited by applicant]
US 10379894B1 · Cruz Oliveira Queiros · 2019 [cited by examiner]
US 10397005B2 · Brickell · 2019 [cited by applicant]
US 10621350B2 · Novak et al. · 2020 [cited by applicant]
US 10880097B2 · Scarlata et al. · 2020 [cited by applicant]
US 10977362B2 · Yu et al. · 2021 [cited by applicant]
US 11164179B2 · Greiche · 2021 [cited by examiner]
US 20080046752A1 · Berger et al. · 2008 [cited by applicant]
US 20130097392A1 · Arges · 2013 [cited by examiner]
US 20130254798A1 · Kim · 2013 [cited by examiner]
US 20140108726A1 · Laurich et al. · 2014 [cited by applicant]
US 20160366185A1 · Lee et al. · 2016 [cited by applicant]
US 20180004954A1 · Liguori · 2018 [cited by examiner]
US 20180109538A1 · Kumar et al. · 2018 [cited by applicant]
US 20190243950A1 · Soriente et al. · 2019 [cited by applicant]
US 20190278911A1 · Pappachan et al. · 2019 [cited by applicant]
US 20190311123A1 · Lal et al. · 2019 [cited by applicant]
US 20200026857A1 · Muller et al. · 2020 [cited by applicant]
US 20200076607A1 · Allen · 2020 [cited by applicant]
US 20200082091A1 · Areno et al. · 2020 [cited by applicant]
US 20200082097A1 · Areno et al. · 2020 [cited by applicant]
US 20200204370A1 · Wisniewski · 2020 [cited by examiner]
US 20200285746A1 · Buendgen · 2020 [cited by applicant]
US 20200349252A1 · Yu et al. · 2020 [cited by applicant]
US 20210011984A1 · Renke · 2021 [cited by examiner]
US 20210232709A1 · Buendgen · 2021 [cited by applicant]
US 20220019698A1 · Durham · 2022 [cited by examiner]
US 20220114249A1 · Grancharov · 2022 [cited by examiner]
US 20220138286A1 · Zage · 2022 [cited by examiner]
US 20220222098A1 · Srivastava et al. · 2022 [cited by applicant]
US 20220222099A1 · Srivastava · 2022 [cited by examiner]
US 20220222357A1 · Buendgen · 2022 [cited by applicant]
CN 101410848B · 2009 [cited by applicant]
CN 103905205B · 2014 [cited by applicant]
CN 103944729A · 2014 [cited by applicant]
CN 112784258A · 2021 [cited by applicant]
EP 2942729A1 · 2015 [cited by applicant]
TW 202036345A · 2020 [cited by applicant]
Yu, “Obtaining the Integrity of Your Virtual Machine in the Cloud”, 2011, IEEE,pp. 213-222 (Year: 2011). [cited by examiner]
Sev-Snp, “Strengthening VM isolation with integrity protection and more”, 2020, White Paper, pp. 3-20 (Year: 2020). [cited by examiner]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, PCT/EP2022/071774, Nov. 21, 2022, 13 pages. [cited by applicant]
Wang, Ziwang et al., TZ-MRAS: A Remote Attestation Scheme for the Mobile Terminal Based o ARM TrustZone, Hindawi Security and Communication Networks, vol. 2020, Article ID 1756130. Sep. 23, 2020, pp. 1-16. [cited by applicant]
Srivastava, Abhinav et al., “Trusted VM Snapshots in Untrusted Cloud Infrastructures,” Jan. 1, 2012, pp. 1-21. [cited by applicant]
AMD, “AMD Secure Encrypted Virtualization (SEV)”, printed Jan. 23, 2023, 5 pages, https://developer.amd.com/sev/. [cited by applicant]
Intel, “Confidential Computing—the emerging paradigm for protecting data in-use”, Sep. 22, 2020, 7 pages, <https://community.intel.com/t5/Blogs/Products-and-Solutions/Security/Confidential-Computing-the-emerging-paradig… [cited by applicant]
IBM, “IBM Secure Execution for Linux”, printed Jan. 30, 2023, 4 pages, <https://www.ibm.com/downloads/cas/0158MBWG>. [cited by applicant]
IBM, “z/Architecture—Principles of Operation,” IBM Publication No. SA22-7832-12, Thirteenth Edition, Sep. 2019, pp. Jan. 2000. [cited by applicant]
Mell, Peter and Tim Grance, “The NIST Definition of Cloud Computing,” National Institute of Standards and Technology, Information Technology Laboratory, Special Publication 800-145, Sep. 2011, pp. 1-7. [cited by applicant]
Sardar, Muhammad Usama et al., “Demystifying Attestation in Intel Trust Domain Extensions Via Formal Verification,” vol. 9, Jun. 15, 2021, pp. 83067-83079. [cited by applicant]
Ozga, Wojciech et al., “WELES: Policy-Driven Runtime Integrity Enforcement of Virtual Machines,” May 3, 2021, pp. 1-19. [cited by applicant]
Conti, Mauro et al., “RADIS: Remote Attestation of Distributed IT Services,” 6th IEEE International Conference on Software Defined Systems, 2019 (no further date information available), pp. 25-32. [cited by applicant]
Eckel, Michael et al., “Secure Attestation of Virtualized Environments,” IFIP International Federation for Information Processing 2020, 2020 (no further date information available), pp. 203-216. [cited by applicant]
EP Response to Rule 161, Application No. 22761128.2, dated Aug. 30, 2024, pp. 1-72. [cited by applicant]
Innovation, Science and Economic Development Canada, “Office Action,” Dec. 19, 2024, 6 Pages, CA Application No. 3217422. [cited by applicant]
Innovation, Science and Economic Development Canada, “Second Office Action,” May 26, 2025, 4 Pages, CA Application No. 3217422. [cited by applicant]