IP Library › Granted Patent US 12,271,469
Granted Patent B2
US 12,271,469 · App. 18/159,263 · Granted Apr 8, 2025

Extending secure guest metadata to bind the secure guest to a hardware security module

Inventors: Reinhard Theodor Buendgen (Tuebingen, DE); Jonathan D. Bradbury (Poughkeepsie, NY)
Assignee: International Business Machines Corporation
G06F21/53G06F21/31G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,271,469
App. No.
18/159,263
Granted
Apr 8, 2025
Kind
B2
Abstract

A method, system, and computer program product implement a three-factor authorization in a trusted computing environment. The method includes triggering, by a hypervisor, a start of a secure guest by passing control regarding an image of the secure guest and metadata of the secure guest to a trusted firmware, where the secure guest is designed to access a hardware security module (HSM). Upon a successful integrity check of the metadata of the secure guest by the trusted firmware, the secure guest is started using the hypervisor and any sensitive request from the secure guest to the HSM is blocked. The secure guest submits a request with a request structure including a third authorization secret and a characterization of a requested HSM to the trusted firmware. The method also includes binding each HSM protected key generated in the requested HSM in response to the request to the third authorization secret.

Claims (51)

1. A computer-implemented method for implementing a three-factor authorization in a trusted computing environment, the method comprising:

triggering, by a hypervisor, a start of a secure guest by passing control regarding an image of the secure guest and metadata of the secure guest to a trusted firmware, wherein the secure guest is designed to access a hardware security module;

upon a successful integrity check of the metadata of the secure guest by the trusted firmware:

starting the secure guest using the hypervisor; and

blocking any sensitive request from the secure guest to the hardware security module;

submitting, by the secure guest, a request comprising a request structure including a third authorization secret and a characterization of a requested hardware security module to the trusted firmware; and

binding, by the trusted firmware, each hardware security module protected key generated in the requested hardware security module in response to the request to the third authorization secret.

2. The computer-implemented method according to claim 1 , further comprising:

unblocking sensitive requests to the requested hardware security module from the secure guest that only operates on at least one of the each hardware security module protected key bound to the third authorization secret.

3. The computer-implemented method according to claim 1 , further comprising:

instructing, by the trusted firmware, the hardware security module to bind each key to be generated to the third authorization secret.

4. The computer-implemented method according to claim 1 , wherein the request structure is integrity protected and partially encrypted such that only the trusted firmware is enabled to decrypt the encrypted part of the request structure and integrity-check the request.

5. The computer-implemented method according to claim 4 , where the encrypted part of the request structure comprises the third authorization secret.

6. The computer-implemented method according to claim 1 , wherein the metadata of the secure guest comprises an extension secret, and the trusted firmware rejects every request that does not contain the extension secret.

7. The computer-implemented method according to claim 1 , wherein the secure guest submits the request to the trusted firmware via a direct firmware call, wherein the request structure and all sensitive cryptography requests target the hardware security module.

8. The computer-implemented method according to claim 1 , wherein each request to the hardware security module that comprises a hardware security module protected key is a sensitive request.

9. The computer-implemented method according to claim 1 , wherein each request that returns a result containing a hardware security module protected key is a sensitive request.

10. The computer-implemented method according to claim 1 wherein the metadata comprises integrity measures of the image.

11. The computer-implemented method according to claim 1 , wherein the metadata comprises security measures.

12. The computer-implemented method according to claim 1 , further comprising:

protecting, by the trusted firmware, the third authorization secret against access from any guest and the hypervisor.

13. The computer-implemented method according to claim 1 , further comprising, upon providing access to the hardware security module to an untrusted component:

instructing, by the trusted firmware, the hardware security module to no longer accept keys bound to the third authorization secret.

14. A system for implementing a three-factor authorization in a trusted computing environment, the system comprising:

one or more processors; and

a memory operationally coupled to the one or more processors, wherein the memory stores program portions which, when executed, enable the one or more processors to perform a method comprising:

triggering, by a hypervisor, a start of a secure guest by passing control regarding an image of the secure guest and metadata of the secure guest to a trusted firmware, wherein the secure guest is designed to access a hardware security module;

upon a successful integrity check of the metadata of the secure guest by the trusted firmware:

starting the secure guest using the hypervisor, and

blocking any sensitive request from the secure guest to the hardware security module;

submitting, by the secure guest, a request comprising a request structure including a third authorization secret and a characterization of a requested hardware security module to the trusted firmware; and

binding, by the trusted firmware, each hardware security module protected key generated in the requested hardware security module in response to the request to the third authorization secret.

15. The system of claim 14 , wherein the method further comprises:

unblocking sensitive requests to the requested hardware security module from the secure guest that only operates on at least one of the each hardware security module protected key bound to the third authorization secret.

16. The system of claim 14 , wherein the method further comprises:

instructing, by the trusted firmware, the hardware security module to bind each key to be generated to the third authorization secret.

17. The system of claim 14 , wherein the request structure is integrity protected and partially encrypted such that only the trusted firmware is enabled to decrypt the encrypted part of the request structure and integrity-check the request.

18. The system of claim 17 , where the encrypted part of the request structure comprises the third authorization secret.

19. The system of claim 14 , wherein the metadata of the secure guest comprises an extension secret.

20. The system of claim 14 , wherein the secure guest submits the request to the trusted firmware via a direct firmware call, wherein the request structure and all sensitive cryptography requests target to the hardware security module.

21. The system of claim 14 , wherein each request to the hardware security module that comprises a hardware security module protected key is sensitive.

22. The system of claim 14 , wherein each request that returns a result containing a hardware security system protected key is a sensitive request.

23. The system of claim 14 , wherein the metadata comprises integrity measures of the image.

24. The system of claim 14 , wherein the method further comprises protecting, by the trusted firmware, the third authorization secret against access from any guest and the hypervisor.

25. A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause a device to perform a method of implementing a three-factor authorization in a trusted computing environment, the method comprising:

triggering, by a hypervisor, a start of a secure guest by passing control regarding an image of the secure guest and metadata of the secure guest to a trusted firmware, wherein the secure guest is designed to access a hardware security module;

upon a successful integrity check of the metadata of the secure guest by the trusted firmware:

starting the secure guest using the hypervisor, and

blocking any sensitive request from the secure guest to the hardware security module;

submitting, by the secure guest, a request comprising a request structure including a third authorization secret and a characterization of a requested hardware security module to the trusted firmware; and

binding, by the trusted firmware, each hardware security module protected key generated in the requested hardware security module in response to the request to the third authorization secret.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2023
From: BUENDGEN, REINHARD THEODOR; BRADBURY, JONATHAN D.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062482/0280 →
Priority Claims (1)
GB 2217870 · Nov 29, 2022 · national
Continuity (1)
Related Publication 20240176870A1 · May 30, 2024
References Cited (19)
US 11023619B2 · Buendgen · 2021 [cited by applicant]
US 11475167B2 · Buendgen · 2022 [cited by applicant]
US 11500988B2 · Buendgen · 2022 [cited by applicant]
US 11533174B2 · Buendgen · 2022 [cited by applicant]
US 20160149877A1 · Kancharla · 2016 [cited by applicant]
US 20160241393A1 · Boenisch et al. · 2016 [cited by applicant]
US 20180212966A1 · Costa · 2018 [cited by examiner]
US 20200076607A1 · Allen · 2020 [cited by applicant]
US 20200089916A1 · Buendgen · 2020 [cited by applicant]
US 20200159940A1 · Werner · 2020 [cited by applicant]
US 20200285746A1 · Buendgen · 2020 [cited by applicant]
US 20200285748A1 · Buendgen · 2020 [cited by applicant]
US 20210232709A1 · Buendgen · 2021 [cited by applicant]
US 20210234681A1 · Buendgen · 2021 [cited by applicant]
US 20220108026A1 · Ortiz · 2022 [cited by examiner]
US 20220222357A1 · Buendgen · 2022 [cited by applicant]
US 20230195490A1 · Gomes · 2023 [cited by examiner]
PCT/EP2023/082297, Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration, Date of Mailing: Feb. 7, 2024, 12 pages. [cited by applicant]
Intellectual Property Office, “Patents Act 1977: Search Report under Section 17(5)”, May 17, 2023, 3 pages, GB Application No. 2217870.1. [cited by applicant]