IP Library › Granted Patent US 12,602,496
Granted Patent B2
US 12,602,496 · App. 18/349,050 · Granted Apr 14, 2026

Commands communications

Inventors: Adrian Laurence Shaw (Bristol, GB); Remy Husson (Bristol, GB); Adrian John Baldwin (Bristol, GB); Joshua Serratelli Schiffman (Washington, DC); Christopher Ian Dalton (Bristol, GB)
Assignee: Hewlett-Packard Development Company, L.P.
G06F21/606G06F21/50H04L9/3234
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,602,496
App. No.
18/349,050
Granted
Apr 14, 2026
Kind
B2
Abstract

In an example, a hypervisor measuring the state of a protected virtual machine using a Trusted Platform Module (TPM) filter. Using the TPM filter, the system ensures an untrusted operating system attempting to access the TPM is secure, without having to trust the security of the operating system or the operating system's built in hypervisor.

Claims (29)

1 . A non-transitory computer-readable medium having instructions that, when executed by a processor of a computing device, cause the computing device to:

intercept, from an operating system of the computing device, a command that attempts to interact with a trusted platform module (TPM) of the computing device;

identify, from among a plurality of platform configuration registers in the TPM, a particular PCR that the command targets; and

block in response to determining that the particular PCR is assigned to a protected virtual application that executes within a virtual machine, the command from interacting with the TPM.

2 . The non-transitory computer-readable medium of claim 1 , wherein the instructions, when executed by the processor, cause the computing device to:

create a set of pate table mappings to protect memory-mapped I/O (MMIO) registers associated with input/output interfaces of the TPM.

3 . The non-transitory computer readable medium of claim 2 , wherein the instructions, when executed by the processor, cause the computing device to:

protect the set of memory-mapped I/O (MMIO) registers.

4 . The non-transitory computer-readable medium of claim 1 , wherein the instructions, when executed by the processor, cause the computing device to:

store, in the particular PCR upon determining that the particular PCR is assigned to the protected virtual application, a digest comprising identifying information of the virtual machine and a random number associated with the virtual machine.

5 . The non-transitory computer-readable medium of claim 4 , wherein the random number provides sequence for future logging events of the virtual machine.

6 . The non-transitory computer-readable medium of claim 4 , wherein the virtual machine decides to reveal the random number to an authorized remote party.

7 . The non-transitory computer-readable medium of claim 4 , wherein the digest is recorded in a Boot Log.

8 . The non-transitory computer-readable medium of claim 4 , wherein the digest is recorded in a Hypervisor Log.

9 . The non-transitory computer-readable medium of claim 1 , wherein the instructions, when executed by the processor, cause the computing device to:

redirect, upon intercepting the command, the command to physical memory residing outside the trusted platform module.

10 . The non-transitory computer-readable medium of claim 1 , wherein the instructions, when executed by the processor, cause the computing device to:

allow, in response to determining that the particular PCR is not assigned to the protected virtual application, the command to interact with the trusted platform module.

11 . The non-transitory computer-readable medium of claim 1 , wherein the trusted platform module is a hardware-based security module that provides cryptographic functions and storage of integrity measurements.

12 . The non-transitory computer-readable medium of claim 1 , wherein the computing device redirects, upon blocking the command, the command to a shadow page in memory separate from the TPM.

13 . The non-transitory computer-readable medium of claim 1 , wherein identifying the particular PCR comprises determining that the command includes a TPM2_PCR_Extend or TPM2_PCR_Event command targeting the particular PCR.

14 . The non-transitory computer-readable medium of claim 1 , wherein the computing device comprises a hypervisor.

15 . The non-transitory computer-readable medium of claim 14 , wherein the hypervisor is to intercept the command when directed to the particular PCR.

16 . The non-transitory computer-readable medium of claim 14 , wherein the hypervisor is to block the command from reaching the particular PCR.

17 . The non-transitory computer-readable medium of claim 16 , wherein the hypervisor is to block the command in response to determining that the particular PCR is one of a subset of the platform configuration registers (PCRs) designated as protected.

18 . The non-transitory computer-readable medium of claim 14 , wherein the hypervisor is to associate the particular PCR with the protected virtual application.

19 . The non-transitory computer-readable medium of claim 14 , wherein the hypervisor is to identify the particular PCR.

20 . The non-transitory computer-readable medium of claim 14 , wherein the hypervisor is to assign the particular PCR to the protected virtual application.

21 . The non-transitory computer-readable medium of claim 14 , wherein the hypervisor is to manage execution of the virtual machine.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2023
From: SHAW, ADRIAN LAURENCE; HUSSON, REMY; BALDWIN, ADRIAN JOHN; DALTON, CHRISTOPHER IAN
To: HP UK DEVELOPMENT LIMITED
Reel/Frame 064703/0132 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2023
From: SCHIFFMAN, JOSHUA SERRATELLI
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 064703/0191 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2023
From: HP UK DEVELOPMENT LIMITED
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 064703/0242 →
Continuity (1)
Related Publication 20250013763A1 · Jan 9, 2025
References Cited (24)
US 7840801B2 · Berger et al. · 2010 [cited by applicant]
US 8776043B1 · Thimsen et al. · 2014 [cited by applicant]
US 8813233B1 · Wilson et al. · 2014 [cited by applicant]
US 8862853B2 · Sahita et al. · 2014 [cited by applicant]
US 8918785B1 · Brandwine et al. · 2014 [cited by applicant]
US 9626512B1 · Brandwine et al. · 2017 [cited by applicant]
US 9667414B1 · Brandwine et al. · 2017 [cited by applicant]
US 9678773B1 · Wagner et al. · 2017 [cited by applicant]
US 9774612B2 · Brandwine et al. · 2017 [cited by applicant]
US 10211985B1 · Brandwine et al. · 2019 [cited by applicant]
US 10243739B1 · Brandwine et al. · 2019 [cited by applicant]
US 20050234909A1 · Bade · 2005 [cited by examiner]
US 20060230401A1 · Grawrock · 2006 [cited by examiner]
US 20080288783A1 · Jansen · 2008 [cited by examiner]
US 20090055641A1 · Smith · 2009 [cited by examiner]
US 20090070598A1 · Cromer · 2009 [cited by examiner]
US 20090172328A1 · Sahita · 2009 [cited by examiner]
US 20090199002A1 · Erickson · 2009 [cited by examiner]
US 20090307487A1 · Movva · 2009 [cited by examiner]
US 20140068276A1 · Imamoto · 2014 [cited by examiner]
US 20140075522A1 · Paris et al. · 2014 [cited by applicant]
US 20170249483A1 · Kawazu · 2017 [cited by examiner]
CN 112364343A · 2021 [cited by examiner]
EP 3217310A1 · 2017 [cited by applicant]