IP Library Granted Patent US 7,484,091
Granted Patent B2
US 7,484,091 · App. 10/835,350 · Granted Jan 27, 2009

Method and system for providing a trusted platform module in a hypervisor environment

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,484,091
App. No.
10/835,350
Filed
Apr 29, 2004
Granted
Jan 27, 2009
Kind
B2
Art Unit
2132
USPC
713/164
Abstract

A method is presented for implementing a trusted computing environment within a data processing system. A hypervisor is initialized within the data processing system, and the hypervisor supervises a plurality of logical, partitionable, runtime environments within the data processing system. The hypervisor reserves a logical partition for a hypervisor-based trusted platform module (TPM) and presents the hypervisor-based trusted platform module to other logical partitions as a virtual device via a device interface. Each time that the hypervisor creates a logical partition within the data processing system, the hypervisor also instantiates a logical TPM within the reserved partition such that the logical TPM is anchored to the hypervisor-based TPM. The hypervisor manages multiple logical TPM's within the reserved partition such that each logical TPM is uniquely associated with a logical partition.

Claims (13)

1. A method for implementing a trusted computing environment within a data processing system, the method comprising:

initializing a hypervisor within the data processing system, wherein the hypervisor supervises a plurality of logical, partitionable, runtime environments within the data processing system;

reserving a logical partition for a hypervisor-based trusted platform module (TPM) which provides integrity measurements for a software state of the data processing system;

presenting the hypervisor-based trusted platform module to logical partitions as a virtual device via a device interface;

creating by the hypervisor multiple logical partitions within the data processing system;

instantiating multiple logical TPM's within the reserved partition, wherein the logical TPM's are anchored to the hypervisor-based TPM; and

managing the multiple logical TPM's within the reserved partition such that each logical TPM is uniquely associated with a logical partition.

2. The method of claim 1 further comprising:

receiving from a TPM device driver in one of the logical partitions a trusted platform module functional request on an input queue of the device interface; and

transferring by the hypervisor the queued TPM functional request to the hypervisor-based TPM.

3. The method of claim 1 further comprising:

receiving from the hypervisor-based TPM a trusted platform module functional response on an output queue of the device interface; and

transferring by the hypervisor the queued TPM functional response to the a TPM device driver in one of the logical partitions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2004
From: BADE, STEVEN A.; CATHERMAN, RYAN CHARLES; HOFF, JAMES PATRICK; KELLEY, NIA LETISE; RATLIFF, EMILY JANE
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 014930/0549 →
Continuity (1)
Related Publication 20050246521A1 · Nov 3, 2005