IP Library Granted Patent US 10,848,474
Granted Patent B2
US 10,848,474 · App. 15/905,287 · Granted Nov 24, 2020

Firmware validation for encrypted virtual machines

Inventor: Michael Tsirkin (Lexington, MA)
Assignee: Red Hat, Inc.
H04L63/08G06F9/45558G06F21/44G06F21/51G06F21/572G06F21/575H04L9/088H04L9/3239H04L9/3247G06F21/62G06F2009/45562G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,848,474
App. No.
15/905,287
Granted
Nov 24, 2020
Kind
B2
Abstract

Systems and methods for firmware validation for encrypted virtual machines are disclosed. An example method may include receiving, by a processing device, a request to launch a virtual machine on a host machine; starting, on the host machine, the virtual machine comprising a first firmware and a second firmware; performing, using the first firmware, a first validation process to authenticate the virtual machine with a server of a guest owner; and performing, using the first firmware, a second validation process to validate the second firmware of the virtual machine. In some embodiments, the first firmware includes a shim firmware. In some embodiments, the second firmware includes BIOS or UEFI.

Claims (43)

1. A method comprising:

receiving, by a processing device, a request to launch a virtual machine on a host machine;

starting, on the host machine, the virtual machine comprising a first firmware;

performing, using the first firmware, a first validation process to authenticate the virtual machine with an external server;

responsive to loading, by the first firmware, a second firmware to the virtual machine, receiving, by the processing device, secret data associated with the virtual machine, wherein the secret data is encrypted with an encryption key; and

performing, using the first firmware, a second validation process to validate the second firmware of the virtual machine.

2. The method of claim 1 , wherein the secret data comprises data to be used to boot the virtual machine on the host machine.

3. The method of claim 1 , wherein the encryption key is inaccessible to a hypervisor managing the virtual machine.

4. The method of claim 1 , wherein the second firmware comprises at least one of BIOS (Basic Input/output System) or UEFI (United Extensible Firmware Interface).

5. The method of claim 1 , wherein performing the first validation process further comprises:

obtaining a measurement representative of a state of the virtual machine; and

transmitting the measurement to a guest owner.

6. The method of claim 5 , wherein the measurement comprises a hash of contents of a memory associated with the virtual machine.

7. The method of claim 1 , wherein performing the second validation process comprises determining whether the second firmware is signed by a predetermined entity.

8. The method of claim 1 , wherein performing the second validation process comprises determining whether the second firmware is signed using a predetermined key.

9. The method of claim 8 , wherein the first firmware comprises a public key, and wherein the predetermined key comprises a private key matching the public key.

10. A system comprising:

a memory; and

a processor operatively coupled to the memory, the processor to:

receive a request to launch a virtual machine on a host machine;

start, on the host machine, the virtual machine comprising a first firmware;

perform, using the first firmware, a first validation process to authenticate the virtual machine with an external server;

responsive to loading, by the first firmware, a second firmware to the virtual machine, receive, by the processor, secret data associated with the virtual machine, wherein the secret data is encrypted with an encryption key; and

perform, using the first firmware, a second validation process to validate the second firmware of the virtual machine.

11. The system of claim 10 , wherein the secret data comprises data to be used to boot the virtual machine on the host machine.

12. The system of claim 10 , wherein the second firmware comprises at least one of BIOS (Basic Input/output System) or UEFI (United Extensible Firmware Interface).

13. The system of claim 10 , wherein, to perform the first validation process, the processor is further to:

obtain a measurement representative of a state of the virtual machine; and

transmit the measurement to a guest owner.

14. The system of claim 13 , wherein the measurement comprises a hash of contents of a portion of the memory that is associated with the virtual machine.

15. The system of claim 10 , wherein, to perform the second validation process, the processor is further to determine whether the second firmware is signed by a predetermined entity.

16. A non-transitory machine-readable storage medium including instructions that, when accessed by a processing device, cause the processing device to:

receive a request to launch a virtual machine on a host machine;

start, on the host machine, the virtual machine comprising a first firmware;

perform, using the first firmware, a first validation process to authenticate the virtual machine with an external server;

responsive to loading, by the first firmware, a second firmw are to the virtual machine, receive, by the processing device, secret data associated with the virtual machine, wherein the secret data is encrypted with an encryption key; and

perform, using the first firmware, a second validation process to validate the second firmware of the virtual machine.

17. The non-transitory machine-readable storage medium of claim 16 , wherein the secret data comprises data to be used to boot the virtual machine on the host machine.

18. The non-transitory machine-readable storage medium of claim 16 , wherein the encryption key is inaccessible to a hypervisor managing the virtual machine.

19. The non-transitory machine-readable storage medium of claim 16 , wherein the second firmware comprises at least one of BIOS (Basic Input/output System) or UEFI (United Extensible Firmware Interface).

20. The non-transitory machine-readable storage medium of claim 16 , wherein to perform the first validation process, the processing device is further to:

obtain a measurement representative of a state of the virtual machine; and

transmit the measurement to a guest owner.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2018
From: TSIRKIN, MICHAEL
To: RED HAT, INC.
Reel/Frame 045843/0173 →
Continuity (1)
Related Publication 20190268318A1 · Aug 29, 2019