IP Library Granted Patent US 12,309,294
Granted Patent B2
US 12,309,294 · App. 17/728,579 · Granted May 20, 2025

Clustered virtual trusted platform module domain services system

Inventors: Jeroen Mackenbach (Roosendaal, NL); Anantha K Boyapalle (Cedar Park, TX); John Henry Terpstra (Austin, TX)
Assignee: Dell Products L.P.
H04L9/3263H04L9/0877H04L9/0897H04L9/3234
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,294
App. No.
17/728,579
Granted
May 20, 2025
Kind
B2
Abstract

An information handling system includes a virtual trusted platform module (TPM) consumer associated with a virtual machine. The virtual TPM (vTPM) consumer may consume TPM services from a clustered vTPM domain service and determine the connection information of the vTPM domain service. The vTPM consumer transmits a connection request for a TPM operation request to the vTPM domain service, wherein the connection request includes a payload in addition to the connection information. The consumer may also receive a response associated with the TPM operation request from the vTPM domain service.

Claims (33)

1. An information handling system, comprising:

a trusted platform module (TPM); and

a virtual TPM (vTPM) domain service that is further configured with at least two TPM servers providing a root of trust that is cross-signed by each one of the at least two TPM servers, the vTPM domain service is configured to:

receive a connection request for a TPM operation from a TPM-vTPM, wherein the TPM-vTPM is configured to connect and consume TPM functionality of the vTPM domain service; and

transmit a response associated with the TPM operation to the TPM-vTPM.

2. The information handling system of claim 1 , wherein the TPM operation is performed by a vTPM instance linked with a virtual machine that is associated with the TPM-vTPM.

3. The information handling system of claim 1 , wherein the connection request is to consume an application programming interface published by the vTPM domain service.

4. The information handling system of claim 3 , wherein the application programming interface published by the vTPM domain service comports with TPM application programming interfaces published by a trusted computing group.

5. The information handling system of claim 3 , wherein the application programming interface published by the vTPM configured as a domain service supports a second application programming interface of a hardware TPM.

6. The information handling system of claim 1 , wherein the root of trust is provided to a virtual machine associated with the TPM-vTPM.

7. The information handling system of claim 1 , wherein the TPM is further configured to sign a vTPM certificate authority certificate.

8. The information handling system of claim 1 , wherein the at least two TPM servers are configured as a cluster.

9. The information handling system of claim 1 , wherein the vTPM domain service is clustered.

10. The information handling system of claim 1 , the vTPM domain service is further configured to generate a vTPM identifier to be used for the connection request.

11. The information handling system of claim 1 , the TPM operation is to migrate a virtual machine from the vTPM domain service to a second vTPM domain service.

12. An information handling system, comprising:

a processor configured to host a virtual machine;

a memory including a trusted platform module (TPM)—virtual trusted platform module (vTPM) associated with the virtual machine, wherein the TPM-vTPM is configured to consume services provided by a hardware TPM via a vTPM domain service, wherein the TPM-vTPM is configured to:

determine connection information of the vTPM domain service;

transmit a connection request for a TPM operation to the vTPM domain service, wherein the connection request includes the connection information and a root certificate that is cross-signed by each one of at least two TPM servers associated with the hardware TPM and the vTPM domain service; and

receive a response associated with the connection request for the TPM operation from the vTPM domain service.

13. The information handling system of claim 12 , wherein the connection information includes an internet protocol address associated with the vTPM domain service.

14. The information handling system of claim 12 , further comprising determining an identifier associated with the vTPM domain service.

15. The information handling system of claim 12 , wherein the root certificate is a public key infrastructure certificate that was retrieved from the vTPM domain service prior to the TPM operation.

16. The information handling system of claim 12 , wherein the vTPM domain service verifies that a status of the connection request is a success prior to performing the TPM operation.

17. A method comprising:

determining, by a processor, connection information of a virtual trusted platform module (vTPM) domain service;

determining an identifier of the vTPM domain service;

transmitting, by a trusted platform module (TPM)-vTPM a connection request for a TPM operation to the vTPM domain service, wherein the connection request includes the connection information and a root certificate that is cross-signed by each one of at least two TPM servers associated with a hardware TPM and the vTPM domain service; and

receiving a response associated with the TPM operation from the vTPM domain service.

18. The method of claim 17 , wherein the connection information is an internet protocol address of the vTPM domain service.

19. The method of claim 17 , wherein the root certificate is a public key infrastructure certificate that was retrieved from the vTPM domain service prior to the TPM operation.

20. The method of claim 17 , wherein the vTPM domain service verifies that a status of the connection request is a success prior to performing the TPM operation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2022
From: MACKENBACH, JEROEN; BOYAPALLE, ANANTHA K; TERPSTRA, JOHN HENRY
To: DELL PRODUCTS L.P.
Reel/Frame 059701/0083 →
Continuity (1)
Related Publication 20230344646A1 · Oct 26, 2023
References Cited (16)
US 8359386B2 · Mohrmann · 2013 [cited by examiner]
US 9846640B2 · Boyapalle et al. · 2017 [cited by applicant]
US 11201785B1 · Kanevsky et al. · 2021 [cited by applicant]
US 20050138423A1 · Ranganathan · 2005 [cited by examiner]
US 20050246552A1 · Bade · 2005 [cited by examiner]
US 20070079120A1 · Bade · 2007 [cited by examiner]
US 20080244569A1 · Challener · 2008 [cited by examiner]
US 20090165117A1 · Brutch · 2009 [cited by examiner]
US 20090210456A1 · Subramaniam · 2009 [cited by applicant]
US 20170075699A1 · Narayanan et al. · 2017 [cited by applicant]
US 20180167219A1 · Campagna · 2018 [cited by examiner]
US 20180234326A1 · Swierk et al. · 2018 [cited by applicant]
US 20220035909A1 · Boyapalle et al. · 2022 [cited by applicant]
US 20220129591A1 · K · 2022 [cited by examiner]
US 20220337481A1 · Guim Bernat · 2022 [cited by examiner]
CN 110325995A · 2019 [cited by examiner]