IP Library › Granted Patent US 9,184,918
Granted Patent B2
US 9,184,918 · App. 14/305,611 · Granted Nov 10, 2015

Trusted hardware for attesting to authenticity in a cloud environment

Inventors: Bradford Thomas Spiers (Bedminster, NJ); Miroslav Halas (Charlottesville, VA); Richard A. Schimmel (Glenmont, NY)
Assignee: Bank of America Corporation
H04L9/3247G06F9/45533G06F21/575H04L9/28H04L9/3234H04L63/0218H04L63/0281H04L63/0428H04L63/08H04L63/0876H04L63/1441H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,184,918
App. No.
14/305,611
Filed
Jun 16, 2014
Granted
Nov 10, 2015
Kind
B2
Art Unit
2436
USPC
726/7
Abstract

Apparatuses, computer readable media, methods, and systems are described for storing a first measurement of a virtualization platform, storing a second measurement of a measured virtual machine, generating a quote using a key, wherein the quote is based on the first measurement and the second measurement, and providing the quote for attesting to authenticity of the virtualization platform and of the measured virtual machine. In a further example, the quote may be generated based on a third measurement of a secure tunnel.

Claims (37)

1. An apparatus comprising:

at least one processor; and

at least one memory storing computer executable instructions that, when executed, cause the apparatus at least to:

store, in a trusted protection module (TPM), a first measurement of a virtualization platform;

store, in the TPM, a second measurement of a measured virtual machine;

generate a TPM quote using a key, wherein the TPM quote is based on the first measurement and the second measurement; and

provide the TPM quote for attesting to authenticity of the virtualization platform and of the measured virtual machine,

wherein the TPM quote is uniquely tied to an individual piece of hardware of physical infrastructure hardware on which the virtualization platform runs, and a cloud provider creates an association between the TPM and the generated TPM quote, the association between the TPM and the generated TPM quote identifying to at least one tenant of the cloud provider the individual piece of hardware of the physical infrastructure hardware on which the virtualization platform runs.

2. The apparatus of claim 1 , wherein the executable instructions, when executed, further cause the apparatus to store a third measurement of a secure channel, wherein the TPM quote is generated based on the third measurement.

3. The apparatus of claim 1 , wherein the first measurement comprises a measurement of the physical infrastructure hardware on which the virtualization platform runs.

4. The apparatus of claim 1 , wherein the TPM quote is generated based on a nonce, wherein the nonce comprises an authentication code.

5. The apparatus of claim 1 , wherein the executable instructions, when executed, further cause the apparatus to process a dedication request that dedicates the apparatus to the measured virtual machine.

6. The apparatus of claim 5 , wherein the executable instructions, when executed, further cause the apparatus to process a release request permitting the apparatus to make a measurement of a second virtual machine different from the measured virtual machine.

7. The apparatus of claim 1 , wherein the second measurement comprises a measurement of at least one of a binary, configuration information, a cryptographic key, a digital certificate, a driver, and a module.

8. A method comprising:

storing, in a trusted protection module (TPM), a first measurement of a virtualization platform;

storing, in the TPM, a second measurement of a measured virtual machine;

generating, by a processor, a TPM quote using a key, wherein the TPM quote is based on the first measurement and the second measurement; and

providing the TPM quote for attesting to authenticity of the virtualization platform and of the measured virtual machine,

wherein the TPM quote is uniquely tied to an individual piece of hardware of physical infrastructure hardware on which the virtualization platform runs, and a cloud provider creates an association between the TPM and the generated TPM quote, the association between the TPM and the generated TPM quote identifying to at least one tenant of the cloud provider the individual piece of hardware of the physical infrastructure hardware on which the virtualization platform runs.

9. The method of claim 8 , further comprising storing a third measurement of a secure tunnel, wherein the TPM quote is generated based on the third measurement.

10. The method of claim 8 , wherein the first measurement comprises a measurement of the physical infrastructure hardware on which the virtualization platform runs.

11. The method of claim 8 , wherein the TPM quote is generated based on a nonce, wherein the nonce comprises an authentication code.

12. The method of claim 8 , further comprising processing a dedication request that dedicates trusted hardware to the measured virtual machine.

13. The method of claim 12 , further comprising processing a release request permitting the trusted module to make a measurement of a second virtual machine different from the measured virtual machine.

14. The method of claim 8 , wherein the second measurement comprises a measurement of at least one of a binary, configuration information, a cryptographic key, a digital certificate, a driver, and a module.

15. The method of claim 8 , wherein the association between the TPM and the generated TPM quote is maintained in an inventory of valid attestation identity keys (AIKs).

16. The method of claim 15 , wherein the cloud provider provides the inventory to the at least one tenant to enable remote attestation of authenticity of a cloud infrastructure providing the measured virtual machine.

17. The method of claim 15 , wherein the inventory identifies at least one specific physical infrastructure that contains a specific TPM having a specific AIK public key.

18. The method of claim 15 , wherein the cloud provider creates the association between the TPM and the generated TPM quote in accordance with a legal agreement between the at least one tenant and the cloud provider.

19. A non-transitory computer readable medium storing computer executable instructions that, when executed, cause an apparatus at least to:

store, in a trusted protection module (TPM), a first measurement of a virtualization platform;

store, in the TPM, a second measurement of a measured virtual machine;

generate a TPM quote using a key, wherein the TPM quote is based on the first measurement and the second measurement; and

provide the TPM quote for attesting to authenticity of the virtualization platform and of the measured virtual machine,

wherein the TPM quote is uniquely tied to an individual piece of hardware of physical infrastructure hardware on which the virtualization platform runs, and a cloud provider creates an association between the TPM and the generated TPM quote, the association between the TPM and the generated TPM quote identifying to at least one tenant of the cloud provider the individual piece of hardware of the physical infrastructure hardware on which the virtualization platform runs.

20. The computer readable medium of claim 19 , wherein the executable instructions, when executed, further cause the apparatus to store a third measurement of a secure tunnel, wherein the TPM quote is generated based on the third measurement.

Assignments (2)
CORRECTION ASSIGNMENT TO CORRECT THE THIRD INVENTORS NAME PREVIOUSLY RECORDED AT REEL: 033111 FRAME: 0790. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 29, 2014
From: SPIERS, BRADFORD THOMAS; HALAS, MIROSLAV; SCHIMMEL, RICHARD A.
To: BANK OF AMERICA CORPORATION
Reel/Frame 034713/0049 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2014
From: SPIERS, BRADFORD THOMAS; HALAS, MIROSLAV; SCHIMMEL, RICARD .A.
To: BANK OF AMERICA CORPORATION
Reel/Frame 033111/0790 →
Continuity (4)
Continuation 13422751 · Mar 16, 2012
Provisional Application 61492612 · Jun 2, 2011
Provisional Application 61476747 · Apr 18, 2011
Related Publication 20140298439A1 · Oct 2, 2014