IP Library › Granted Patent US 9,721,103
Granted Patent B2
US 9,721,103 · App. 13/929,334 · Granted Aug 1, 2017

Trusted boot of a virtual machine

Inventors: David Sherwood (Manchester, GB); James W. Walker (Manchester, GB); Travis Walton (Manchester, GB)
Assignee: International Business Machines Corporation
G06F21/575G06F9/45533G06F9/45558G06F11/1484G06F21/52G06F9/4401G06F2009/45575G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,721,103
App. No.
13/929,334
Granted
Aug 1, 2017
Kind
B2
Abstract

A method, system and program product for performing a trusted boot of a virtual machine comprises the steps of executing, in turn, a series of components of the trusted boot, performing a function on each component prior to the execution of the respective component, storing the output of the functions in a virtual trusted platform module, detecting that the virtual trusted platform module has not responded to the storing of the output of a function in the virtual trusted platform module, and generating a request that the virtual trusted platform module be disabled.

Claims (26)

1. A system for performing a trusted boot of a virtual machine, the system comprising a server arranged to:

execute, in turn, a series of components of the trusted boot;

perform a function on each respective component of the series of components prior to the execution of the respective component when attempting to establish a chain of trust for the series of components;

store the output of the functions in a virtual trusted platform module;

detect that the virtual trusted platform module has not responded to the storing of the output of a function in the virtual trusted platform module;

generate a request that the virtual trusted platform module be disabled; and

transmit the generated request to a hypervisor and disable the virtual trusted platform module using a command from the hypervisor.

2. The system according to claim 1 , wherein the system is arranged, when detecting that the virtual trusted platform module has not responded to the storing of the output of a function in the virtual trusted platform module, to wait for a predetermined time period.

3. The system according to claim 1 , wherein the system is arranged, when performing a function on each component prior to the execution of the respective component, to perform a predefined hashing function on the respective component.

4. The system according to claim 1 , wherein the system is arranged, when performing a function on each component prior to the execution of the respective component, to perform the function by the previously loaded component.

5. A computer program product comprising instructions stored on a non-transitory computer readable storage device that are operable for performing a trusted boot of a virtual machine, wherein the instructions are operable when executed by a processor for:

executing, in turn, a series of components of the trusted boot;

performing a function on each respective component of the series of components prior to the execution of the respective component when attempting to establish a chain of trust for the series of components;

storing the output of the functions in a virtual trusted platform module;

detecting that the virtual trusted platform module has not responded to the storing of the output of a function in the virtual trusted platform module;

generating a request that the virtual trusted platform module be disabled; and

transmitting the generated request to a hypervisor and disabling the virtual trusted platform module using a command from the hypervisor.

6. The computer program product according to claim 5 , wherein the instructions for detecting that the virtual trusted platform module has not responded to the storing of the output of a function in the virtual trusted platform module comprise instructions for waiting for a predetermined time period.

7. The computer program product according to claim 5 , wherein the instructions for performing a function on each component prior to the execution of the respective component comprise instructions for performing a predefined hashing function on the respective component.

8. The computer program product according to claim 5 , wherein the instructions for performing a function on each component prior to the execution of the respective component is performed by the previously loaded component.

9. The system according to claim 1 , wherein the server is arranged to generate the request responsive to detecting that the virtual trusted platform module has not responded to the storing of the output of a function in the virtual trusted platform module.

10. The system according to claim 1 , wherein the server is arranged to:

execute the hypervisor to supervise a plurality of logical, partitionable runtime environments within the server, reserve a logical partition for a hypervisor-based trusted platform module, and present the hypervisor-based trusted platform module to another logical partition as the virtual trusted platform module.

11. The computer program product according to claim 5 , wherein the request is generated responsive to detecting that the virtual trusted platform module has not responded to the storing of the output of a function in the virtual trusted platform module.

12. The computer program product according to claim 5 , wherein the instructions are operable when executed by the processor for:

executing the hypervisor to supervise a plurality of logical, partitionable runtime environments within the server, reserve a logical partition for a hypervisor-based trusted platform module, and present the hypervisor-based trusted platform module to another logical partition as the virtual trusted platform module.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2013
From: SHERWOOD, DAVID; WALKER, JAMES W.; WALTON, TRAVIS
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 031257/0430 →
Priority Claims (1)
GB 1211544.0 · Jun 29, 2012 · national
Continuity (1)
Related Publication 20140013327A1 · Jan 9, 2014