×

Distributed trusted virtualization platform

  • US 20090204964A1
  • Filed: 10/14/2008
  • Published: 08/13/2009
  • Est. Priority Date: 10/12/2007
  • Status: Abandoned Application
First Claim
Patent Images

1. A trusted virtualization system comprising a trustworthy mobile endpoint device, the mobile endpoint device comprising:

  • a communications module that provides a communications link between the mobile endpoint device and a networked infrastructure;

    a host processor and memory;

    a hardware based tamper-resistant module (hereafter, the hardware root of trust or HROT), the HROT comprising;

    secure non-volatile memory for storing integrity measurement data and data related to keys,a computational module;

    a key pair generation module, anda random number generator;

    a trusted boot process executed by the host processor to boot the mobile endpoint device into a known state, the trusted boot process utilizing the HROT to provide cryptographic resources and secure non-volatile memory to verify the integrity of the mobile endpoint device;

    an attestation process executed by the host processor to attest to the integrity of the mobile endpoint device in response to an attestation challenge, the attestation process utilizing the HROT to provide integrity measurements of the mobile endpoint device, said integrity measurements verifying an integrity of a state of the mobile endpoint device;

    a Type-1 trusted virtual machine monitor (hereafter, the Type-1 TMM) that executes on the host processor, the trusted boot process including booting of the Type-1 TVMM and utilizing the HROT to verify the integrity of the Type-1 TVMM, the Type-1 TVMM capable of hosting a plurality of virtual machines and virtualizing the HROT independently for each such hosted virtual machine.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×