Invention Grant
- Patent Title: Parallel virtual machine managers
-
Application No.: US13799134Application Date: 2013-03-13
-
Publication No.: US10579405B1Publication Date: 2020-03-03
- Inventor: Nachiketh Rao Potlapally , Michael David Marr
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: AMAZON TECHNOLOGIES, INC.
- Current Assignee: AMAZON TECHNOLOGIES, INC.
- Current Assignee Address: US WA Seattle
- Agency: Hogan Lovells US LLP
- Main IPC: G06F9/455
- IPC: G06F9/455 ; G06F21/60

Abstract:
A processor on a host machine can concurrently operate a standard virtual machine manager (VMM) and a security VMM (SVMM), where the SVMM has a higher privilege level and manages access to a hardware TPM or other trusted source on the host machine. Such a configuration prevents a compromised VMM from gaining access to secrets stored in the hardware TPM. The SVMM can create a virtual TPM (vTPM) for each guest VM, and can seal information in each vTPM to the hardware TPM. A guest VM or the standard VMM can access information in the corresponding vTPM only through the corresponding SVMM. Such an approach enables the host to securely implement critical security functionality that can be exposed to customers, and provides protection against leakage of customer secrets in case of a security compromise.
Information query