Invention Grant
US08090919B2 System and method for high performance secure access to a trusted platform module on a hardware virtualization platform
有权
用于高性能安全访问硬件虚拟化平台上的可信平台模块的系统和方法
- Patent Title: System and method for high performance secure access to a trusted platform module on a hardware virtualization platform
- Patent Title (中): 用于高性能安全访问硬件虚拟化平台上的可信平台模块的系统和方法
-
Application No.: US11967683Application Date: 2007-12-31
-
Publication No.: US08090919B2Publication Date: 2012-01-03
- Inventor: Ravi Sahita , Travis T. Schluessler
- Applicant: Ravi Sahita , Travis T. Schluessler
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Agency: Barnes & Thornburg LLP
- Main IPC: G06F12/00
- IPC: G06F12/00 ; G06F13/00 ; G06F13/28

Abstract:
A system and method for high performance secure access to a trusted platform module on a hardware virtualization platform. The virtualization platform including Virtual Machine Monitor (VMM) managed components coupled to the VMM. One of the VMM managed components is a TPM (Trusted Platform Module). The virtualization platform also includes a plurality of Virtual Machines (VMs). Each of the virtual machines includes a guest Operating System (OS), a TPM device driver (TDD), and at least one security application. The VMM creates an intra-partition in memory for each TDD such that other code and information at a same or higher privilege level in the VM cannot access the memory contents of the TDD. The VMM also maps access only from the TDD to a TPM register space specifically designated for the VM requesting access. Contents of the TPM requested by the TDD are stored in an exclusively VMM-managed protected page table that provides hardware-based memory isolation for the TDD.
Public/Granted literature
Information query