Abstract:
A migration scheme for virtualized Trusted Platform Modules (430, 432, 434) is presented. The procedure is capable of securely migrating an instance of a virtual Trusted Platform Module from one physical platform (402) to another (404). A virtual Trusted Platform Module instance's state is downloaded from a source virtual Trusted Platform Module (432) and all its state information is encrypted using a hybrid of public and symmetric key cryptography (612). The encrypted state is transferred to the target physical platform (616), decrypted and the state of the virtual Trusted Platform Module instance is rebuilt (620).