Virtual machine monitor local integrity detection system and implementation method
A virtual machine monitor and integrity detection technology, applied in the field of information security, can solve problems such as low security, inconvenient implementation, and inability to realize the integrity detection of the underlying environment, so as to ensure safe production, simple structure, and easy promotion and use value effect
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0037] as attached figure 1 As shown, a system for local integrity detection of a virtual machine monitor of the present invention, the system includes a physical platform and a VM (virtual machine), the physical platform is provided with a TPM or TCM chip, and the TPM or TCM chip can work normally Start and run, and virtualize the corresponding vTPM (virtual trusted platform module) for each VM on the physical platform. The method of the system to realize the integrity detection: map the physical PCR with the VMM state to the vPCR corresponding to the vTPM , the VM user specifies the confidential data in the VM, encapsulates the confidential data and the state information in the vPCR into a data block and saves it; when the data block is decapsulated, only the vPCR value currently storing the VMM state information and the Only when the vPCR value is consistent can the data block be successfully decapsulated to obtain the confidential data.
Embodiment 2
[0039]The realization method of local integrity detection of a kind of virtual machine monitor of the present invention, this realization method comprises two phases, is respectively standard PCR value encapsulation stage and PCR value comparison decapsulation stage; Standard PCR value encapsulation stage refers to the VMM (Virtual Machine Controller) When starting for the first time, map the physical PCR with the VMM state to the vPCR corresponding to the vTPM, and the VM user specifies the confidential data in the VM, and encapsulates the confidential data and the state information in the vPCR into a data block And save; PCR value comparison decapsulation stage means that when the subsequent VM is restarted, the decapsulation operation is performed on the data block first, and only when the vPCR value currently storing the VMM state information is consistent with the vPCR value in the data block, can it be successful Decapsulate to get confidential data; if decapsulation fail...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com