Trusted boot of a virtual machine

US9898609B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9898609-B2
Application numberUS-201514867265-A
CountryUS
Kind codeB2
Filing dateSep 28, 2015
Priority dateJun 29, 2012
Publication dateFeb 20, 2018
Grant dateFeb 20, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method, system and program product for performing a trusted boot of a virtual machine comprises the steps of executing, in turn, a series of components of the trusted boot, performing a function on each component prior to the execution of the respective component, storing the output of the functions in a virtual trusted platform module, detecting that the virtual trusted platform module has not responded to the storing of the output of a function in the virtual trusted platform module, and generating a request that the virtual trusted platform module be disabled.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method of performing a trusted boot of a virtual machine, the method comprising the steps of: executing, in turn, a series of components of the trusted boot; performing a function on each respective component of the series of components prior to the execution of the respective component when attempting to establish a chain of trust for the series of components; storing an output of the function in a virtual trusted platform module; detecting that the virtual trusted platform module has not responded to the storing of the output of the function in the virtual trusted platform module; generating a request that the virtual trusted platform module be disabled; and transmitting the generated request to a hypervisor and disabling the virtual trusted platform module using a command from the hypervisor. 2. A method according to claim 1 , wherein the step of detecting that the virtual trusted platform module has not responded to the storing of the output of the function in the virtual trusted platform module comprises waiting for a predetermined time period. 3. A method according to claim 1 , and further comprising transmitting the generated request to a hypervisor and disabling the virtual trusted platform module using a command from the hypervisor. 4. A method according to claim 1 , wherein the step of performing a function on each component prior to the execution of the respective component comprises performing a predefined hashing function on the respective component. 5. A method according to claim 1 , wherein the step of performing a function on each component prior to the execution of the respective component is performed by the previously loaded component. 6. The method according to claim 1 , wherein the request is generated responsive to detecting that the virtual trusted platform module has not responded to the storing of the output of the function in the virtual trusted platform module. 7. The method according to claim 1 , and further comprising executing a hypervisor to supervise a plurality of logical, partitionable runtime environments within the server, reserve a logical partition for a hypervisor-based trusted platform module, and present the hypervisor-based trusted platform module to another logical partition as the virtual trusted platform module.

Assignees

Inventors

Classifications

  • G06F21/575Primary

    Secure boot · CPC title

  • Hypervisors; Virtual machine monitors · CPC title

  • Monitoring or debugging support · CPC title

  • during program execution, e.g. stack integrity {; Preventing unwanted data erasure; Buffer overflow} · CPC title

  • Starting, stopping, suspending or resuming virtual machine instances · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9898609B2 cover?
A method, system and program product for performing a trusted boot of a virtual machine comprises the steps of executing, in turn, a series of components of the trusted boot, performing a function on each component prior to the execution of the respective component, storing the output of the functions in a virtual trusted platform module, detecting that the virtual trusted platform module has n…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F21/575. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Feb 20 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).