Invention Grant
- Patent Title: Distributed trusted platform module key management protection for roaming data
-
Application No.: US17459445Application Date: 2021-08-27
-
Publication No.: US12158980B2Publication Date: 2024-12-03
- Inventor: Ronald Aigner , Giridhar Viswanathan , Lars Reuther , Alvin Morales Caro , David Kimler Altobelli , Dan Ma
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Main IPC: G06F21/78
- IPC: G06F21/78 ; H04L9/08 ; H04L9/32

Abstract:
Distributed security key management for protecting roaming data via a trusted platform module is performed by systems that include first and second processors, and first and second respective hardware security modules. The first security module encrypts a security key using a public key from the second security module, and the encrypted security key is provided to the second security module. A virtual machine (VM) executed by the first processor has a first virtual security module instance having state data that includes a storage key encrypting VM virtual disk data and that is encrypted with the security key. When a transfer condition is determined, the VM is transferred and executed by the second processor, using a second virtual security module instance, based on decrypting the security key by the second security module using a private key and decrypting the state data for the second virtual security module using the security key.
Public/Granted literature
- US20230066427A1 DISTRIBUTED TRUSTED PLATFORM MODULE KEY MANAGEMENT PROTECTION FOR ROAMING DATA Public/Granted day:2023-03-02
Information query