Invention Grant
- Patent Title: Provisioning identity certificates using hardware-based secure attestation in a virtualized and clustered computer system
-
Application No.: US17148445Application Date: 2021-01-13
-
Publication No.: US11709700B2Publication Date: 2023-07-25
- Inventor: Abhishek Srivastava , David A. Dunn , Jesse Pool , Adrian Drzewiecki
- Applicant: VMware, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: VMware, Inc.
- Current Assignee: VMware, Inc.
- Current Assignee Address: US CA Palo Alto
- Agency: Kim & Stewart LLP
- Main IPC: G06F9/455
- IPC: G06F9/455

Abstract:
An example method of secure attestation of a workload deployed in a virtualized computing system is described. The virtualized computing system includes a host cluster and a virtualization management server, the host cluster having hosts and a virtualization layer executing on hardware platforms of the hosts. The method includes: launching, in cooperation with a security module of a host, a guest as a virtual machine (VM) managed by the virtualization layer, the security module generating an attestation report from at least a portion of the VM loaded into memory of the host; sending the attestation report from the security module to a trust authority; receiving, in response to verification of the attestation report by the trust authority, a secret from the trust authority at the security module; and providing the secret from the security module to the guest.
Public/Granted literature
Information query