Administrative Domain: Security Enhancement for Virtual TPM
Xin Jin, Lina Wang, Rongwei Yu, Peng Kou, Chenglin Shen · 2010
Trusted computing has been introduced into virtualization as an approach of providing trust in a computing platform. However, the primitive design of privileged domain menaces virtual TPMs with oversize of trusted computing base, leading to security vulnerabilities. This paper proposes a new administrative domain (Domain A), an architecture that prevents virtual TPMs from tampers. We port the VTPM components from the privileged domain to Domain A. We begin with reviewing the Xen virtual TPM architecture and depicting the attack in Xen. Then, the Domain A-based scheme is described with the design principle and implementation of porting virtual TPM manager and TPM drivers to Domain A. Finally, its security value is analyzed with evidences to prove validation and worth of the new architecture.