Hardware-bound virtual TPM for cloud computing deep attestation
Andrea Bertorello · 2020
Nowadays the cloud computing paradigm changed the IT industry, reshaping the the hardware provisioning and the how services and infrastructures are developed. Cloud computing is in fact a method to increase capabilities without the need for investment in infrastructure as well as in software. However, this evolution leads to integrity and security issues. Data integrity is nothing but the guarantee that the data is not accessed or modified by those that are not authorized. It can be achieved on a system through the usage of the Trusted Platform Module, through the collection and generation of integrity measures, it offers tamper resistance. Despite everything, this procedure cannot be supported in a virtual environment since a virtual TPM, vTPM, although it provides the same functionalities of a physical TPM ,pTPM, has the same weaknesses of any software. Since Data Integrity is a crucial point in the cloud computing environment in order to provide reliability to the whole system, this thesis work proposes to investigate a solution for the Deep Attestation based on virtual TPM and its binding to a physical TPM, in order to retain the security strength of hardware-based root of trusts and the capability to correctly evaluate the reliability of a system.