03-08-2017 дата публикации
Номер: WO2017128720A1
Принадлежит:
The present invention relates to the technical field of the Internet. Disclosed are a VTPM-based method and system for virtual machine security and protection. The method comprises: a physical host receives a primary seed access request sent by a virtual machine, wherein the primary seed access request at least carries a UUID (201); the physical host sends the UUID to a KMC (202), such that the KMC can generate a primary seed according to the UUID; the physical host receives the primary seed fed back by the KMC (204), and then sends the primary seed to the virtual machine (205) and allow the virtual machine to create, on the basis of the primary seed, a root key of the VTPM, wherein the root key is used by the VTPM to create a key for the virtual machine for security and protection of the virtual machine. The method does not rely on any physical host, and uses a third-party device to assign a primary seed to a virtual machine, subsequently enabling the creation of an identical root key ...
Подробнее