23.10.2015 Views

BATTLE OF SKM AND IUM

1MHMIxh

1MHMIxh

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

VIRTUAL MACHINE SECURE WORKER PROCESS<br />

• Hyper-V architecture separates the work required to perform VM emulation for each partition into two<br />

categories<br />

• Enlightened I/O which is handled by VSP and VSC pairs (Virtualization Service Providers/Clients) that are<br />

typically kernel-mode drivers on both the host and the client<br />

• Legacy I/O which is handled by Virtual Machine Worker Processes (VMWP.EXE)<br />

• Emulates standard i440BX motherboard legacy devices<br />

• Also handles services such as RDP, clipboard, etc…<br />

• With vTPM, a partition has a Truslet process as well – VMSP.EXE<br />

• Its agent is the VMWP.EXE process mentioned above<br />

• VMSP Uses the Mailbox and Secure Storage interface to store and encrypt TPM secrets using the IDK<br />

• Mailbox provides things like a “Security Cookie” to authenticate communications<br />

• Secure Storage is used for Ingress, Egress and other cryptographic keys for vTPM

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!