Overview
ISO/IEC 27070:2021 specifies requirements for establishing virtualized roots of trust (vRoT) in virtualized and cloud environments. It defines the functional and security expectations for components that create per‑VM trust anchors - including trusted modules (TM), virtual trusted modules (vTM), the VMM/hypervisor, and cloud OS layers - to support integrity measurement, secure storage, remote attestation and trusted VM migration. The standard provides an architectural (functional) view and an activity view covering trust bootstrapping, transitive trust, integrity measurement and reporting, data protection, and vTM migration.
Key topics and technical requirements
- Virtualized root of trust concepts: Definitions and roles for RoT, vRTM, vRTR, vRTS, vPCR and vTM that enable per‑VM attestable trust.
- Hardware TM requirements: A TM (e.g., TPM/TCM class device) must support integrity measurement, secure storage, key generation and signature/reporting for measurements; it must protect confidential keys and PCR contents.
- VMM and vTM management: The VMM layer must provide virtualized RoTs, a vTM manager to bind vTM instances to VMs, and a unified Trusted Software Stack (TSS) interface for upper layers.
- Integrity measurement and remote attestation: Processes for calculating and reporting hashes of components (integrity measurement), and mechanisms to evaluate those measurements remotely (RA) to establish platform trust.
- Data protection primitives: Data binding and data sealing procedures tied to vPCR/state to ensure secrets are accessible only in authorized VM states.
- Transitive trust and migration: Requirements to maintain trust chains across host, VMM and VM layers and secure procedures for trusted VM migration.
- Security controls: Ensure TM/vTM security, secure storage of Storage Root Keys (SRK/vSRK), protection of attestation/endorsement keys and secure random number generation.
Applications and who uses it
ISO/IEC 27070 is aimed at organizations building or operating trusted virtualized infrastructure:
- Cloud providers and service operators designing trusted cloud services
- Hypervisor/VMM vendors and OS developers implementing vTM and attestation APIs
- Hardware vendors (TPM/secure element) integrating with virtualized RoT solutions
- Security architects, system integrators and auditors assessing cloud integrity, remote attestation workflows and secure VM migration
- Developers of confidential computing and workload isolation solutions
Keywords: ISO/IEC 27070, virtualized root of trust, vTM, trusted computing, remote attestation, integrity measurement, TPM, VMM, cloud security.
Related standards
- ISO/IEC 11889‑1 (TPM terminology and functions) – referenced in definitions
- Broader ISO/IEC 27000 series and trusted computing publications for complementary guidance on information security management and platform trust.