IP Library Granted Patent US 7,392,403
Granted Patent B1
US 7,392,403 · App. 11/960,167 · Granted Jun 24, 2008

Systems, methods and computer program products for high availability enhancements of virtual security module servers

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,392,403
App. No.
11/960,167
Granted
Jun 24, 2008
Kind
B1
Abstract

Systems, methods and computer program products for high availability enhancements of virtual security module servers. Exemplary embodiments include a command processing method, including receiving a command from a virtual machine monitor in an I/O controller of a recipient virtual security appliance, determining a load of a crypto engine of the recipient virtual security appliance to assign a master/slave flag, the crypto engine having a master virtual trusted platform module and a slave trusted platform module, assigning a master/slave flag to the command to identify a command type, determining the command type in the I/O controller, receiving output from the crypto engine and returning the output to the virtual machine monitor.

Claims (24)

1. In a virtual security appliance system, a command processing method, comprising:

receiving a command from a Virtual Machine Monitor in an I/O controller of a recipient Virtual Security Appliance in the virtual security appliance system;

determining a load of a crypto engine of the recipient virtual security appliance to assign a master/slave flag, the crypto engine having a master virtual Trusted Platform Module and a slave virtual Trusted Platform Module;

assigning a master/slave flag to the command to identify a command type;

determining the command type in the I/O controller;

in response to a random command type:

sending the command to the master virtual Trusted Platform Module and to the slave virtual Trusted Platform Module;

generating a random number in the master virtual Trusted Platform Module;

sending the random number to the slave virtual Trusted Platform Module;

processing the command in the master virtual Trusted Platform Module and in the slave virtual Trusted Platform Module;

sending the processed command to the I/O controller as output;

in response to a write command type:

sending the command to the master virtual Trusted Platform Module and to the slave virtual Trusted Platform Module;

processing the command in the master virtual Trusted Platform Module and in the slave virtual Trusted Platform Module;

sending the processed command to the I/O controller as output

in response to a read command type:

sending the command to the master virtual Trusted Platform Module

sending the command to the I/O controller as output;

receiving output from the crypto engine; and

returning the output to the Virtual Machine Monitor.

2. The method as claimed in claim 1 wherein the crypto engine includes an appliance endorsement key configured to provide an identification and to pair with an additional recipient virtual security appliance in the virtual security appliance system, the additional recipient virtual security appliance including an additional crypto engine having an additional appliance endorsement key.

3. The method as claimed in claim 2 further comprising:

establishing a pair credential between the recipient virtual security appliance and the additional recipient virtual security appliance; and

establishing a secure channel between the recipient virtual security appliance and the additional recipient virtual security appliance through an exchange of the appliance endorsement key and the additional appliance endorsement key through the pair credential.

Assignments (1)
CHANGE OF NAME Recorded Dec 20, 2021
From: FACEBOOK, INC.
To: META PLATFORMS, INC.
Reel/Frame 058553/0802 →