IP Library Granted Patent US 8,627,112
Granted Patent B2
US 8,627,112 · App. 12/749,881 · Granted Jan 7, 2014

Secure virtual machine memory

Inventors: Pradeep Kumar Chaturvedi (Bangalore, IN); Gosukonda Naga Venkata Satya Sudhakar (Bangalore, IN)
Assignee: Novell, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,627,112
App. No.
12/749,881
Granted
Jan 7, 2014
Kind
B2
Abstract

Apparatus, systems, and methods may operate to allocating encrypted memory locations to store encrypted information, the information to be encrypted and decrypted using a single hypervisor. Further activity may include permitting access to a designated number of the encrypted memory locations to a single application executed by an associated virtual machine (VM) subject to the hypervisor, and denying access to the designated number of the encrypted memory locations to any other application executed by the associated VM, or any other VM. In some embodiments, the operational state of the associated VM may be restored using the encrypted information. Additional apparatus, systems, and methods are disclosed.

Claims (49)

1. An apparatus, comprising:

a first node including encrypted memory locations that have been allocated to store encrypted information; and

a storage supervision processor executing a single hypervisor and communicatively coupled to the first node to:

permit access to a designated number of the encrypted memory locations to a single application executed by an associated virtual machine (VM) subject to the hypervisor, the encrypted memory locations being usable as main memory, and the single application being from a plurality of applications executing in the associated VM; and

deny access to the designated number of the encrypted memory locations to any other application executed by the associated VM, or any other VM, the information to be encrypted and decrypted using the single hypervisor and a dynamic encryption key; and

a key generation module, implemented by a processor, to generate the dynamic encryption key to be made accessible to the single hypervisor, the dynamic encryption key created for each snapshot taken of the associated VM.

2. The apparatus of claim 1 , further comprising:

a second node to execute the single application, and to request storage and recall of the information using a memory configuration associated with the encrypted memory locations.

3. The apparatus of claim 1 , further comprising:

a second node to execute the single application, and to request storage and recall of the information without having a memory configuration associated with the encrypted memory locations.

4. The apparatus of claim 1 , further comprising:

a second node to house the storage supervision processor.

5. The apparatus of claim 1 , wherein the encrypted memory locations comprise non-volatile memory.

6. A processor-implemented method to execute on one or more processors that perform the method, comprising:

executing a single hypervisor;

allocating encrypted memory locations to store encrypted information, the encrypted memory locations being usable as main memory, and the information to be encrypted and decrypted using the single hypervisor and a dynamic encryption key;

permitting access to a designated number of the encrypted memory locations to a single application executed by an associated virtual machine (VM) subject to the hypervisor, the single application being from a plurality of applications executing in the associated VM; and

denying access to the designated number of the encrypted memory locations to any other application executed by the associated VM, or any other VM; and

creating, by the hypervisor, the dynamic encryption key associated with the information for each snapshot taken of the associated VM.

7. The method of claim 6 , wherein the permitting access comprises:

permitting access when the single application requests access using a secure memory request designated by the associated VM.

8. The method of claim 6 , wherein the single application comprises

one of a word processing application, a presentation application, a spreadsheet application, an email application, a database application, or a browser application.

9. The method of claim 6 , further comprising:

presenting the encrypted memory locations by the hypervisor to the associated VM as a secure disk file memory configuration, wherein the associated VM is to manage storage operations associated with secure disk file memory.

10. The method of claim 9 , further comprising:

mounting a secure disk containing the secure disk file by the associated VM;

mapping memory in the secure disk file to the designated number of the encrypted memory locations; and

granting access to the secure disk file to the single application by the associated VM.

11. The method of claim 6 , further comprising:

storing the encrypted information in the encrypted memory locations comprising non-volatile memory locations; and

one of transmitting the encrypted information and at least one shared key to a new hypervisor or transmitting a decrypted version of the encrypted information to the new hypervisor over a secure network connection.

12. The method of claim 6 , further comprising:

decrypting the encrypted information to provide the information;

assembling a memory file comprising content of regular memory associated with the single application and the information; and

migrating the memory file to a physical machine to permit unencrypted access to the information by the physical machine.

13. The method of claim 6 , further comprising:

granting access by the hypervisor to an operating system (OS) associated with the associated VM, to the designated number of the encrypted memory locations, without transmitting a configuration of the encrypted memory locations to the associated VM.

14. The method of claim 6 , further comprising:

receiving a request to access the encrypted memory locations from an unknown application that is not the single application, or an unknown VM that is not associated with the single application; and

denying access to the unknown application or the unknown VM by the associated VM.

15. The method of claim 6 , wherein the information is to be shared between the single application and another application, further comprising:

requesting recall of the information by the single application;

decrypting of the encrypted information by the hypervisor to provide the information; and

transmitting the information from the hypervisor to the single application.

16. The method of claim 6 , further comprising:

requesting storage of the information by the single application;

encrypting the information by the hypervisor to provide the encrypted information; and

storing the encrypted information in the encrypted memory locations by the hypervisor.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2010
From: CHATURVEDI, PRADEEP KUMAR; SUDHAKAR, GOSUKONDA NAGA VENKATA SATYA
To: NOVELL, INC.
Reel/Frame 024172/0348 →
Continuity (1)
Related Publication 20110246767A1 · Oct 6, 2011