IP Library Granted Patent US 9,374,228
Granted Patent B2
US 9,374,228 · App. 13/651,380 · Granted Jun 21, 2016

Verifying a geographic location of a virtual disk image executing at a data center server within a data center

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,374,228
App. No.
13/651,380
Granted
Jun 21, 2016
Kind
B2
Abstract

A method to verify a geographic location of a virtual disk image executing at a data center server within a data center. One embodiment includes a cryptoprocessor proximate the data center server, a hypervisor configured to send a disk image hash value of the virtual disk image, a digital certificate issued to the cryptoprocessor, an endorsement key to a data center tenant and a location provider. The method includes sending a disk image hash value of the virtual disk image, an endorsement key unique to a cryptoprocessor proximate the data center server to a data center tenant, and a digital certificate to a data center tenant. Next, the location provider sends the geographic location of the cryptoprocessor matching the endorsement key to the data center tenant.

Claims (21)

1. A method to verify a geographic location of a virtual disk image executing at a data center server within a data center, the method comprising:

receiving the virtual disk image from a data center tenant for execution at the data center;

sending a disk image hash value of the virtual disk image signed by an endorsement key unique to a cryptoprocessor within the data center server to the data center tenant, a public half of the endorsement key, and a digital certificate certifying the public half of the endorsement key to the data center tenant, private half of the endorsement key is stored in the cryptoprocessor and is unique to the cryptoprocessor; and

sending the geographic location of the cryptoprocessor matching the public half of the endorsement key to the data center tenant by a location provider within the data center.

2. The method of claim 1 , wherein the disk image hash value is signed by a public key of an attestation identity key pair.

3. The method of claim 1 , wherein sending the geographic location of the cryptoprocessor includes reading a radio-frequency identification (RFID) tag by the location provider, the RFID tag carried by the cryptoprocessor.

4. The method of claim 1 , wherein the location provider is inaccessible to an owner of the data center.

5. The method of claim 1 , further comprising receiving the virtual disk image from the data center tenant for execution at the data center.

6. The method of claim 1 , further comprising computing the disk image hash value by a computer processor of the data center server.

7. The method of claim 1 , further comprising:

receiving by the hypervisor an attestation request from the data center tenant; and

in response to the attestation request, sending the hash value of the virtual disk image by cryptoprocessor to the hypervisor.

8. The method of claim 1 , further comprising:

generating an attestation identity key pair by the cryptoprocessor; and

sending a public key of the attestation identity key pair to a certificate authority via the hypervisor.

9. The method of claim 8 , further comprising:

verifying an authenticity of the public key of the attestation identity key pair by the certificate authority; and

generating a digital certificate for the attestation identity key pair by the certificate authority upon verifying the authenticity of the public key.

10. The method of claim 9 , wherein sending the disk image hash value includes sending the public key of the attestation identity key pair and the digital certificate for the attestation identity key pair to the data center tenant.

11. The method of claim 10 , further comprising comparing, by the data center tenant, the public key of the attestation identity key pair to contents of the digital certificate for the attestation identity key.

12. The method of claim 11 , further comprising verifying, by the certificate authority, that the endorsement key and the public key of the attestation identity key pair belong to the cryptoprocessor proximate the data center server.

Assignments (5)
SECURITY INTEREST Recorded Mar 28, 2025
From: AVALARA, INC.; EDISON VAULT, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 070671/0097 →
RELEASE OF SECURITY INTEREST Recorded Mar 28, 2025
From: BLUE OWL CREDIT INCOME CORP (F/K/A OWL ROCK CORE INCOME CORP.), AS COLLATERAL AGENT
To: AVALARA, INC.; EDISON VAULT, LLC
Reel/Frame 070671/0486 →
SECURITY INTEREST Recorded Oct 20, 2022
From: AVALARA, INC.; EDISON VAULT, LLC
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 061728/0201 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: EDISON VAULT, LLC
Reel/Frame 057059/0956 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2012
From: PENDARAKIS, DIMITRIOS; SESHADRI, ARVIND
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 029124/0429 →