IP Library Granted Patent US 9,710,400
Granted Patent B2
US 9,710,400 · App. 14/148,088 · Granted Jul 18, 2017

Secure virtual machine memory

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,710,400
App. No.
14/148,088
Granted
Jul 18, 2017
Kind
B2
Abstract

Apparatus, systems, and methods may operate to restore an operational state of an associated virtual machine (VM) using encrypted information stored in encrypted memory locations. A single hypervisor may be used to encrypt and decrypt the information. Access may be permitted to a designated number of the encrypted memory locations only to a single application executed by the associated VM subject to the hypervisor. Access may be denied to any other application executed by the associated VM, or any other VM.

Claims (42)

1. A machine-readable medium that is not a transitory propagating signal, the machine-readable medium including instructions that, when executed by a machine, cause the machine to perform operations comprising:

granting access by a single hypervisor to an operating system (OS) associated with an associated virtual machine (VM), to a designated number of the encrypted memory locations, without transmitting a configuration of the encrypted memory locations to the associated VM;

copying, by the hypervisor, associated VM memory to a file in response to an instruction to snapshot virtual machine memory, clone the associate VM, pause the associated VM, or suspend the associated VM, the associated VM memory including encrypted memory locations, a designated number of the encrypted memory locations assigned to a single application executing in the OS of the associated VM, the encrypted memory locations specified by memory addresses, the encrypted memory locations accessible to the single application via a secure memory access request to the OS using the memory addresses, the copying including encrypting data from the encrypted memory locations prior to storage in the file;

restoring an operational state of application data for the associated VM, using encrypted information of the application data stored in the encrypted memory locations, the information to be encrypted and decrypted using the single hypervisor; and

permitting, in response to a request by the single application executed in the OS of the associated VM, access to the designated number of the encrypted memory locations only to the single application executed by the associated VM subject to the hypervisor, wherein the access is denied to any other application executed by the associated VM, or any other VM.

2. The machine-readable medium of claim 1 , wherein the operations further comprise:

receiving a request to access the encrypted memory locations from an unknown application that is not the single application, or an unknown VM that is not associated with the single application; and

denying access to the unknown application by the associated VM.

3. The machine-readable medium of claim 1 , wherein the operations further comprise:

receiving a request to restore the operational state of application data for the associated VM after one of a pause operation or a suspend operation;

decrypting, by the hypervisor, the encrypted information to provide the information; and

transmitting the information to be used to restore the operational state of application data for the associated VM.

4. The machine-readable medium of claim 1 , wherein the operations further comprise:

creating, by the hypervisor, a decryption key associated with the information once for a lifetime of the VM, or for some number of times equal to a number of snapshots taken of the VM.

5. An apparatus comprising:

a first node including encrypted memory locations specified by memory addresses; and

a storage supervision processor to execute a single hypervisor, the storage supervision processor to:

copy associated virtual machine (VM) memory to a file in response to an instruction to snapshot virtual machine memory, clone the associate VM, pause the associated VM, or suspend the associated VM, the associated VM memory including the encrypted memory locations, a designated number of the encrypted memory locations assigned to a single application executing in an operating system (OS) of the associated VM, the encrypted memory locations accessible to the single application via a secure memory access request to the OS using the memory addresses, wherein to copy the associated VM memory includes encrypting data from the encrypted memory locations prior to storage in the file restore an operational state of application data for the associated VM using encrypted information of the application data stored in the encrypted memory locations;

permit, in response to a request by the single application executed in an operating system of the associated VM, access to the designated number of the encrypted memory locations only to the single application executed by the associated VM on a second node subject to the hypervisor, wherein the access is denied to any other application executed by the associated VM, or any other VM; and

grant access to the OS associated with the associated VM, to a designated number of the encrypted memory locations, without transmitting a configuration of the encrypted memory locations to the associated VM.

6. The apparatus of claim 5 , wherein the apparatus is to:

receive a request to access the encrypted memory locations from an unknown application that is not the single application, or an unknown VM that is not associated with the single application; and

deny access to the unknown application by the associated VM.

7. The apparatus of claim 5 , wherein the apparatus is to:

receive a request to restore the operational state of the application data for the associated VM after one of a pause operation or a suspend operation;

decrypt, by the hypervisor, the encrypted information to provide the information; and

transmit the information to be used to restore the operational state application data for of the associated VM.

8. The apparatus of claim 5 , wherein the hypervisor is to create a decryption key associated with the information once for a lifetime of the VM, or for some number of times equal to a number of snapshots taken of the VM.

9. A processor-implemented method to execute on one or more processors that perform the method, comprising:

granting access by a single hypervisor to an operating system (OS) associated with an associated virtual machine (VM), to a designated number of the encrypted memory locations, without transmitting a configuration of the encrypted memory locations to the associated VM;

copying, by the hypervisor, associated VM memory to a file in response to an instruction to snapshot virtual machine memory, clone the associate VM, pause the associated VM, or suspend the associated VM, the associated VM memory including encrypted memory locations, a designated number of the encrypted memory locations assigned to a single application executing in the OS of the associated VM, the encrypted memory locations specified by memory addresses, the encrypted memory locations accessible to the single application via a secure memory access request to the OS using the memory addresses, the copying including encrypting data from the encrypted memory locations prior to storage in the file;

restoring an operational state of application data for the associated VM, using encrypted information of the application data stored in the encrypted memory locations, the information to be encrypted and decrypted using the single hypervisor; and

permitting, in response to a request by the single application executed in the OS of the associated VM, access to the designated number of the encrypted memory locations only to the single application executed by the associated VM subject to the hypervisor, wherein the access is denied to any other application executed by the associated VM, or any other VM.

10. The method of claim 9 , further comprising:

receiving a request to access the encrypted memory locations from an unknown application that is not the single application, or an unknown VM that is not associated with the single application; and

denying access to the unknown application by the associated VM.

11. The method of claim 9 , further comprising:

receiving a request to restore the operational state of the application data for the associated VM after one of a pause operation or a suspend operation;

decrypting, by the hypervisor, the encrypted information to provide the information; and

transmitting the information to be used to restore the operational state of the associated VM.

12. The method of claim 9 , further comprising:

creating, by the hypervisor, a decryption key associated with the information once for a lifetime of the VM, or for some number of times equal to a number of snapshots taken of the VM.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2026
From: MICRO FOCUS SOFTWARE INC.
To: MICRO FOCUS LLC
Reel/Frame 073758/0781 →
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →