IP Library Granted Patent US 10,154,023
Granted Patent B1
US 10,154,023 · App. 14/972,377 · Granted Dec 11, 2018

Method and system for secure instantiation of an operation system within the cloud

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,154,023
App. No.
14/972,377
Granted
Dec 11, 2018
Kind
B1
Abstract

A method is disclosed for executing a secure virtual machine stored in encrypted form in IaaS cloud such as Microsoft Azure or Amazon Web Services. A first execution environment comprising a key access protocol for accessing a cipher key is initiated. The first execution environment executes the secure virtual machine by accessing a secret for use in deciphering the encrypted form of the secure virtual machine and providing same to allow the secure virtual machine to be executed.

Claims (32)

1. A method comprising:

initiating a first execution environment, the first execution environment comprising a key access protocol for accessing a cipher key; and,

initiating by the first execution environment a virtual machine, the virtual machine stored in encrypted form, the first execution environment accessing the cipher key for deciphering the encrypted form of the virtual machine to allow the virtual machine to be executed,

wherein the first execution environment comprises a pre-boot environment comprising a Unix-like virtual machine and wherein the virtual machine comprises an operating system including encryption of portions of the operating system required for execution of the operating system other than a preboot portion thereof within the operating system and requiring password entry prior to decryption of the encrypted portions of the operating system, and

wherein the first execution environment controls at least an aspect of the operating system during execution thereof to enter an unsecured password through a keyboard interface to the operating system to continue execution of the virtual machine.

2. A method according to claim 1 comprising:

storing by the first execution environment the cipher key within a known memory location prior to initiating the virtual machine.

3. A method according to claim 1 wherein the key protocol comprises providing a token stored within the first execution environment and having an expiry time to a third other virtual machine for authentication and the first virtual environment for, when authenticated, receiving a secret at the first execution environment in response to the authentication.

4. A method according to claim 1 wherein the first execution environment comprises an interface interfacing with a secure key store for retrieving therefrom the cipher key, the interface for performing an integrity check on at least one of the first execution environment and the virtual machine.

5. A method according to claim 1 wherein the first execution environment comprises an interface for interfacing with a user, the interface for demanding user reply.

6. A method according to claim 1 wherein the virtual machine is executed within the first execution environment.

7. A method according to claim 1 wherein the first execution environment is in execution within a first virtual memory space, and wherein the virtual machine is executed by the first execution environment thereby replacing the first execution environment within the first virtual memory space.

8. A method comprising:

initiating a first execution environment, the first execution environment comprising a key access protocol for accessing a cipher key; and,

initiating by the first execution environment a virtual machine, the virtual machine stored partially in encrypted form and requiring a secret for decrypting thereof, the first execution environment accessing the secret for deciphering the encrypted form of the virtual machine to allow the virtual machine to continue execution,

wherein the first execution environment comprises a security protocol for verifying an initiator thereof to authenticate the initiator as someone permitted to execute the virtual machine,

wherein the first execution environment comprises a pre-boot environment comprising a Unix-like virtual machine and wherein the virtual machine comprises an operating system including encryption of portions of the operating system required for execution of the operating system other than a preboot portion thereof within the operating system and requiring password entry prior to decryption of the encrypted portions of the operating system, and

wherein the first execution environment controls at least an aspect of the operating system during execution thereof to enter an unsecured password through a keyboard interface to the operating system to continue execution of the virtual machine.

9. A method according to claim 8 wherein the first execution environment accesses the cipher key via a key management system within a third other virtual machine.

10. A method according to claim 8 wherein the first execution environment verifies the initiator thereof by verifying a token stored therein to determine whether the token has expired.

11. A method according to claim 8 wherein the first execution environment verifies the initiator thereof by providing a token stored therein to a third other virtual machine for authentication and the first execution environment for, when authenticated, receiving the secret from the third other virtual machine.

12. A method comprising:

initiating a first execution environment within the cloud, the first execution environment comprising a key access protocol for accessing a cipher key and for storing said cipher key within the first execution environment and for executing an operating system stored in encrypted form;

accessing by the first execution environment the cipher key for deciphering the encrypted form of the operating system to allow the operating system to be executed within the first execution environment; and

executing the operating system,

wherein the key access protocol comprises a pre-boot environment comprising a Unix-like operating system in execution for accessing a cipher key and for storing said cipher key within the first execution environment and wherein the operating system comprises a first operating system including encryption of portions of the operating system required for execution of the operating system other than a preboot portion thereof within the operating system and requiring password entry prior to decryption of the encrypted portions of the operating system,

wherein the first execution environment controls at least an aspect of the operating system during execution thereof to enter an unsecured password through a keyboard interface to the operating system to continue execution of the virtual machine.

13. A method according to claim 12 wherein:

the Unix-like operating system stores the cipher key within a known memory location prior to initiating the first operating system including encryption of portions of the operating system required for execution of the operating system other than a preboot portion thereof within the operating system and requiring password entry prior to decryption of the encrypted portions of the operating system; and

the Unix-like operating system controlling at least an aspect of the first operating system one of before and during execution thereof to enter an unsecured password to the first operating system to support decryption of the first operating system and execution thereof within the first execution environment.

14. A method according to claim 12 wherein the first execution environment comprises a security protocol for authenticating execution of the operating system comprising:

providing a token stored within the first execution environment and having an expiry time to a third other virtual machine for authentication and for, when authenticated, receiving a secret in response to the authentication, the secret for use one of for accessing the cipher key and as the cipher key.

Assignments (11)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2015
From: NOSSIK, MICHAEL; BRAMBLE, TIMOTHY ROGER MASSON; MCCULLIGH, MURRAY; BERFELD, YURI
To: CLOUDLINK TECHNOLOGIES INC.
Reel/Frame 037316/0260 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2015
From: DU, LEJIN
To: EMC CORPORATION
Reel/Frame 037316/0672 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2015
From: CLOUDLINK TECHNOLOGIES INC.
To: EMC CORPORATION
Reel/Frame 037316/0541 →
Cited By (6)
US 12,261,940 US 12,277,228 US 12,288,101 US 12,506,817 US 12,598,078 US 12,619,465