IP Library Granted Patent US 11,036,875
Granted Patent B2
US 11,036,875 · App. 15/414,412 · Granted Jun 15, 2021

Dependent enclave binaries

Inventor: Manuel Costa (Cambridge, GB)
Assignee: Microsoft Technology Licensing, LLC
G06F21/6218G06F21/57G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,036,875
App. No.
15/414,412
Granted
Jun 15, 2021
Kind
B2
Abstract

Techniques for instantiating an enclave from dependent enclave images are presented. The techniques include identifying a first set of dependent enclave indicators from a primary enclave image, identifying a first dependent enclave image corresponding to one of the first set of dependent enclave indicators, creating a secure enclave container, and copying at least a portion of the primary enclave image and at least a portion of the first dependent enclave image into the secure enclave container.

Claims (57)

1. A method for instantiating an enclave, comprising:

identifying a first set of dependent enclave indicators that are included in metadata of a primary enclave image and that reference respective dependent enclave images on which the primary enclave image depends, the dependent enclave images including an abstraction platform image and a non-platform image, the abstraction platform image is an image of an abstraction platform that is configured to enable a version of enclave software and enclave client software to run on multiple native enclave platforms, the non-platform image includes at least one of code or data that is specific to the enclave;

identifying a first dependent enclave image corresponding to one of the first set of dependent enclave indicators;

creating a secure enclave container; and

copying at least a portion of the primary enclave image and at least a portion of the first dependent enclave image into the secure enclave container.

2. The method of claim 1 , further comprising:

identifying a second set of dependent enclave indicators from the first dependent enclave image;

identifying a second dependent enclave image corresponding to one of the second set of dependent enclave indicators; and

copying at least a portion of the second dependent enclave image into the secure enclave container.

3. The method of claim 1 , further comprising:

verifying integrity of the first dependent enclave image with a key associated with an author of the first dependent enclave image.

4. The method of claim 1 , wherein the primary enclave image is associated with a first enclave author and the first dependent enclave image is associated with an enclave platform, and wherein the secure enclave container conforms to the enclave platform, and further comprising:

verifying integrity of the primary enclave image with a key associated with the first enclave author; and

verifying integrity of the first dependent enclave image with a key associated with the enclave platform.

5. The method of claim 4 , wherein:

the enclave platform is an abstraction platform.

6. The method of claim 4 , wherein:

the enclave platform is a native platform.

7. The method of claim 1 , wherein the first set of dependent enclave indicators are abstract enclave indicators, and wherein the first dependent enclave image is identified by looking up the one of the first set of dependent enclave indicators in a registry of enclave binaries.

8. A system comprising:

memory; and

one or more processors coupled to the memory, the one or more processors configured to:

identify a first set of dependent enclave indicators that are included in metadata of a primary enclave image and that reference respective dependent enclave images on which the primary enclave image depends, the dependent enclave images including an abstraction platform image and a non-platform image, the abstraction platform image is an image of an abstraction platform that is configured to enable a version of enclave software and enclave client software to run on multiple native enclave platforms, the non-platform image includes at least one of code or data that is specific to the enclave;

identify a first dependent enclave image corresponding to one of the first set of dependent enclave indicators;

create a secure enclave container; and

copy at least a portion of the primary enclave image and at least a portion of the first dependent enclave image into the secure enclave container.

9. The system of claim 8 , wherein the one or more processors are further configured to:

identify a second set of dependent enclave indicators from the first dependent enclave image;

identify a second dependent enclave image corresponding to one of the second set of dependent enclave indicators; and

copy at least a portion of the second dependent enclave image into the secure enclave container.

10. The system of claim 8 , wherein the one or more processors are further configured to:

verify integrity of the first dependent enclave image with a key associated with an author of the first dependent enclave image.

11. The system of claim 8 , wherein the primary enclave image is associated with a first enclave author and the first dependent enclave image is associated with an enclave platform;

wherein the secure enclave container conforms to the enclave platform; and

wherein the one or more processors are configured to:

verify integrity of the primary enclave image with a key associated with the first enclave author; and

verify integrity of the first dependent enclave image with a key associated with the enclave platform.

12. The system of claim 11 , wherein the enclave platform is an abstraction platform.

13. The system of claim 11 , wherein the enclave platform is a native platform.

14. The system of claim 8 , wherein the first set of dependent enclave indicators are abstract enclave identities, and wherein the first dependent enclave image is identified by looking up the one of the first set of dependent enclave indicators in a registry of enclave binaries.

15. A system comprising:

means for identifying a first set of dependent enclave indicators that are included in metadata of a primary enclave image and that indicate respective entry points of respective dependent enclave images on which the primary enclave image depends, the dependent enclave images including an abstraction platform image and a non-platform image, the abstraction platform image is an image of an abstraction platform that is configured to enable a version of enclave software and enclave client software to run on multiple native enclave platforms, the non-platform image includes at least one of code or data that is specific to the enclave;

means for identifying a first dependent enclave image corresponding to one of the first set of dependent enclave indicators;

means for creating a secure enclave container; and

means for copying at least a portion of the primary enclave image and at least a portion of the first dependent enclave image into the secure enclave container.

16. The system of claim 15 , further comprising:

means for identifying a second set of dependent enclave indicators from the first dependent enclave image;

means for identifying a second dependent enclave image corresponding to one of the second set of dependent enclave indicators; and

means for copying at least a portion of the second dependent enclave image into the secure enclave container.

17. The system of claim 15 , further comprising:

means for verifying the integrity of the first dependent enclave image with a key associated with an author of the first dependent enclave image.

18. The system of claim 15 , wherein the primary enclave image is associated with a first enclave author and the first dependent enclave image is associated with an enclave platform, and wherein the secure enclave container conforms to the enclave platform, and further comprising:

means for verifying integrity of the primary enclave image with a key associated with the first enclave author; and

means for verifying integrity of the first dependent enclave image with a key associated with the enclave platform.

19. The system of claim 18 , wherein:

the enclave platform is an abstraction platform.

20. The system of claim 15 , wherein the first set of dependent enclave indicators are abstract enclave identities, and wherein the first dependent enclave image is identified by looking up the one of the first set of dependent enclave indicators in a registry of enclave binaries.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2017
From: COSTA, MANUEL
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 043860/0286 →
Continuity (1)
Related Publication 20180211054A1 · Jul 26, 2018