IP Library Granted Patent US 11,120,140
Granted Patent B2
US 11,120,140 · App. 16/019,624 · Granted Sep 14, 2021

Secure operations on encrypted data

Inventors: Oliver Benke (Stuttgart, DE); Tobias U. Bergmann (Weinstadt, DE)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/602H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,120,140
App. No.
16/019,624
Filed
Jun 27, 2018
Granted
Sep 14, 2021
Kind
B2
Art Unit
2434
USPC
713/150
Abstract

Secure operations are performed on encrypted code. A processor in a first operating mode obtains encrypted code. The processor switches from the first operating mode to a second operating mode, and decrypts the encrypted code to obtain decrypted code. The decrypted code is executed, based on the processor being in the second operating mode, to provide a result. The result is encrypted, and the encrypted result is sent to a user, based on the processor switching back to the first operating mode.

Claims (47)

1. A computer program product for facilitating processing within a computing environment, the computer program product comprising:

at least one computer readable storage medium readable by at least one processing circuit and storing instructions for performing a method comprising:

obtaining, by a processor in a first operating mode, encrypted code, the processor to execute clear text instructions based on being in the first operating mode;

switching the processor from the first operating mode to a second operating mode, the second operating mode being different from the first operating mode, wherein the switching the processor from the first operating mode to the second operating mode includes deactivating one or more communication connections of the processor to external components of the processor to place the processor in the second operating mode, and the deactivating the one or more communication connections of the processor to external components of the processor to place the processor in the second operating mode comprises fencing physical wires to and from the processor to fence data signals to and from the processor;

decrypting the encrypted code to obtain decrypted code, based on the processor being in the second operating mode;

executing the decrypted code, based on the processor being in the second operating mode; and

ending the second operating mode, the ending the second operating mode including restoring the one or more communications connections of the processor placing the processor in the first operating mode.

2. The computer program product of claim 1 , wherein the executing the decrypted code comprises:

performing one or more operations using the decrypted code to provide a result;

encrypting the result to provide an encrypted result; and

providing the encrypted result to a client, based on the processor switching from the second operating mode to the first operating mode.

3. The computer program product of claim 2 , wherein the ending the second operating mode includes switching from the second operating mode to the first operating mode enabling communications from the processor to external components of the processor, the switching including deleting unencrypted data from one or more caches of the processor.

4. The computer program product of claim 2 , wherein the method further comprises decrypting input data to provide decrypted data, and wherein the one or more operations are performed on the decrypted data to provide the result.

5. The computer program product of claim 4 , wherein the decrypting the input data comprises using at least one data key for decrypting the input data, the at least one data key being provided by the decrypted code.

6. The computer program product of claim 1 , wherein the decrypting the encrypted code comprises decrypting the encrypted code using a private key unique to the processor.

7. The computer program product of claim 1 , wherein the encrypted code is encrypted using a public key associated with a unique identifier of the processor.

8. The computer program product of claim 1 , wherein the processor is provided by a cloud service provider.

9. The computer program product of claim 8 , wherein the method further comprises:

providing, by the cloud service provider, based on a request for the processor, a unique identifier of the processor and a public key associated with the unique identifier of the processor;

encrypting code using the public key to provide the encrypted code; and

sending the encrypted code to the processor.

10. A computer system for facilitating processing within a computing environment, the computer system comprising:

a memory; and

a processor in communication with the memory, wherein the computer system is configured to perform a method, said method comprising:

obtaining, by the processor in a first operating mode, encrypted code, the processor to execute clear text instructions based on being in the first operating mode;

switching the processor from the first operating mode to a second operating mode, the second operating mode being different from the first operating mode, wherein the switching the processor from the first operating mode to the second operating mode includes deactivating one or more communication connections of the processor to external components of the processor to place the processor in the second operating mode, and the deactivating the one or more communication connections of the processor to external components of the processor to place the processor in the second operating mode comprises fencing physical wires to and from the processor to fence data signals to and from the processor;

decrypting the encrypted code to obtain decrypted code, based on the processor being in the second operating mode;

executing the decrypted code, based on the processor being in the second operating mode; and

ending the second operating mode, the ending the second operating mode including restoring the one or more communications connections of the processor placing the processor in the first operating mode.

11. The computer system of claim 10 , wherein the executing the decrypted code comprises:

performing one or more operations using the decrypted code to provide a result;

encrypting the result to provide an encrypted result; and

providing the encrypted result to a client, based on the processor switching from the second operating mode to the first operating mode.

12. The computer system of claim 10 , wherein the encrypted code is encrypted using a public key associated with a unique identifier of the processor.

13. The computer system of claim 10 , wherein the processor is provided by a cloud service provider.

14. A computer-implemented method of facilitating processing within a computing environment, the computer-implemented method comprising:

obtaining, by a processor in a first operating mode, encrypted code, the processor to execute clear text instructions based on being in the first operating mode;

switching the processor from the first operating mode to a second operating mode, the second operating mode being different from the first operating mode, wherein the switching the processor from the first operating mode to the second operating mode includes deactivating one or more communication connections of the processor to external components of the processor to place the processor in the second operating mode, and the deactivating the one or more communication connections of the processor to external components of the processor to place the processor in the second operating mode comprises fencing physical wires to and from the processor to fence data signals to and from the processor;

decrypting the encrypted code to obtain decrypted code, based on the processor being in the second operating mode;

executing the decrypted code, based on the processor being in the second operating mode; and

ending the second operating mode, the ending the second operating mode including restoring the one or more communications connections of the processor placing the processor in the first operating mode.

15. The computer-implemented method of claim 14 , wherein the executing the decrypted code comprises:

performing one or more operations using the decrypted code to provide a result;

encrypting the result to provide an encrypted result; and

providing the encrypted result to a client, based on the processor switching from the second operating mode to the first operating mode.

16. The computer-implemented method of claim 14 , wherein the encrypted code is encrypted using a public key associated with a unique identifier of the processor.

17. The computer-implemented method of claim 14 , wherein the processor is provided by a cloud service provider.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2018
From: BENKE, OLIVER; BERGMANN, TOBIAS U.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 046216/0090 →
Continuity (1)
Related Publication 20200004969A1 · Jan 2, 2020