IP Library › Granted Patent US 11,888,972
Granted Patent B2
US 11,888,972 · App. 16/802,066 · Granted Jan 30, 2024

Split security for trusted execution environments

Inventor: Michael Tsirkin (Westford, MA)
Assignee: RED HAT, INC.
H04L9/083G06F9/45558H04L9/085H04L9/0894G06F2009/45562
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,888,972
App. No.
16/802,066
Granted
Jan 30, 2024
Kind
B2
Abstract

A system includes a memory, an application TEE instance, an escrow TEE instance, and a server. The server is configured to receive a request to start the application TEE instance and launch the escrow TEE instance provisioned with a secret. The secret is initially accessible from a first location until the escrow TEE instance is provisioned and accessibility to the secret in the first location is restricted after provisioning the escrow TEE instance with the secret. The escrow TEE instance is configured to obtain a cryptographic measurement associated with the application TEE instance, validate the application TEE instance, and provide the secret from a second location to the application TEE instance.

Claims (47)

1. A system comprising:

a memory;

an application trusted execution environment (“TEE”) instance;

an escrow TEE instance different from the application TEE instance; and

a server configured to:

launch the escrow TEE instance provisioned with a secret, wherein the secret is initially accessible from a first location until the escrow TEE instance is provisioned,

and wherein accessibility to the secret in the first location is restricted after provisioning the escrow TEE instance with the secret, and

receive a request to start the application TEE instance, and

wherein the escrow TEE instance is configured to:

validate the application TEE instance, and

upon a successful validation of the application TEE instance, provide the secret from a second location to the application TEE instance, wherein the providing of the secret to the application TEE instance allows the application TEE instance to complete the launch;

upon the receipt of the secret by the application TEE instance, create, by the application TEE instance, a clone TEE instance of the application TEE instance;

provide the secret to the clone TEE instance by the application TEE instance, wherein the clone TEE instance comprises a service to launch additional clone TEE instances, wherein the clone TEE instance is configured to provide the secret to the additional clone TEE instances; and

disable at least one of the escrow TEE, the application TEE instance, or the clone TEE instance based upon a security breach of at least one of the escrow TEE instance, the application TEE instance, or the clone TEE instance.

2. The system of claim 1 , wherein the escrow TEE instance is configured to take the cryptographic measurement of the application TEE instance prior to validating the application TEE instance.

3. The system of claim 2 , wherein the cryptographic measurement identifies characteristics of the application TEE instance including at least one of a type of the TEE instance, a version of the TEE instance, and a description of software components loaded into the TEE instance.

4. The system of claim 2 , wherein the cryptographic measurement further includes an integrity code to validate the cryptographic measurement.

5. The system of claim 1 , wherein the application TEE instance is an encrypted virtual machine.

6. The system of claim 1 , wherein the escrow TEE instance is an encrypted virtual machine, and wherein the escrow TEE instance is another application TEE instance that includes a clone service.

7. The system of claim 1 , wherein the memory is hardware encrypted storage.

8. The system of claim 1 , wherein restricting accessibility to the secret includes removing the secret from the memory.

9. The system of claim 1 , wherein the memory is part of a private network, wherein the escrow TEE instance is part of an outside network, wherein the secret is initially stored in the memory at a first time, and wherein restricting accessibility to the secret includes removing the secret from the memory at a second time immediately after provisioning the escrow TEE instance with the secret.

10. The system of claim 1 , wherein the secret is initially stored in the first location on a device at a first time, and after provisioning the escrow TEE instance with the secret, the device is air gapped at a second time immediately after provisioning the escrow TEE instance with the secret.

11. A method comprising:

launching, by a processor, an escrow TEE instance provisioned with a secret, wherein the secret is initially accessible from a first location, and wherein accessibility to the secret in the first location is restricted after provisioning the escrow TEE instance with the secret;

launching the application TEE instance;

obtaining, during a launch of the application TEE instance, a cryptographic measurement associated with the application TEE instance;

validating the application TEE instance;

based upon a successful validation of the application TEE instance, providing the secret from a second location to the application TEE instance;

upon the receipt of the secret by the application TEE instance, creating, by the application TEE instance, a clone TEE instance of the application TEE instance; and

providing the secret to the clone TEE instance by the application TEE instance, wherein the clone TEE instance comprises a service to launch additional clone TEE instances, wherein the clone TEE instance is configured to provide the secret to the additional clone TEE instances.

12. The method of claim 11 , wherein the cryptographic measurement identifies characteristics of the application TEE instance including at least one of a type of the TEE instance, a version of the TEE instance, and a description of software components loaded into the TEE instance.

13. The method of claim 12 , wherein the cryptographic measurement further includes an integrity code to validate the cryptographic measurement.

14. The method of claim 11 , wherein the application TEE instance is an encrypted virtual machine.

15. The method of claim 11 , wherein the escrow TEE instance is an encrypted virtual machine, and wherein that escrow TEE instance is configured to serve application requests similar to the application TEE instance.

16. The method of claim 11 , wherein the memory is hardware encrypted storage.

17. The method of claim 11 , wherein restricting accessibility to the secret includes removing the secret from the memory.

18. The method of claim 11 , wherein the secret is initially stored in memory that is part of a private network at a first time, wherein the escrow TEE instance is part of an outside network, and wherein restricting accessibility to the secret includes removing the secret from the memory at a second time immediately after provisioning the escrow TEE instance with the secret.

19. The method of claim 11 , wherein the secret is initially stored in the first location on a device and the device is air gapped after provisioning the escrow TEE instance with the secret.

20. A non-transitory machine-readable medium storing code, which when executed by a processor is configured to:

launch an escrow TEE instance provisioned with a secret, wherein the secret is initially accessible from a first location, and wherein accessibility to the secret in the first location is restricted after provisioning the escrow TEE instance with the secret;

receive a request to start an application TEE instance;

obtain, during a launch of the application TEE instance, a cryptographic measurement associated with the application TEE instance;

validate, the application TEE instance;

upon a successful validation of the application TEE instance provide the secret from a second location to the application TEE instance, wherein the providing of the secret to the application TEE instance allows the application TEE instance to complete the launch;

create a clone TEE instance based on the application TEE instance; and

provide the secret to the clone TEE instance by the application TEE instance, wherein the clone TEE instance includes a clone service to launch additional clone TEE instances and provide the secret to the additional clone TEE instances.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2020
From: TSIRKIN, MICHAEL
To: RED HAT, INC.
Reel/Frame 051965/0441 →
Continuity (1)
Related Publication 20210266148A1 · Aug 26, 2021