IP Library Granted Patent US 11,604,671
Granted Patent B2
US 11,604,671 · App. 16/824,538 · Granted Mar 14, 2023

Secure virtual machine and peripheral device communication

Inventor: Michael Tsirkin (Lexington, MA)
Assignee: Red Hat, Inc.
G06F9/45558G06F9/544G06F13/28H04L9/0825H04L9/0894H04L9/3247G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,604,671
App. No.
16/824,538
Granted
Mar 14, 2023
Kind
B2
Abstract

A method includes receiving, by a virtual machine running on a computing system, a public cryptographic key associated with a peripheral device of the computing system. The method further includes, responsive to validating the public cryptographic key, encrypting a cryptographic nonce value with the public cryptographic key. The cryptographic nonce value encrypted with the public cryptographic key is transmitted to the peripheral device. The method further includes using a shared cryptographic key generated from the cryptographic nonce value to access contents of a direct memory access (DMA) buffer utilized by the peripheral device.

Claims (30)

1. A method comprising:

receiving, by a virtual machine running on a computing system, a public cryptographic key associated with a peripheral device of the computing system;

responsive to validating the public cryptographic key, encrypting a cryptographic nonce value with the public cryptographic key;

transmitting, to the peripheral device, the cryptographic nonce value encrypted with the public cryptographic key; and

using a shared cryptographic key generated from the cryptographic nonce value to access contents of a direct memory access (DMA) buffer utilized by the peripheral device.

2. The method of claim 1 , wherein receiving the public cryptographic key comprises retrieving the public cryptographic key from a configuration space of the peripheral device.

3. The method of claim 1 , wherein the shared cryptographic key is used by the peripheral device and the computing system to access the contents of the DMA buffer.

4. The method of claim 1 , wherein validating the public cryptographic key comprises verifying an electronic signature of the public cryptographic key.

5. The method of claim 1 , further comprising:

using the shared cryptographic key to access contents of a configuration space of the peripheral device.

6. The method of claim 1 , wherein the peripheral device is provided by one of: an encrypted storage device or a networking device.

7. The method of claim 1 , further comprising:

receiving a request to provide data to the peripheral device;

encrypting the data with the shared cryptographic key; and

storing the data encrypted with the shared cryptographic key at the DMA buffer.

8. A non-transitory computer readable storage medium including instructions that, when executed by a processing device, cause the processing device to perform a method comprising:

receiving, by a virtual machine running on a computing system, a public cryptographic key associated with a peripheral device of the computing system;

responsive to validating the public cryptographic key, encrypting a cryptographic nonce value with the public cryptographic key;

transmitting, to the peripheral device, the cryptographic nonce value encrypted with the public cryptographic key; and

using a shared cryptographic key generated from the cryptographic nonce value to access contents of a direct memory access (DMA) buffer utilized by the peripheral device.

9. The non-transitory computer readable storage medium of claim 8 , wherein receiving the public cryptographic key comprises retrieving the public cryptographic key from a configuration space of the peripheral device.

10. The non-transitory computer readable storage medium of claim 8 , wherein the shared cryptographic key is used by the peripheral device and the processing device to access the contents of the DMA buffer.

11. The non-transitory computer readable storage medium of claim 8 , wherein validating the public cryptographic key comprises verifying an electronic signature of the public cryptographic key.

12. The non-transitory computer readable storage medium of claim 8 , wherein the processing device is further to perform:

using the shared cryptographic key to access contents of a configuration space of the peripheral device.

13. The non-transitory computer readable storage medium of claim 8 , wherein the peripheral device is provided by one of: an encrypted storage device or a networking device.

14. The non-transitory computer readable storage medium of claim 8 , wherein the processing device is further to perform:

receiving a request to provide data to the peripheral device;

encrypting the data with the shared cryptographic key; and

storing the data encrypted with the shared cryptographic key at the DMA buffer.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2020
From: TSIRKIN, MICHAEL
To: RED HAT, INC.
Reel/Frame 052172/0457 →
Continuity (1)
Related Publication 20210294628A1 · Sep 23, 2021
Cited By (1)
US 12,561,440