IP Library Granted Patent US 11,314,882
Granted Patent B2
US 11,314,882 · App. 16/990,003 · Granted Apr 26, 2022

System of enclaves

Inventors: Nelly Porter (Kirkland, WA); David Benson Cross (Redmond, WA); Uday Ramesh Savagaonkar (Redmond, WA); Brandon S. Baker (Redmond, WA); Sergey Simakov (Redmond, WA)
Assignee: Google LLC
G06F21/6218G06F21/6245G06F21/64G06F21/70H04L63/08H04L63/126H04L67/10G06F2221/2105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,314,882
App. No.
16/990,003
Granted
Apr 26, 2022
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for instantiating and managing systems that utilize hierarchal enclaves in a cloud environment.

Claims (21)

1. A method performed by data processing apparatus, the method comprising:

launching a first root enclave and first component enclaves according to a first manifest;

launching a second root enclave and second component enclaves according to a second manifest providing first data to the first component enclaves; and

providing second data that is different from the first data to the second component enclaves;

accessing a first enclave manifest by the first root enclave, the first enclave manifest specifies, for each of a plurality of the first component enclaves, a particular role for each first component enclave;

accessing a second enclave manifest by the second root enclave, the second enclave manifest specifying, for each of a plurality of second component enclaves, a particular role for each second component enclave.

2. The method of claim 1 , wherein the first root enclave and the first component enclaves are launched in a private cloud, and the second root enclave and the second component enclaves are launched in a public cloud.

3. The method of claim 1 , wherein the first root enclave and the first component enclaves are launched in a first private cloud, and the second root enclave and the second component enclaves are launched in a second private cloud.

4. The method of claim 3 , wherein the first root enclave, the first component enclaves, the second root enclave, and the second component enclaves are launched in a server.

5. The method of claim 1 , comprising instantiating each of the first component enclaves, each first component enclave configured to perform its respective role.

6. The method of claim 1 , wherein the first root enclave and first component enclaves form a first enclave pod.

7. The method of claim 1 , comprising instantiating each of the second component enclaves, each second component enclave configured to perform its respective role.

8. The method of claim 1 , wherein the second root enclave and second component enclaves form a second enclave pod.

9. A method performed by data processing apparatus, the method comprising:

establishing an enclave pod comprising a root enclave, a manifest and two or more component enclaves, each component enclave assigned to perform a particular process, the manifest identifying the two or more component enclaves and the particular process assigned to each component enclave;

providing first data to a first component enclave from among the two or more component enclaves; and

providing second data that is different from the first data to a second component enclave from among the two or more component enclaves, wherein the root enclave verifies the two or more component enclaves using the manifest.

10. The method of claim 9 , wherein the root enclave and the first component enclave are launched in a private cloud, and the second component enclave is launched in a public cloud.

11. The method of claim 9 , wherein the root enclave and the first component enclave are launched in a first private cloud, and the second component enclave is launched in a second private cloud.

12. The method of claim 9 , comprising communicating, by the two or more component enclaves, over an authenticated channel with the root enclave.

13. The method of claim 12 , comprising communicating, by the two or more component enclaves, over an encrypted channel with the root enclave.

Assignments (2)
CHANGE OF NAME Recorded Aug 13, 2020
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 053482/0960 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2020
From: PORTER, NELLY; CROSS, DAVID BENSON; SAVAGAONKAR, UDAY RAMESH; BAKER, BRANDON S.; SIMAKOV, SERGEY
To: GOOGLE INC.
Reel/Frame 053471/0983 →
Continuity (3)
Division 15812875 · Nov 14, 2017
Provisional Application 62421905 · Nov 14, 2016
Related Publication 20200372166A1 · Nov 26, 2020
Cited By (1)
US 12,598,184