IP Library Granted Patent US 11,501,005
Granted Patent B2
US 11,501,005 · App. 17/002,966 · Granted Nov 15, 2022

Security system for using shared computational facilities

Inventor: Bryan L Lapworth (Derby, GB)
Assignee: ROLLS-ROYCE plc
G06F21/602G06F9/48G06F21/78H04L9/083H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,501,005
App. No.
17/002,966
Granted
Nov 15, 2022
Kind
B2
Abstract

A method and system for performing computational jobs securely on a shared computing resource. Data files for the computational job are encrypted on a secure system and the encrypted data files are stored in a data store on the shared computing resource. A key distribution server is established using a secure enclave on a front end of the shared computing resource. Cryptographic keys and application binaries are transferred to the enclave of the shared computing resource using a session key. The computational job is run using an application launcher on compute nodes of an untrusted execution environment of the shared computing resource, the application launcher obtaining the application binaries and the cryptographic keys from the key distribution server.

Claims (29)

1. A method of performing computational jobs securely on a shared computing resource, comprising:

encrypting data files for a computational job on a secure system and storing the encrypted data files in a data store on the shared computing resource;

establishing a key distribution server using a secure enclave on a front end of the shared computing resource;

transferring cryptographic keys and application binaries to the secure enclave of the shared computing resource using a session key;

running the computational job via an application launcher on compute nodes of an untrusted execution environment of the shared computing resource, said application launcher obtaining the application binaries for the computational job and the cryptographic keys for decrypting the encrypted data files from the key distribution server.

2. The method of claim 1 , wherein the application binaries are obtained at a launch-time of the computational job and are not stored in a non-volatile data store of the shared computing resource.

3. The method of claim 1 , wherein a data file cryptographic key is transferred between the front end and the untrusted execution environment of the shared computing resource at launch-time of the computational job via the application launcher whose authenticity is verified without reference to a certificating authority.

4. The method of claim 1 , comprising holding the obtained cryptographic keys in a secure memory of the application launcher, which is accessed via a call back routine.

5. The method of claim 1 , wherein multiple session keys are used for transfer of data files, application binaries and/or data cryptographic keys to the shared computing resource and/or execution environment thereof.

6. The method of claim 1 , wherein the application binaries are loaded into anonymous RAM in the untrusted execution environment.

7. The method of claim 1 , wherein there is a time delay of hours, days or weeks between storing the encrypted data files in the data store on the shared computing resource and running the computational job on the shared computing resource.

8. The method of claim 7 , wherein the key distribution server is maintained on the front end of the shared computing resource during said time delay and/or wherein the application launcher is at rest on a non-volatile data store of the shared computing resource.

9. The method of claim 1 , wherein the application launcher comprises a key client and/or key call back routine/module.

10. The method of claim 1 , wherein the application binaries and/or the application launcher are protected by obfuscation.

11. The method of claim 1 , wherein verification of the application binaries is performed at a launch-time of the computational job by attestation and/or checksum verification.

12. The method of claim 1 , wherein each compute node comprises a key client and implements a key call back routine.

13. The method of claim 1 , wherein a first compute node of the untrusted execution environment communicates with the key distribution server and the session key is exchanged between the first compute node and a plurality of other compute nodes of the untrusted execution environment at launch-time.

14. The method of claim 1 , wherein the shared computing resource comprises a plurality of different sets of data files pertaining to different computational jobs that are queued for running on the shared computing resource, each of a plurality of computational jobs, including the computational job, being run sequentially upon the compute nodes becoming available after completing a previous computational job in the queue.

15. A data carrier or data storage medium comprising machine readable instructions for one or more processor of an execution environment of a shared computational system to operate as an application launcher for a computational job run using the method of claim 1 , wherein the application launcher (i) comprises a key client for communication with the key distribution server on the front end of the shared computational system and (ii) obtains the application binaries at the launch-time for performing the computational job.

16. The method of claim 1 , further comprising

registering the application launcher using the key distribution server when the application launcher is launched.

17. A shared computational system arranged to perform computational jobs instigated by a trusted system, the shared computational system comprising:

a non-volatile data store arranged to store encrypted data files for a planned computational job;

a key distribution server on a front end of the shared computational system having a secure enclave;

an execution environment comprising multiple compute nodes and a key client for communication with the key distribution server so as to enable decryption of the encrypted data files and application binaries at a launch-time for performing the planned computational job on the multiple compute nodes; and

an application launcher on compute nodes of a shared computing resource including the execution environment, said application launcher arranged to obtain the application binaries and the cryptographic keys from the key distribution server.

18. The shared computational system of claim 17 , wherein the application binaries are obtained at a launch-time of the planned computational job and are not stored in a non-volatile data store of the shared computing resource.

19. The shared computational system of claim 17 , wherein the key distribution server is maintained on the front end of the shared computing resource during a time delay between storing the encrypted data files in the non-volatile data store and running the planned computational job and/or wherein the application launcher is at rest on a non-volatile data store of the shared computing resource.

20. The shared computational system of claim 17 , wherein the shared computing resource comprises a plurality of different sets of data files pertaining to different computational jobs that are queued for running on the shared computational resource, each of the computational jobs being run sequentially upon the compute nodes becoming available after completing a previous computational job in the queue.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2020
From: LAPWORTH, BRYAN L
To: ROLLS-ROYCE PLC
Reel/Frame 053600/0137 →
Priority Claims (1)
GB 1912629 · Sep 3, 2019 · national
Continuity (1)
Related Publication 20210064765A1 · Mar 4, 2021