IP Library Granted Patent US 11,748,520
Granted Patent B2
US 11,748,520 · App. 17/083,002 · Granted Sep 5, 2023

Protection of a secured application in a cluster

Inventors: Krishnaprasad K (Bengaluru, IN); Gobind Vijayakumar (Trichy, IN); Murugan Sekar (Tindivanam, IN)
Assignee: Dell Products L.P.
G06F21/72G06F9/45533G06F21/57G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,748,520
App. No.
17/083,002
Granted
Sep 5, 2023
Kind
B2
Abstract

An information handling system may include at least one processor; and a memory coupled to the at least one processor. The information handling system may be configured to: execute an application on the at least one processor, wherein at least a portion of data of the application is stored encrypted in a secure enclave region of the memory; and securely transfer execution of the application to a second information handling system by: transmitting platform configuration register (PCR) measurement data to the second information handling system; and transmitting the data of the application to the second information handling system; wherein the PCR measurement data is usable by the second information handling system to perform a remote attestation, the remote attestation including verification of the PCR measurement data to confirm that the data of the application has not been changed.

Claims (48)

1. An information handling system comprising:

at least one processor; and

a memory coupled to the at least one processor;

wherein the information handling system is configured to:

execute an application within a guest operating system (OS) on the at least one processor, wherein at least a portion of data of the application is stored encrypted in a secure enclave region of the memory; and

securely transfer execution of the application to a second information handling system by:

performing first measurements relating to the information handling system by a physical cryptoprocessor of the information handling system,

performing second measurements relating to the guest OS by a virtual cryptoprocessor of the guest OS,

determining platform configuration register (PCR) measurement data that is based on the first and second measurements,

transmitting the PCR measurement data to the second information handling system, and

transmitting the at least a portion of data of the application to the second information handling system;

wherein the PCR measurement data is usable by the second information handling system to perform a remote attestation, the remote attestation including:

verification of the PCR measurement data to confirm that the at least a portion of data of the application has not been changed, and

verification that the guest OS and a physical cryptoprocessor of the second information handling system are bound and associated with a single physical platform.

2. The information handling system of claim 1 , wherein the secure enclave region is based on Software Guard Extensions (SGX) of the at least one processor.

3. The information handling system of claim 1 , wherein the information handling system and the second information handling system are nodes of a hyper-converged infrastructure (HCI) cluster.

4. The information handling system of claim 1 , wherein a hypervisor is configured to execute the guest OS.

5. The information handling system of claim 1 , wherein the physical cryptoprocessor is a Trusted Platform Module (TPM).

6. A method comprising:

an information handling system executing an application within a guest operating system (OS) on at least one processor of the information handling system,

wherein at least a portion of data of the application is stored encrypted in a secure enclave region of a memory of the information handling system; and

the information handling system securely transferring execution of the application to a second information handling system by:

performing first measurements relating to the information handling system by a physical cryptoprocessor of the information handling system,

performing second measurements relating to the guest OS by a virtual cryptoprocessor of the guest OS,

determining platform configuration register (PCR) measurement data that is based on the first and second measurements,

transmitting the PCR measurement data to the second information handling system, and

transmitting the at least a portion of data of the application to the second information handling system;

wherein the PCR measurement data is usable by the second information handling system to perform a remote attestation, the remote attestation including:

verification of the PCR measurement data to confirm that the at least a portion of data of the application has not been changed, and

verification that the guest OS and a physical cryptoprocessor of the second information handling system are bound and associated with a single physical platform.

7. The method of claim 6 , wherein the secure enclave region is based on Software Guard Extensions (SGX) of the at least one processor.

8. The method of claim 6 , wherein the information handling system and the second information handling system are nodes of a hyper-converged infrastructure (HCI) cluster.

9. The method of claim 6 , wherein the physical cryptoprocessor is a Trusted Platform Module (TPM).

10. An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable code thereon that is executable by a processor of an information handling system for:

executing an application within a guest operating system (OS) on the processor, wherein at least a portion of data of the application is stored encrypted in a secure enclave region of a memory of the information handling system; and

securely transferring execution of the application to a second information handling system by:

performing first measurements relating to the information handling system by a physical cryptoprocessor of the information handling system,

performing second measurements relating to the guest OS by a virtual cryptoprocessor of the guest OS,

determining platform configuration register (PCR) measurement data that is based on the first and second measurements,

transmitting the PCR measurement data to the second information handling system, and

transmitting the at least a portion of data of the application to the second information handling system;

wherein the PCR measurement data is usable by the second information handling system to perform a remote attestation, the remote attestation including:

verification of the PCR measurement data to confirm that the at least a portion of data of the application has not been changed, and

verification that the guest OS and a physical cryptoprocessor of the second information handling system are bound and associated with a single physical platform.

11. The article of claim 10 , wherein the secure enclave region is based on Software Guard Extensions (SGX) of the at least one processor.

12. The article of claim 10 , wherein the information handling system and the second information handling system are nodes of a hyper-converged infrastructure (HCI) cluster.

13. The article of claim 10 , wherein a hypervisor is configured to execute the guest OS.

14. The article of claim 10 , wherein the physical cryptoprocessor is a Trusted Platform Module (TPM).

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2020
From: K, KRISHNAPRASAD; VIJAYAKUMAR, GOBIND; SEKAR, MURUGAN
To: DELL PRODUCTS L.P.
Reel/Frame 054201/0225 →