IP Library Granted Patent US 11,868,476
Granted Patent B2
US 11,868,476 · App. 17/344,358 · Granted Jan 9, 2024

Boot-specific key access in a virtual device platform

Inventors: Brian J. Vetter (Austin, TX); Phani Achanta (Austin, TX); Mohammad Salman Dhedhi (Round Rock, TX); Muhammad Irfan Azam (Reston, VA); Terrimane Shon Pritchett (Reston, VA)
Assignee: HYPORI, INC.
G06F21/575G06F21/33G06F21/602G06F21/604G06F21/72G06F21/107G06F21/1014
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,868,476
App. No.
17/344,358
Granted
Jan 9, 2024
Kind
B2
Abstract

Some embodiments may facilitate boot-specific key access to perform cryptographic operations. A first boot record and a second boot record may be generated independently in response to a request to boot a virtual device. The first and second boot records may be compared and in response to a match between the first boot record and the second boot record, an identify certificate may be obtained. Authorization to access and use a key for cryptographic operations may be obtained in response to a verification of the identity certificate by a cryptographic processor.

Claims (46)

1. A system for facilitating boot-specific key access in a virtual device platform, the system comprising:

the virtual device platform including circuitry configured to:

generate a first boot marker including a first boot identifier in response to a request to boot a virtual device;

generate a second boot marker including a second boot identifier in response to the request to boot the virtual device, where the second boot marker is associated with a trusted virtual device;

generate, by a first subsystem of the virtual device platform, a first boot record including the first boot identifier and a first boot process identifier, the first boot process identifier being associated with a booting of the virtual device;

generate, by a second subsystem of the virtual device platform, a second boot record including the second boot identifier and a second process identifier, the second process identifier being associated with a booting of the trusted virtual device;

obtain a dynamic credential in response to a match between the first boot record and the second boot record, where the match comprises:

a match between the first boot identifier and the second boot identifier, and

a match between the first process identifier and the second process identifier;

obtain an identity certificate, the identity certificate including an identifier of the virtual device and the identity certificate being generated in response to a verification of the dynamic credential; and

obtain, from a cryptographic processor, authorization to access a key in response to a verification of the identity certificate by the cryptographic processor.

2. The system of claim 1 , wherein the first boot marker and the second boot marker include information related to services associated with the virtual device platform.

3. The system of claim 1 , wherein the authorization to access the key is an authorization to allow the virtual device to access and use the key for cryptographic operations.

4. The system of claim 1 , wherein the first boot record expires after a predetermined amount of time, and wherein the circuitry is configured to compare the first boot record and the second boot record prior to an expiration of the predetermined amount of time.

5. The system of claim 1 , wherein the identity certificate expires after a predetermined amount of time, and wherein the identity certificate is verified by the cryptographic processor prior to an expiration of the predetermined amount of time.

6. The system of claim 1 , wherein the key is generated by the cryptographic processor and stored in a memory associated with the virtual device platform.

7. A method for facilitating boot-specific key access, the method comprising:

generating a first boot identifier in response to a request to boot a virtual device;

generating a second boot identifier in response to the request to boot the virtual device, where the second boot identifier is associated with a trusted virtual device;

generating and obtaining, by a first subsystem, a first boot record including the first boot identifier and a first boot process identifier, the first boot process identifier being associated with a booting of the virtual device;

generating, by a second subsystem, a second boot record including the second boot identifier and a second process identifier, the second process identifier being associated with a booting of the trusted virtual device;

comparing the first boot record and the second boot record and obtaining an identity certificate in response to a match between the first boot record and the second boot record, the identity certificate including an identifier of the virtual device, where the match comprises:

a match between the first boot identifier and the second boot identifier, and

a match between the first process identifier and the second process identifier; and

obtaining, from a cryptographic processor, authorization to use a key in response to a verification of the identity certificate by the cryptographic processor.

8. The method of claim 7 , the method further comprising:

obtaining, from a physical client device, an external security token, wherein the authorization to use the key is further in response to a verification of the external security token by the cryptographic processor.

9. The method of claim 7 , wherein the first boot record is obtained from a hypervisor of a virtual device platform.

10. The method of claim 7 , further comprising:

generating a first boot marker and a second boot marker that include information related to services associated with a virtual device platform that hosts the virtual device,

wherein the first boot record includes the first boot marker and the second boot record includes the second boot marker.

11. The method of claim 7 , wherein the identity certificate expires after a predetermined amount of time, and wherein the identity certificate is verified by the cryptographic processor prior to an expiration of the predetermined amount of time.

12. The method of claim 7 , wherein the authorization to use the key is an authorization to allow the virtual device to access and use the key for cryptographic operations.

13. The method of claim 7 , wherein the first boot record expires after a predetermined amount of time, and wherein the first boot record and the second boot record are compared prior to an expiration of the predetermined amount of time.

14. The method of claim 7 , wherein the key is generated by the cryptographic processor and wherein the key is stored in a memory separate from the cryptographic processor.

15. A system for facilitating boot-specific access to a service in a virtual device platform, the system comprising:

the virtual device platform including circuitry configured to:

generate a first boot marker including a first boot identifier in response to a request to boot a virtual device;

generate a second boot marker including a second boot identifier in response to the request to boot the virtual device, where the second boot marker is associated with a trusted virtual device;

generate, bya first subsystem of the virtual device platform, a first boot record including the first boot identifier and a first boot process identifier, the first boot process identifier being associated with a booting of the virtual device;

generate, bya second subsystem of the virtual device platform, a second boot record including the second boot identifier and a second process identifier, the second process identifier being associated with a booting of the trusted virtual device;

obtain an identity certificate, the identity certificate including an identifier of the virtual device, the identity certificate being obtained in response to a match between the first boot record and the second boot record, where the match comprises:

a match between the first boot identifier and the second boot identifier, and

a match between the first process identifier and the second process identifier; and

obtain authorization to access or use a service via the virtual device platform in response to a verification of the identity certificate.

16. The system of claim 15 , wherein the service is at least one of a cryptographic service, system update service, or data synchronization service.

Assignments (2)
CHANGE OF NAME Recorded Aug 12, 2023
From: HYPORI LLC
To: HYPORI, INC.
Reel/Frame 064573/0202 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2023
From: VETTER, BRIAN J.; ACHANTA, PHANI; DHEDHI, MOHAMMAD SALMAN; AZAM, MUHAMMAD IRFAN; PRITCHETT, TERRIMANE SHON
To: HYPORI, LLC
Reel/Frame 063417/0166 →
Continuity (2)
Provisional Application 63033777 · Jun 2, 2020
Related Publication 20220100862A1 · Mar 31, 2022