IP Library Granted Patent US 11,741,251
Granted Patent B2
US 11,741,251 · App. 17/699,554 · Granted Aug 29, 2023

System of enclaves

Inventors: Nelly Porter (Kirkland, WA); David Benson Cross (Redmond, WA); Uday Ramesh Savagaonkar (Redmond, WA); Brandon S. Baker (Redmond, WA); Sergey Simakov (Redmond, WA)
Assignee: Google LLC
G06F21/6218G06F21/6245G06F21/64G06F21/70H04L63/08H04L63/126H04L67/10G06F2221/2105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,741,251
App. No.
17/699,554
Granted
Aug 29, 2023
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for instantiating and managing systems that utilize hierarchal enclaves in a cloud environment.

Claims (26)

1. A method for creating a secure execution environment, comprising:

receiving a request to create a master enclave, the master enclave being associated with a private key of a customer and a public key of the customer;

instantiating the master enclave, as part of a public cloud service, such that it includes code and data provided by the customer;

distributing the code and data to one or more member enclaves according to a master manifest associated with the master enclave; and

operating the one or more member enclaves such that a first member enclave of the one or more member enclaves uses the public key to validate that a transaction is associated with the master enclave and that the master enclave is signed using the private key.

2. The method of claim 1 , comprising creating the master enclave in an on-premises or private cloud environment.

3. The method of claim 1 , wherein receiving comprises receiving an upload of the master enclave that is signed with the private key of the customer.

4. The method of claim 3 , wherein the master enclave is empty.

5. The method of claim 4 , wherein empty comprises the master enclave having no code and no data.

6. The method of claim 1 , wherein receiving comprises receiving the public key via another secure channel than a channel over which the private key of the customer is received.

7. The method of claim 1 , wherein the master manifest specifies parameters comprising a member enclave location, a hierarchical relationship between the one or more member enclaves, or an availability of the one or more member enclaves.

8. The method of claim 7 , wherein distributing comprises distributing the code and data to the one or more member enclaves according to one or more of the parameters.

9. A system, comprising:

a plurality of computing devices in communication with each other;

a non-transitory computer readable medium storing instructions executable by the plurality of computing devices, the instructions causing the plurality of computing devices to perform operations comprising:

receiving a request to create a master enclave, the master enclave being associated with a private key of a customer and a public key of the customer;

instantiating the master enclave, as part of a public cloud service, such that it includes code and data provided by the customer;

distributing the code and data to one or more member enclaves according to a master manifest associated with the master enclave; and

operating the one or more member enclaves such that a first member enclave of the one or more member enclaves uses the public key to validate that a transaction is associated with the master enclave and that the master enclave is signed using the private key.

10. The system of claim 9 , comprising creating the master enclave in an on-premises or private cloud environment.

11. The system of claim 9 , wherein receiving comprises receiving an upload of the master enclave that is signed with the private key of the customer.

12. The system of claim 11 , wherein the master enclave is empty.

13. The system of claim 12 , wherein empty comprises the master enclave having no code and no data.

14. The system of claim 9 , wherein receiving comprises receiving the public key via another secure channel than a channel over which the private key of the customer is received.

15. The system of claim 9 , wherein the master manifest specifies parameters comprising a member enclave location, a hierarchical relationship between the one or more member enclaves, or an availability of the one or more member enclaves.

16. The system of claim 15 , wherein distributing comprises distributing the code and data to the one or more member enclaves according to one or more of the parameters.

Assignments (2)
CHANGE OF NAME Recorded Mar 25, 2022
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 059511/0080 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2022
From: PORTER, NELLY; CROSS, DAVID BENSON; SAVAGAONKAR, UDAY RAMESH; BAKER, BRANDON S.; SIMAKOV, SERGEY
To: GOOGLE INC.
Reel/Frame 059390/0487 →
Continuity (4)
Continuation 16990003 · Aug 11, 2020
Division 15812875 · Nov 14, 2017
Provisional Application 62421905 · Nov 14, 2016
Related Publication 20220215112A1 · Jul 7, 2022