IP Library Granted Patent US 12,323,404
Granted Patent B2
US 12,323,404 · App. 17/709,054 · Granted Jun 3, 2025

Securing data for dynamic environment

Inventors: Michael G. Varteresian (Lexington, MA); Shaojuan Lin (Shanghai, CN); Eric O'Callaghan (Macroom, IE); Wenfeng Li (Shanghai, CN)
Assignee: Dell Products L.P.
H04L63/068G06F9/4856G06F21/53G06F21/602G06F21/6218H04L9/3215
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,323,404
App. No.
17/709,054
Granted
Jun 3, 2025
Kind
B2
Abstract

An information handling system may include at least one processor and a memory. The information handling system may be configured to: store a cryptographic lockbox that is secured by a set of secrets and that is accessible from a virtual machine, wherein the set of secrets comprises a first subset of one or more secrets based on a hardware environment of the information handling system and a second subset of one or more secrets based on a virtualized environment associated with the virtual machine; migrate the virtual machine to a different information handling system, wherein the migration is configured not to alter the second subset; and access the cryptographic lockbox from the migrated virtual machine.

Claims (27)

1. An information handling system comprising:

at least one processor; and

a memory;

wherein the information handling system is configured to:

store a cryptographic lockbox that is a component of a virtual machine, wherein the cryptographic lockbox is secured by a set of secrets and is accessible from the virtual machine, and wherein the set of secrets comprises a first subset of one or more secrets based on a hardware environment of the information handling system and a second subset of one or more secrets based on a virtualized environment associated with the virtual machine, wherein the second subset is inaccessible to non-privileged users of the information handling system;

migrate the virtual machine to a different information handling system, wherein the migration is configured not to alter the second subset; and

access the cryptographic lockbox from the migrated virtual machine.

2. The information handling system of claim 1 , wherein the hardware environment comprises a hyper-converged infrastructure cluster.

3. The information handling system of claim 2 , wherein the first subset comprises a virtual object associated with the cluster.

4. The information handling system of claim 1 , wherein the second subset comprises an attribute of the virtual machine.

5. The information handling system of claim 1 , wherein the cryptographic lockbox is secured by concatenating the secrets of the first and second subsets to generate a concatenated result, deriving a cryptographic key from the concatenated result, and encrypting the cryptographic lockbox with the cryptographic key.

6. A computer-implemented method comprising:

storing a cryptographic lockbox that is a component of a virtual machine, wherein the cryptographic lockbox is secured by a set of secrets and is accessible from the virtual machine, and wherein the set of secrets comprises a first subset of one or more secrets based on a hardware environment of the information handling system and a second subset of one or more secrets based on a virtualized environment associated with the virtual machine, wherein the second subset is inaccessible to non-privileged users of the information handling system;

migrating the virtual machine to a different information handling system, wherein the migration is configured not to alter the second subset; and

accessing the cryptographic lockbox from the migrated virtual machine.

7. The method of claim 6 , wherein the hardware environment comprises a hyper-converged infrastructure cluster.

8. The method of claim 7 , wherein the first subset comprises a virtual object associated with the cluster.

9. The method of claim 6 , wherein the second subset comprises an attribute of the virtual machine.

10. The method of claim 6 , wherein the cryptographic lockbox is secured by concatenating the secrets of the first and second subsets to generate a concatenated result, deriving a cryptographic key from the concatenated result, and encrypting the cryptographic lockbox with the cryptographic key.

11. An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable instructions thereon that are executable by a processor of an information handling system for:

storing a cryptographic lockbox that is a component of a virtual machine, wherein the cryptographic lockbox is secured by a set of secrets and is accessible from the virtual machine, and wherein the set of secrets comprises a first subset of one or more secrets based on a hardware environment of the information handling system and a second subset of one or more secrets based on a virtualized environment associated with the virtual machine, wherein the second subset is inaccessible to non-privileged users of the information handling system;

migrating the virtual machine to a different information handling system, wherein the migration is configured not to alter the second subset; and

accessing the cryptographic lockbox from the migrated virtual machine.

12. The article of claim 11 , wherein the hardware environment comprises a hyper-converged infrastructure cluster.

13. The article of claim 12 , wherein the first subset comprises a virtual object associated with the cluster.

14. The article of claim 11 , wherein the second subset comprises an attribute of the virtual machine.

15. The article of claim 11 , wherein the cryptographic lockbox is secured by concatenating the secrets of the first and second subsets to generate a concatenated result, deriving a cryptographic key from the concatenated result, and encrypting the cryptographic lockbox with the cryptographic key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2022
From: VARTERESIAN, MICHAEL G.; LIN, SHAOJUAN; O'CALLAGHAN, ERIC; LI, WENFENG
To: DELL PRODUCTS L.P.
Reel/Frame 059448/0617 →
Continuity (1)
Related Publication 20230315866A1 · Oct 5, 2023
References Cited (19)
US 8572410B1 · Tkacik · 2013 [cited by applicant]
US 8977842B1 · McCorkendale · 2015 [cited by applicant]
US 9667416B1 · Machani · 2017 [cited by examiner]
US 10922420B2 · Allo · 2021 [cited by examiner]
US 11849037B1 · Tong · 2023 [cited by applicant]
US 20090132804A1 · Paul · 2009 [cited by applicant]
US 20120204030A1 · Nossik · 2012 [cited by applicant]
US 20130191648A1 · Bursell · 2013 [cited by applicant]
US 20130326110A1 · Tsirkin et al. · 2013 [cited by applicant]
US 20180145955A1 · Nirwal · 2018 [cited by examiner]
US 20180276019A1 · Ali · 2018 [cited by applicant]
US 20190065756A1 · Tsirkin · 2019 [cited by applicant]
US 20190332421A1 · Kozlowski et al. · 2019 [cited by applicant]
US 20200034167A1 · Parthasarathy · 2020 [cited by applicant]
US 20210173685A1 · Tsirkin · 2021 [cited by applicant]
US 20220103520A1 · Chifor · 2022 [cited by applicant]
CN 102208001A · 2011 [cited by examiner]
Non-Final Office Action, U.S. Appl. No. 17/584,884 mailed Apr. 1, 2024, U.S. Patent and Trademark Office. [cited by applicant]
Final Office Action, U.S. Appl. No. 17/584,884 mailed Aug. 26, 2024, U.S. Patent and Trademark Office. [cited by applicant]