IP Library Granted Patent US 12,306,932
Granted Patent B2
US 12,306,932 · App. 18/126,918 · Granted May 20, 2025

Attesting on-the-fly encrypted root disks for confidential virtual machines

Inventor: Daniel Pierres Berrange (Farnborough, GB)
Assignee: Red Hat, Inc.
G06F21/53G06F21/602G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,306,932
App. No.
18/126,918
Granted
May 20, 2025
Kind
B2
Abstract

Responsive to a request for an encrypted confidential virtual machine (CVM) disk image, an unencrypted CVM disk image, an image signature, and a public key associated with the image signature is obtained. The CVM disk image is encrypted to produce an encrypted CVM disk image. Full disk encryption (FDE) is applied against the encrypted CVM disk image to obtain an FDE header. A concatenation of the image signature, the public key associated with the image signature, and the FDE header is signed to obtain an image encryption service (IES) signature. The IES signature and associated certificate chain are written to the extensible firmware interface system partition (ESP) of the encrypted CVM disk image.

Claims (36)

1. A method comprising:

responsive to a request for an encrypted confidential virtual machine (CVM) disk image, obtaining an unencrypted CVM disk image, an image signature, and a public key associated with the image signature;

encrypting the CVM disk image to produce an encrypted CVM disk image;

applying full disk encryption (FDE) against the encrypted CVM disk image to obtain an FDE header;

signing, by a processing device, a concatenation of the image signature, the public key associated with the image signature, and the FDE header to obtain an image encryption service (IES) signature; and

writing the IES signature to an extensible firmware interface system partition (ESP) of the encrypted CVM disk image.

2. The method of claim 1 , further comprising writing the image signature to the ESP of the encrypted CVM disk image.

3. The method of claim 1 , further comprising writing, to the ESP, a certificate chain associated with the IES signature.

4. The method of claim 1 , wherein encrypting the CVM disk image comprises verifying the image signature.

5. The method of claim 1 , wherein the CVM disk image is encrypted using authenticated encryption with associated data (AEAD).

6. The method of claim 1 , wherein the image signature comprises an encrypted hash.

7. The method of claim 1 , wherein signing the concatenation of the image signature and the FDE header is performed using a private key of a private key/public key pair, the private key/public key pair associated with a certificate authority.

8. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

responsive to a request for an encrypted confidential virtual machine (CVM) disk image, obtain an unencrypted CVM disk image, an image signature, and a public key associated with the image signature;

encrypt the CVM disk image to produce an encrypted CVM disk image; apply full disk encryption (FDE) against the encrypted CVM disk image to obtain an FDE header;

sign a concatenation of the image signature, the public key associated with the image signature, and the FDE header to obtain an image encryption service (IES) signature; and

write the IES signature to an extensible firmware interface system partition (ESP) of the encrypted CVM disk image.

9. The system of claim 8 , wherein the processing device is further to write the image signature to the ESP of the encrypted CVM disk image.

10. The system of claim 8 , wherein the processing device is further to write, to the ESP, a certificate chain associated with the IES signature.

11. The system of claim 8 , wherein, to encrypt the CVM disk image, the processing device is further to verify the image signature.

12. The system of claim 8 , wherein the CVM disk image is encrypted using authenticated encryption with associated data (AEAD).

13. The system of claim 8 , wherein the image signature comprises an encrypted hash.

14. The system of claim 8 , wherein, to sign the concatenation of the image signature and the FDE header, the processing device is further to use a private key of a private key/public key pair, the private key/public key pair associated with a certificate authority.

15. A non-transitory computer-readable storage medium including instructions that, when executed by a processing device, cause the processing device to:

responsive to a request for an encrypted confidential virtual machine (CVM) disk image, obtain an unencrypted CVM disk image, an image signature, and a public key associated with the image signature;

encrypt the CVM disk image to produce an encrypted CVM disk image;

apply full disk encryption (FDE) against the encrypted CVM disk image to obtain an FDE header;

sign, by the processing device, a concatenation of the image signature, the public key associated with the image signature, and the FDE header to obtain an image encryption service (IES) signature; and

write the IES signature to an extensible firmware interface system partition (ESP) of the encrypted CVM disk image.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the instructions further cause the processing device to write the image signature to the ESP of the encrypted CVM disk image.

17. The non-transitory computer-readable storage medium of claim 15 , wherein, to encrypt the CVM disk image, the instructions further cause the processing device to verify the image signature.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the CVM disk image is encrypted using authenticated encryption with associated data (AEAD).

19. The non-transitory computer-readable storage medium of claim 15 , wherein the image signature comprises an encrypted hash.

20. The non-transitory computer-readable storage medium of claim 15 , wherein, to sign the concatenation of the image signature, the public key associated with the image signature, and the FDE header, the instructions further cause the processing device to use a private key of a private key/public key pair, the private key/public key pair associated with a certificate authority.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2025
From: BERRANGE, DANIEL PIERRES
To: RED HAT, INC.
Reel/Frame 070130/0968 →
Continuity (1)
Related Publication 20240330435A1 · Oct 3, 2024
References Cited (19)
US 11055428B1 · Clerget · 2021 [cited by examiner]
US 20110246778A1 · Duane · 2011 [cited by examiner]
US 20150278531A1 · Smith · 2015 [cited by examiner]
US 20160140343A1 · Novak · 2016 [cited by examiner]
US 20180295105A1 · Feng · 2018 [cited by examiner]
US 20190034218A1 · El-Moussa · 2019 [cited by examiner]
US 20210409199A1 · Tsirkin · 2021 [cited by applicant]
US 20220129544A1 · Touitou · 2022 [cited by examiner]
US 20220222100A1 · Srivastava et al. · 2022 [cited by applicant]
US 20220391494A1 · Yang et al. · 2022 [cited by applicant]
US 20220394015A1 · Han et al. · 2022 [cited by applicant]
US 20230106781A1 · Srinivasan · 2023 [cited by examiner]
US 20240184928A1 · Kim · 2024 [cited by examiner]
CN 111625871A · 2020 [cited by examiner]
WO 2021057024A1 · 2021 [cited by applicant]
Bossi S, Visconti A. What users should know about full disk encryption based on LUKS. InCryptology and Network Security: 14th International Conference, CANS 2015, Marrakesh, Morocco, Dec. 10-12, 2015, Proceedings 14 201… [cited by examiner]
Bro, Milan. “Authenticated and resilient disk encryption.” (2018). (Year: 2018). [cited by examiner]
Alarood, Alaa Abdulsalm et al. “IES: Hyper-chaotic plain image encryption scheme using improved shuffled confusion-diffusion”, Ain Shams Engineering Journal, vol. 13, Issue 3 (May 2022), pp. 1-12, https://doi.org/10.101… [cited by applicant]
Zhang, Shijie et al. “A Novel Plain-Text Related Image Encryption Algorithm Based on LB Compound Chaotic Map”, Mathematics 9, No. 21: 2778 (Nov. 2, 2021), pp. 1-25, https://doi.org/10.3390/math9212778. [cited by applicant]