IP Library › Granted Patent US 12,225,140
Granted Patent B2
US 12,225,140 · App. 18/214,209 · Granted Feb 11, 2025

Method and apparatus for external control planes to cryptographically trust software artifacts launched at public cloud providers

Inventors: Michal Davidson (Beir Shemesh, IL); Dominique Prunier (Montreal, CA); Alan White (Glasgow, GB)
Assignee: Dell Products L.P.
H04L9/3268H04L9/0825H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,140
App. No.
18/214,209
Filed
Jun 26, 2023
Granted
Feb 11, 2025
Kind
B2
Art Unit
2435
USPC
713/156
Abstract

A system, method, and computer-readable medium for performing a data center monitoring and management operation. The data center monitoring and management operation includes: submitting a request for a workload instance to a cloud service provider; establishing a secure communication channel between the cloud service provider and a data center monitoring and management console; exchanging information between the cloud service provider and the data center monitoring and management console via the secure communication channel, the information including a verifiable workload instance identity; and, using the verifiable workload instance identity to authenticate a workload instance provided by the cloud service provider.

Claims (58)

1. A computer-implementable method for performing a data center monitoring and management operation, comprising:

submitting a request for a workload instance to a cloud service provider;

establishing a secure communication channel between the cloud service provider and a data center monitoring and management console;

exchanging information between the cloud service provider and the data center monitoring and management console via the secure communication channel, the information including a verifiable workload instance identity, the verifiable workload instance identity being unique, linked by the cloud service provider to the workload instance and cryptographically verifiable; and,

using the verifiable workload instance identity to authenticate a workload instance provided by the cloud service provider, the data center monitoring and management console authenticating the workload instance.

2. The method of claim 1 , wherein:

the secure connection is established using a public key provided by the cloud service provider.

3. The method of claim 2 , wherein:

the data center monitoring and management console comprises a workload authentication system; and,

the workload authentication system verifies a signature of the cloud service provider using the public key provided by the cloud service provider and stores with verifiable workload instance identity.

4. The method of claim 2 , wherein:

the cloud service provider generates a certificate signing request (CSR) when establishing the secure communication channel between the cloud service provider and a data center monitoring and management console.

5. The method of claim 4 , wherein:

the workload authentication system processes the CSR to generate a signed certificate containing an authenticated workload identity.

6. The method of claim 1 , further comprising:

initiating an instance of a requested workload; and,

retrieving the verifiable instance identity when the instance of the requested workload is initiated.

7. A system comprising:

a processor;

a data bus coupled to the processor; and,

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

submitting a request for a workload instance to a cloud service provider;

establishing a secure communication channel between the cloud service provider and a data center monitoring and management console;

exchanging information between the cloud service provider and the data center monitoring and management console via the secure communication channel, the information including a verifiable workload instance identity, the verifiable workload instance identity being unique, linked by the cloud service provider to the workload instance and cryptographically verifiable; and,

using the verifiable workload instance identity to authenticate a workload instance provided by the cloud service provider, the data center monitoring and management console authenticating the workload instance.

8. The system of claim 7 , wherein:

the secure connection is established using a public key provided by the cloud service provider.

9. The system of claim 8 , wherein:

the data center monitoring and management console comprises a workload authentication system; and,

the workload authentication system verifies a signature of the cloud service provider using the public key provided by the cloud service provider and stores with verifiable workload instance identity.

10. The system of claim 8 , wherein:

the cloud service provider generates a certificate signing request (CSR) when establishing the secure communication channel between the cloud service provider and a data center monitoring and management console.

11. The system of claim 10 , wherein:

the workload authentication system processes the CSR to generate a signed certificate containing an authenticated workload identity.

12. The system of claim 7 , wherein the instructions executable by the processor are further configured for:

initiating an instance of a requested workload; and,

retrieving the verifiable instance identity when the instance of the requested workload is initiated.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

submitting a request for a workload instance to a cloud service provider;

establishing a secure communication channel between the cloud service provider and a data center monitoring and management console;

exchanging information between the cloud service provider and the data center monitoring and management console via the secure communication channel, the information including a verifiable workload instance identity, the verifiable workload instance identity being unique, linked by the cloud service provider to the workload instance and cryptographically verifiable; and,

using the verifiable workload instance identity to authenticate a workload instance provided by the cloud service provider, the data center monitoring and management console authenticating the workload instance.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the secure connection is established using a public key provided by the cloud service provider.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

the data center monitoring and management console comprises a workload authentication system; and,

the workload authentication system verifies a signature of the cloud service provider using the public key provided by the cloud service provider and stores with verifiable workload instance identity.

16. The non-transitory, computer-readable storage medium of claim 14 , wherein:

the cloud service provider generates a certificate signing request (CSR) when establishing the secure communication channel between the cloud service provider and a data center monitoring and management console.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the workload authentication system processes the CSR to generate a signed certificate containing an authenticated workload identity.

18. The non-transitory, computer-readable storage medium of claim 17 , wherein the computer executable instructions are further configured for:

initiating an instance of a requested workload; and,

retrieving the verifiable instance identity when the instance of the requested workload is initiated.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2023
From: DAVIDSON, MICHAL; PRUNIER, DOMINIQUE; WHITE, ALAN
To: DELL PRODUCTS L.P.
Reel/Frame 064061/0217 →
Continuity (1)
Related Publication 20240430106A1 · Dec 26, 2024
References Cited (14)
US 10931741B1 · Liguori · 2021 [cited by examiner]
US 20120324527A1 · Brown · 2012 [cited by examiner]
US 20130275744A1 · Resch · 2013 [cited by examiner]
US 20130275776A1 · Baptist · 2013 [cited by examiner]
US 20150365238A1 · Hui · 2015 [cited by examiner]
US 20160280371A1 · Canavor · 2016 [cited by examiner]
US 20170359170A1 · Bower, III · 2017 [cited by examiner]
US 20190123905A1 · Kirner · 2019 [cited by examiner]
US 20200142735A1 · Maciocco · 2020 [cited by examiner]
US 20200412720A1 · Siefker · 2020 [cited by examiner]
US 20210124606A1 · Alcorn · 2021 [cited by examiner]
US 20220019478A1 · Sridharan · 2022 [cited by examiner]
US 20220103361A1 · Kirner · 2022 [cited by examiner]
US 20240333497A1 · Khan · 2024 [cited by examiner]