IP Library › Granted Patent US 12,056,248
Granted Patent B1
US 12,056,248 · App. 18/230,101 · Granted Aug 6, 2024

Enclave-based cryptography services in edge computing environments

Inventor: Peter Buonora (Hopkinton, MA)
Assignee: Amazon Technologies, Inc.
G06F21/602G06F8/60G06F21/12G06F21/44G06F21/62H04L9/3226G06F21/1064G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,056,248
App. No.
18/230,101
Granted
Aug 6, 2024
Kind
B1
Abstract

Systems and methods for providing cryptographic services. A cryptography service obtains a request to provision a computing device to perform cryptographic operations. The cryptography service generates executable code for a protected execution environment. The computing device obtains and executes the executable code. The computing device fulfills requests for cryptographic operations in the protected execution environment.

Claims (47)

1. A computer-implemented method, comprising:

obtaining executable code based at least in part on a cryptographic key, the executable code, as a result of being executed by a device, to cause the device to provision a protected execution environment used to process one or more cryptographic requests;

executing, by the device, the executable code to process a cryptographic request associated with at least one computing device;

based on the cryptographic request, performing at least one cryptographic operation using the cryptographic key within the protected execution environment; and

providing a result of the cryptographic operation, the result obtainable by the at least one computing device.

2. The computer-implemented method of claim 1 , further comprising:

using an indication of the cryptographic key to obtain the cryptographic key;

generating a trusted portion of the executable code, wherein the trusted portion of the executable code comprises:

a set of entry points invokable from an untrusted portion of the executable code; and

a set of functions that, as a result of execution, perform a set of cryptographic operations using the cryptographic key; and

generating an untrusted portion of the executable code that, as a result of execution, invokes the set of entry points to fulfill requests to perform cryptographic operations.

3. The computer-implemented method of claim 1 , wherein the protected execution environment is an enclave.

4. The computer-implemented method of claim 1 , wherein the cryptographic request is obtained through one or more local networks.

5. A system, comprising:

one or more processors; and

memory that stores computer-executable instructions that are executable by the one or more processors to cause the system to:

obtain executable code based at least in part on a cryptographic key, the executable code, as a result of being executed by a device, to cause the device to provision a protected execution environment used to process one or more cryptographic requests using the cryptographic key;

execute, by the device, the executable code to process a cryptographic request associated with at least one computing device;

based on the cryptographic request, perform at least one cryptographic operation using the cryptographic key within the protected execution environment; and

provide a result of the cryptographic operation, the result obtainable by the at least one computing device.

6. The system of claim 5 , wherein the instructions further include instructions that, as a result of execution by the one or more processors, cause the system to:

detect occurrence of a key rotation indicating the cryptographic key has been updated to provide an updated cryptographic key; and

obtain an updated executable code based at least in part on the updated cryptographic key.

7. The system of claim 6 , wherein the updated executable code encodes at least the cryptographic key and the updated cryptographic key, and further wherein the cryptographic key is usable for decryption requests and unusable for encryption requests.

8. The system of claim 5 , wherein the cryptographic request includes an encryption request, a decryption request, or a cryptographic key generation request.

9. The system of claim 5 , wherein the instructions further include instructions that, as a result of execution by the one or more processors, cause the system to decrypt a ciphertext to obtain the cryptographic key.

10. The system of claim 5 , wherein the instructions further include instructions that, as a result of execution by the one or more processors, cause the system to:

obtain another executable code based at least in part on another cryptographic key, wherein the other executable code, as a result of being executed by the device, to cause the device to provision another protected execution environment.

11. The system of claim 10 , wherein the other protected execution environment is usable in addition to the protected execution environment for processing the one or more cryptographic requests.

12. The system of claim 5 , wherein the executable code comprises cryptographic material for authenticating the executable code.

13. A non-transitory computer-readable storage medium storing thereon executable instructions that, as a result of being executed by one or more processors of a computer system, cause the computer system to:

obtain executable code based at least in part on a cryptographic key, the executable code, as a result of being executed by a device, to cause the device to provision a protected execution environment to process one or more cryptographic requests using the cryptographic key;

execute the executable code to obtain a cryptographic request associated with at least one computing device;

based on the cryptographic request, perform one or more cryptographic operations using the cryptographic key; and

provide a result of the one or more cryptographic operations, the result obtainable by the at least one computing device.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the executable instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to at least:

detect occurrence of a key rotation indicating the cryptographic key has been updated to provide an updated cryptographic key;

generate an updated executable code based at least in part on the updated cryptographic key; and

provide the updated executable code to the device.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the executable instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to encode, by the updated executable code, at least the cryptographic key and the updated cryptographic key, wherein the cryptographic key is usable for decryption requests and unusable for encryption requests.

16. The non-transitory computer-readable storage medium of claim 13 , wherein the cryptographic request an encryption request, a decryption request, or a cryptographic key generation request.

17. The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further include instructions that, as a result of execution by the one or more processors, cause the system to decrypt a ciphertext to obtain the cryptographic key.

18. The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to at least:

obtain another request, the other request indicating another cryptographic key to be supported by the device; and

generate another executable code based at least in part on the other cryptographic key, wherein the other executable code, as a result of being executed by the device, causes the device to provision another protected execution environment.

19. The non-transitory computer-readable storage medium of claim 18 , wherein the other protected execution environment is usable in addition to the protected execution environment for processing the cryptographic requests.

20. The non-transitory computer-readable storage medium of claim 13 , wherein the executable code comprises cryptographic material for authenticating the executable code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2023
From: BUONORA, PETER
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 064488/0859 →
Continuity (2)
Continuation 17964625 · Oct 12, 2022
Continuation 17103533 · Nov 24, 2020