IP Library › Granted Patent US 12,591,655
Granted Patent B2
US 12,591,655 · App. 18/552,877 · Granted Mar 31, 2026

Systems and methods of protecting secrets in use with containerized applications

Inventors: Michael Joseph Quinlan (San Francisco, CA); Ajit Gaddam (San Francisco, CA); Rashmi Krishnan (San Francisco, CA)
Assignee: Visa International Service Association
G06F21/44G06F9/45558G06F21/53G06F21/6218H04L9/0894H04L9/3271G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,591,655
App. No.
18/552,877
Granted
Mar 31, 2026
Kind
B2
Abstract

Data encryption keys (and other sensitive data) can be secured during use by a key protection service that performs cryptographic operations on behalf of a client application. The key protection service can be implemented as a lightweight virtual machine that appears externally as a container and that can be executed in a secured environment. The lightweight virtual machine can include containerized processes to support an application program interface to interact with the client application and an attestation client to interact with a secured key storage system external to the secured environment.

Claims (52)

1 . A method implemented in a virtual machine that executes program code in a processor of a computer system, the method comprising:

receiving a request to access a data encryption key from a client app via an application program interface executing in the virtual machine;

establishing a secure connection between a key storage system and an attestation client executing in the virtual machine;

requesting, by the attestation client, via the secure connection, the data encryption key from the key storage system;

receiving, by the attestation client, via the secure connection, an attestation challenge from the key storage system;

generating, by the attestation client, a response to the attestation challenge, wherein the response includes a data block generated by the processor based on the program code being executed in the virtual machine;

sending, by the attestation client, via the secure connection, the response to the key storage system;

receiving, via the secure connection, the data encryption key from the key storage system;

storing the data encryption key in a secured memory area of the virtual machine; and

using the data encryption key to respond to a subsequent request received from the client app via the application program interface.

2 . The method of claim 1 wherein the key storage system includes a key management service that generates the attestation challenge, determines whether the response to the attestation challenge succeeds, and retrieves the data encryption key from a secure key storage device only if the response to the attestation challenge succeeds.

3 . The method of claim 2 wherein the key management service determines whether the client app is authorized to receive the data encryption key prior to generating the attestation challenge and wherein the attestation challenge is generated only if the client app is authorized to receive the data encryption key.

4 . The method of claim 1 wherein the virtual machine is executed as a secure virtual machine.

5 . The method of claim 4 wherein the data block generated by the processor includes a launch digest based on an unencrypted image of the secure virtual machine as installed in a system memory of the computer system.

6 . A computer-readable storage medium having stored therein program code instructions that, when executed by a processor of a computer system, cause the computer system to perform a method comprising:

establishing a secure virtual machine in the computer system;

executing an application program interface within the secure virtual machine;

receiving a request to access a data encryption key from a client app via the application program interface;

establishing a secure connection to a key storage system by an attestation client executing in the virtual machine;

requesting the data encryption key by the attestation client via the secure connection;

receiving, by the attestation client, an attestation challenge from the key storage system via the secure connection;

generating, by the attestation client, a response to the attestation challenge, wherein the response includes a data block generated by the processor based on the program code being executed in the virtual machine;

sending, by the attestation client, via the secure connection, the response to the key storage system;

receiving, via the secure connection, the data encryption key from the key storage system;

storing the data encryption key in a secured memory area of the virtual machine; and

using the data encryption key to respond to a subsequent request received from the client app via the application program interface.

7 . The computer-readable storage medium of claim 6 wherein the key storage system includes one or more of a hardware storage module or a data vault.

8 . The computer-readable storage medium of claim 6 wherein the processor supports creation of a secure virtual machine in which all data and program code associated with the secure virtual machine is protected from access by any process executing on the processor outside the secure virtual machine.

9 . The computer-readable storage medium of claim 6 wherein the virtual machine is implemented as a pod that appears externally as a container.

10 . The computer-readable storage medium of claim 9 wherein the application program interface is exposed as a device plugin by the pod.

11 . The computer-readable storage medium of claim 6 wherein the data block generated by the processor includes a launch digest based on an unencrypted image of the secure virtual machine as installed in a system memory of the computer system.

12 . The computer-readable storage medium of claim 6 wherein generating the response to the attestation challenge includes digitally signing the response.

13 . A system comprising:

a secure memory to store program code and data;

a communication interface to communicate with one or more client applications; and

a processor coupled to the secure memory and configured to execute the stored program code,

wherein the stored program code includes a virtual machine compatible with the Open Container Initiative and the virtual machine includes:

a first module exposing an application program interface for a client application;

a second module implementing a set of key-using functions that are invocable via the client application program interface; and

a third module implementing an attestation client configured to establish a secure connection with a key storage system to request execution of key-management operations; to receive and respond to attestation challenges from the key storage system, wherein the response to each attestation challenge includes an attestation report comprising a data block generated by the processor based on the program code being executed in the virtual machine; and to store, in the secure memory, one or more data encryption keys received from the key storage system responsive to execution of the key-management operation.

14 . The system of claim 13 wherein the virtual machine is implemented as a pod that appears externally as a container.

15 . The system of claim 14 wherein the application program interface is exposed as a device plugin by the pod.

16 . The system of claim 13 wherein the processor supports creation of a secure virtual machine in which all data and program code associated with the secure virtual machine is protected from access by any process executing on the processor outside the secure virtual machine.

17 . The system of claim 13 wherein the key storage system includes:

a secure key storage device including one or more of a hardware storage module or a data vault; and

a key management service coupled to the secure key storage device and configured to:

receive a request to perform the key-management operation from the attestation client, the request including credentials of a client app;

determine, based on an authorization policy stored in the secure key storage device, whether the client app is authorized to perform the requested key-management operation;

generate an attestation challenge to the attestation client only if the client app is authorized to perform the requested key-management operation;

receive a response to the attestation challenge from the attestation client; and

perform the requested key-management operation only if the response to the attestation challenge is accepted.

18 . The system of claim 13 further comprising a system memory, wherein the attestation client is further configured such that the data block generated by the processor includes a launch digest based on an unencrypted image of the virtual machine as installed in the system memory of the system.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE CORRECT SIGNATURE DATE OF INVENTOR MICHAEL JOSEPH QUINLAN TO 05/07/2022 PREVIOUSLY RECORDED AT REEL: 065055 FRAME: 0082. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 5, 2023
From: QUINLAN, MICHAEL JOSEPH; GADDAM, AJIT; KRISHNAN, RASHMI
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 065155/0928 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2023
From: QUINLAN, MICHAEL JOSEPH; GADDAM, AJIT; KRISHNAN, RASHMI
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 065055/0082 →
Continuity (2)
Provisional Application 63167459 · Mar 29, 2021
Related Publication 20240193255A1 · Jun 13, 2024
References Cited (19)
US 10303899B2 · Durham · 2019 [cited by examiner]
US 10621350B2 · Novak · 2020 [cited by examiner]
US 20090172781A1 · Masuoka et al. · 2009 [cited by applicant]
US 20140089658A1 · Raghuram · 2014 [cited by examiner]
US 20140289535A1 · Gan · 2014 [cited by examiner]
US 20160087995A1 · Gehrmann et al. · 2016 [cited by applicant]
US 20180004954A1 · Liguori · 2018 [cited by examiner]
US 20180181756A1 · Campagna · 2018 [cited by examiner]
US 20180183578A1 · Chakrabarti · 2018 [cited by examiner]
US 20200136822A1 · Villapakkam · 2020 [cited by examiner]
US 20200220713A1 · Li · 2020 [cited by examiner]
US 20210397698A1 · Li · 2021 [cited by examiner]
US 20220222099A1 · Srivastava · 2022 [cited by examiner]
US 20220222100A1 · Srivastava · 2022 [cited by examiner]
WO 2020260864A1 · 2020 [cited by applicant]
Application No. PCT/US2022/022372 , International Search Report and Written Opinion, Mailed On Jul. 13, 2022, 10 pages. [cited by applicant]
Advaned Micro Devices, Inc., “AMD SEV-SNP: Strengthening VM Isolation with Integrity Protection and More”, AMD, Jan. 2020, pp. 1-20. [cited by applicant]
Larrew , “[kata-dvv] Kata with AMD SEcure Encrypted Virtualization (SEV)”, https://openstack.org; located at https://lists.katacontainers.io/pipermail/kata-dev/2018-February/000029.html, Feb. 21, 2018, 4 pages. [cited by applicant]
Application No. SG11202307070Y, Notice of Decision to Grant, Mailed on Jan. 23, 2026, 4 pages. [cited by applicant]