IP Library Patent Application 18984668
Patent Application
App. No. 18/984,668

MIGRATION AND DISASTER RECOVERY OF VTPM ENABLED VIRTUAL MACHINES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/984,668
Filed
Dec 17, 2024
Art Unit
2439
USPC
713/168
Abstract

Techniques for migration or disaster recovery of vTPM enabled virtual machines include non-transitory computer-readable media storing program instructions that, when executed by one or more processors associated with a computing device, cause the one or more processors to perform a method including transmitting, by a primary site, an encryption secret for an encrypted storage device to a secondary site, the encrypted storage device storing data encrypted based on the encryption secret; and transmitting, by the primary site using an unsecure channel, the data as encrypted based on the encryption secret to the secondary site.

Claims (48)

1 . One or more non-transitory computer-readable media storing program instructions that, when executed by one or more processors associated with a primary site, cause the one or more processors to perform a method comprising:

transmitting, by the primary site, an encryption secret for an encrypted storage device to a secondary site, the encrypted storage device storing data encrypted based on the encryption secret; and

transmitting, by the primary site using an unsecure channel, the data as encrypted based on the encryption secret to the secondary site.

2 . The one or more non-transitory computer-readable media of claim 1 , wherein transmitting the encryption secret for the encrypted storage device to the secondary site is performed using a secure channel between the primary site and the secondary site.

3 . The one or more non-transitory computer-readable media of claim 2 , further comprising transmitting, by the primary site using the secure channel, a virtual machine configuration associated with the data as encrypted.

4 . The one or more non-transitory computer-readable media of claim 1 , wherein transmitting the encryption secret for the encrypted storage device to the secondary site further comprises encrypting the encryption secret using an encryption key associated with the primary site.

5 . The one or more non-transitory computer-readable media of claim 4 , wherein the encryption key is different from the encryption secret.

6 . The one or more non-transitory computer-readable media of claim 1 , wherein the data as encrypted is not decrypted prior to being transmitted.

7 . The one or more non-transitory computer-readable media of claim 1 , wherein the encryption secret is a virtual trusted platform (vTPM) secret.

8 . The one or more non-transitory computer-readable media of claim 1 , wherein the encrypted storage device is a disk volume.

9 . The one or more non-transitory computer-readable media of claim 1 , further comprising receiving, at the primary site, the encryption secret from a first local secure store of the primary site, wherein the encryption secret is transmitted to the secondary site for encryption by a second local secure store of the secondary site.

10 . The one or more non-transitory computer-readable media of claim 9 , wherein the first local secure store is a key store.

11 . The one or more non-transitory computer-readable media of claim 9 , further comprising:

receiving, by a recovery service at the primary site, the encryption secret in encrypted form from a virtual machine (VM) service at the primary site; and

sending the encryption secret to the first local secure store for decryption.

12 . A method comprising:

transmitting, by a primary site, an encryption secret for an encrypted storage device to a secondary site, the encrypted storage device storing data encrypted based on the encryption secret; and

transmitting, by the primary site using an unsecure channel, the data as encrypted based on the encryption secret to the secondary site.

13 . The method of claim 12 , wherein transmitting the encryption secret for the encrypted storage device to the secondary site is performed using a secure channel between the primary site and the secondary site.

14 . The method of claim 13 , further comprising transmitting, by the primary site using the secure channel, a virtual machine configuration associated with the data as encrypted.

15 . The method of claim 12 , wherein transmitting the encryption secret for the encrypted storage device to the secondary site further comprises encrypting the encryption secret using an encryption key associated with the primary site.

16 . The method of claim 15 , wherein the encryption key is different from the encryption secret.

17 . The method of claim 12 , wherein the data as encrypted is not decrypted prior to being transmitted.

18 . The method of claim 12 , wherein the encryption secret is a virtual trusted platform (vTPM) secret.

19 . The method of claim 12 , wherein the encrypted storage device is a disk volume.

20 . The method of claim 12 , further comprising receiving, at the primary site, the encryption secret from a first local secure store of the primary site, wherein the encryption secret is transmitted to the secondary site for encryption by a second local secure store of the secondary site.

21 . The method of claim 20 , wherein the first local secure store is a key store.

22 . The method of claim 20 , further comprising:

receiving, by a recovery service at the primary site, the encryption secret in encrypted form from a virtual machine (VM) service at the primary site; and

sending the encryption secret to the first local secure store for decryption.

23 . A system comprising:

a primary computing device;

memory storing instructions; and

one or more processors coupled to the memory and, when executing the instructions, are configured to perform operations comprising:

transmitting, by the primary computing device, an encryption secret for an encrypted storage device to a secondary computing device, the encrypted storage device storing data encrypted based on the encryption secret; and

transmitting, by the primary computing device using an unsecure channel, the data as encrypted based on the encryption secret to the secondary computing device.

24 . The system of claim 23 , wherein transmitting the encryption secret for the encrypted storage device to the secondary computing device is performed using a secure channel between the primary computing device and the secondary computing device.

25 . The system of claim 24 , further comprising transmitting, by the primary computing device using the secure channel, a virtual machine configuration associated with the data as encrypted.

26 . The system of claim 23 , wherein transmitting the encryption secret for the encrypted storage device to the secondary computing device further comprises encrypting the encryption secret using an encryption key associated with the primary computing device.

27 . The system of claim 26 , wherein the encryption key is different from the encryption secret.

28 . The system of claim 23 , wherein the data as encrypted is not decrypted prior to being transmitted.

29 . The system of claim 23 , wherein the encryption secret is a virtual trusted platform (vTPM) secret.

30 . The system of claim 23 , wherein the encrypted storage device is a disk volume.

31 . The system of claim 23 , further comprising receiving, at the primary computing device, the encryption secret from a first local secure store of the primary computing device, wherein the encryption secret is transmitted to the secondary computing device for encryption by a second local secure store of the secondary computing device.

32 . The system of claim 31 , wherein the first local secure store is a key store.

33 . The system of claim 31 , further comprising:

receiving, by a recovery service at the primary computing device, the encryption secret in encrypted form from a virtual machine (VM) service at the primary computing device; and

sending the encryption secret to the first local secure store for decryption.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2025
From: EIBAGI, AMIR; TYAGI, MAYANK; KUMAR, NAVEEN; GHADAGE, SANDEEP; SAH, SUDISH
To: NUTANIX, INC.
Reel/Frame 070946/0439 →
SECURITY INTEREST Recorded Feb 13, 2025
From: NUTANIX, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 070206/0463 →