IP Library Granted Patent US 8,458,490
Granted Patent B2
US 8,458,490 · App. 12/790,547 · Granted Jun 4, 2013

System and method for supporting full volume encryption devices in a client hosted virtualization system

Inventors: David Konetski (Austin, TX); Kenneth W. Stufflebeam (Georgetown, TX); Shree Dandekar (Round Rock, TX)
Assignee: Dell Products, LP
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,458,490
App. No.
12/790,547
Filed
May 28, 2010
Granted
Jun 4, 2013
Kind
B2
Examiner
SONG, HOSUK
Art Unit
2435
USPC
713/189
Abstract

A client hosted virtualization system includes a full volume encryption (FVE) storage device, a processor, and non-volatile memory with BIOS code and virtualization manager code. The virtualization manager initializes the client hosted virtualization system, authenticates a virtual machine image, launches the virtual machine based on the image, receives a transaction from the virtual machine targeted to the FVE storage device, sends the transaction to the FVE storage device, receives a response from the FVE storage device, and sends the first response to the first virtual machine. The client hosted virtualization system is configurable to execute the BIOS or the virtualization manager.

Claims (119)

1. A client hosted virtualization system (CHVS) comprising:

a full volume encryption (FVE) storage device;

a processor operable to execute code; and

a non-volatile memory including first code to implement a basic input/output system to initialize the CHVS, and second code to implement a virtualization manager operable to:

initialize the CHVS;

authenticate a first virtual machine image associated with a first virtual machine;

launch the first virtual machine on the CHVS based on the first virtual machine image;

receive a first transaction from the first virtual machine, a target of the first transaction being the FVE storage device;

send the first transaction to the FVE storage device;

receive a first response to the first transaction from the FVE storage device; and

send the first response to the first virtual machine;

wherein the CHVS is configurable in a first configuration to execute the first code and not the second code, and is configurable in a second configuration to execute the second code and not the first code.

2. The CHVS of claim 1 , further comprising a mass storage device, and wherein the first virtual machine image:

is stored on the mass storage device; and

includes an operating system and an application.

3. The CHVS of claim 1 , further comprising:

a general purpose encryption (GPE) engine;

wherein in sending the first transaction to the FVE storage device, the virtualization manager is further operable to send the first transaction to the GPE engine.

4. The CHVS of claim 3 , wherein:

the first transaction is a write transaction; and

in sending the first transaction to the GPE engine, the virtualization manager is further operable to direct the GPE engine to encrypt information associated with the first transaction, and to store the information on the FVE storage device.

5. The CHVS of claim 3 , wherein:

the first transaction is a read transaction;

in sending the first transaction to the GPE engine, the virtualization manager is further operable to direct the GPE retrieve information associated with the first transaction from the FVE storage device; and

in receiving the first response to the first transaction from the FVE storage device engine, the virtualization manager is further operable to direct the GPE engine to decrypt the information.

6. The CHVS of claim 1 , wherein the virtualization manager is further operable to:

authenticate a second virtual machine image associated with a second virtual machine;

launch the second virtual machine on the CHVS based on the second virtual machine image;

receive a second transaction from the second virtual machine, a target of the second transaction being the FVE storage device;

send the second transaction to the FVE storage device;

receive a second response to the first transaction from the FVE storage device; and

send the second response to the second virtual machine.

7. The CHVS of claim 6 , further comprising:

an unencrypted storage device;

wherein the virtualization manager is further operable to:

receive a third transaction from the first virtual machine, a target of the third transaction being the unencrypted storage device;

send the third transaction to the unencrypted storage device;

receive a third response to the third transaction from the unencrypted storage device; and

send the third response to the first virtual machine.

8. The CHVS of claim 7 , wherein the virtualization manager is further operable to:

receive a fourth transaction from the second virtual machine, a target of the fourth transaction being the unencrypted storage device;

send the fourth transaction to the unencrypted storage device;

receive a fourth response to the fourth transaction from the unencrypted storage device; and

send the fourth response to the second virtual machine.

9. A method of providing a client hosted virtualization system (CHVS) comprising:

storing first code in a non-volatile memory of the CHVS to implement a basic input/output system to initialize the CHVS;

storing second code in the non-volatile memory, the second code being operable to:

initialize the CHVS;

authenticate a first virtual machine image associated with a first virtual machine;

launch the first virtual machine on the CHVS based on the first virtual machine image;

receive a first transaction from the first virtual machine, a target of the first transaction being a full volume encryption (FVE) storage device of the CHVS;

send the first transaction to the FVE storage device;

receive a first response to the first transaction from the FVE storage device; and

send the first response to the first virtual machine;

determining to execute the first code to the exclusion of the second code;

in response to determining to execute the first code, executing the first code;

determining to execute the second code to the exclusion of the first code; and

in response to determining to execute the second code, executing the second code.

10. The method of claim 9 , wherein the first virtual machine image includes an operating system and an application.

11. The method of claim 9 , wherein in sending the first transaction to the FVE storage device, the second code is further operable to send the first transaction to a general purpose encryption (GPE) engine of the CHVS.

12. The method of claim 11 , wherein:

the first transaction is a write transaction; and

in sending the first transaction to the GPE engine, the second code is further operable to:

direct the GPE engine to encrypt information associated with the first transaction; and

store the information on the FVE storage device.

13. The method of claim 11 , wherein:

the first transaction is a read transaction;

in sending the first transaction to the GPE engine, the second code is further operable to direct the GPE retrieve information associated with the first transaction from the FVE storage device; and

in receiving the first response to the first transaction from the FVE storage device engine, the second code is further operable to direct the GPE engine to decrypt the information.

14. The method of claim 9 , the second code being further operable to:

authenticate a second virtual machine image associated with a second virtual machine;

launch the second virtual machine on the CHVS based on the second virtual machine image;

receive a second transaction from the second virtual machine, a target of the second transaction being the FVE storage device;

send the second transaction to the FVE storage device;

receive a second response to the second transaction from the FVE storage device; and

send the second response to the second virtual machine.

15. The method of claim 14 , the second code being further operable to:

receive a third transaction from the first virtual machine, a target of the third transaction being an unencrypted storage device of the CHVS;

send the third transaction to the unencrypted storage device;

receive a third response to the third transaction from the unencrypted storage device; and

send the third response to the first virtual machine.

16. The method of claim 15 , the second code being further operable to:

receive a fourth transaction from the second virtual machine, a target of the fourth transaction being an unencrypted storage device of the CHVS;

send the fourth transaction to the unencrypted storage device;

receive a fourth response to the fourth transaction from the unencrypted storage device; and

send the fourth response to the second virtual machine.

17. Machine-executable code for an information handling system (IHS), wherein the machine-executable code is embedded within a non-transitory medium and includes instructions for carrying out a method, the method comprising:

storing first code in a non-volatile memory of the IHS to implement a basic input/output system to initialize the IHS;

storing second code in the non-volatile memory, the second code being operable to:

initialize the IHS;

authenticate a first virtual machine image associated with a first virtual machine, the first virtual machine image including a first operating system and a first application;

launch the first virtual machine on the IHS based on the first virtual machine image;

receive a first transaction from the first virtual machine, a target of the first transaction being a full volume encryption (FVE) storage device of the client hosted virtualization system;

send the first transaction to the FVE storage device;

receive a first response to the first transaction from the FVE storage device; and

send the first response to the first virtual machine;

determining to execute the first code to the exclusion of the second code;

in response to determining to execute the first code, executing the first code;

determining to execute the second code to the exclusion of the first code; and

in response to determining to execute the second code, executing the second code.

18. The machine-executable code of claim 17 , wherein:

the first transaction is a write transaction;

in sending the first transaction to the FVE storage device, the second code is further operable to send the first transaction to a GPE engine of the client hosted virtualization system; and

in sending the first transaction to the GPE engine, the second code is further operable to:

direct the GPE engine to encrypt information associated with the first transaction; and

store the information on the FVE storage device.

19. The machine-executable code of claim 17 , wherein:

the first transaction is a read transaction;

in sending the first transaction to the FVE storage device, the second code is further operable to:

send the first transaction to a GPE engine of the client hosted virtualization system; and

direct the GPE retrieve information associated with the first transaction from the FVE storage device; and

in receiving the first response to the first transaction from the FVE storage device engine, the second code is further operable to direct the GPE engine to decrypt the information.

20. The machine-executable code of claim 17 , the second code being further operable to:

authenticate a second virtual machine image associated with a second virtual machine;

launch the second virtual machine on the client hosted virtualization system based on the second virtual machine image;

receive a second transaction from the second virtual machine, a target of the second transaction being the FVE storage device;

send the second transaction to the FVE storage device;

receive a second response to the second transaction from the FVE storage device; and

send the second response to the second virtual machine.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2010
From: KONETSKI, DAVID; STUFFLEBEAM, KENNETH W.; DANDEKAR, SHREE
To: DELL PRODUCTS, LP
Reel/Frame 024497/0149 →
Continuity (1)
Related Publication 20110296197A1 · Dec 1, 2011