IP Library Granted Patent US 9,667,606
Granted Patent B2
US 9,667,606 · App. 14/789,916 · Granted May 30, 2017

Systems, methods and computer readable medium to implement secured computational infrastructure for cloud and data center environments

Inventors: Ari Birger (Palo Alto, CA); Haim Dror (Tel-Mond, IL)
Assignee: CypherMatrix, Inc.
H04L63/045G06F3/065G06F3/0619G06F3/0689G06F9/45558G06F13/1663G06F21/602G06F21/629G06F21/6209H04L63/0428H04L63/061H04L63/0876G06F2009/45562G06F2009/45583
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,667,606
App. No.
14/789,916
Granted
May 30, 2017
Kind
B2
Abstract

Systems, methods, and non-transitory computer-readable medium are provided to secure data centers and cloud computing. A method receives network identifiers for functions, requests a network key for each function, allocates network interfaces, requests a virtual network interface controller allocation, requests a network key for each cloud function, receives storage identifiers for functions, requests a storage key for each cloud function, allocates virtual storage disks, requests a storage interface controller allocation, requests a storage key for each cloud function. Methods secure migration of a virtual machine from a source to a target server. A server includes multiple cores where each core is dedicated to a compute function and a unique key encrypts data of each compute function. A non-transitory computer-readable medium encodes programs that execute the above methods.

Claims (18)

1. A method of computer security executed on one or more servers of a cloud or data center provider, comprising:

receiving a network identifier for a plurality of functions from a cloud or data center manager;

requesting a network key for each function from key server(s) or from a local key generator based on one or multiple secrets;

allocating a plurality of isolated network interfaces based on a cloud or data center provider's and/or a customer's requirements;

requesting a virtual network interface controller allocation per function per virtual machine;

requesting from the key server a network key for each cloud or data center function;

receiving a storage identifier for a plurality of functions from a cloud or data center manager;

requesting a storage key for each function from key server(s) or from a local key generator based on one or multiple secrets;

allocating a plurality of isolated virtual storage disks based on cloud or data center provider and/or customer requirements;

requesting a storage controller allocation per function per virtual machine;

requesting from the key server a storage key(s) for each cloud or data center function; and

encrypting each function with either the network key or the storage key.

2. The method of claim 1 , wherein the network key(s) are obtained from key server(s) and/or from a local key generator based on one or multiple secrets from cloud or data center provider and/or customer.

3. The method of claim 1 , wherein the storage key(s) are obtained from key server(s) and/or from a local key generator based on one or multiple secrets from cloud or data center provider and/or customer.

4. The method of claim 1 , wherein each network key and each storage key is retrieved from a key management server that resides on premises only accessible to a customer of the cloud or data center provider.

5. The method of claim 1 , wherein each network key and each storage key is retrieved from a key management server that resides on one or more servers.

6. The method of claim 1 , wherein the network key is retrieved from a key management server that resides on customer premises for customer storage and connectivity.

7. The method of claim 5 , wherein the network key is retrieved from a key management server that resides on customer premises for customer storage and connectivity.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2017
From: CYPHERMATRIX INC.
To: BIRGER, ARI
Reel/Frame 042198/0502 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2015
From: BIRGER, ARI, MR.; DROR, HAIM, MR.
To: CYPHERMATRIX, INC.
Reel/Frame 036191/0141 →
Continuity (1)
Related Publication 20170005990A1 · Jan 5, 2017