IP Library Granted Patent US 9,680,805
Granted Patent B1
US 9,680,805 · App. 14/705,887 · Granted Jun 13, 2017

Method and system for key management

Inventors: Robert Stephen Rodgers (Mountain View, CA); William Norman Eatherton (San Jose, CA); Michael John Beesley (Atherton, CA); Stefan Alexander Dyckerhoff (Palo Alto, CA); Philippe Gilbert Lacroute (Sunnyvale, CA); Edward Ronald Swierk (Mountain View, CA); Neil Vincent Geraghty (San Francisco, CA); Keith Eric Holleman (Campbell, CA); Thomas John Giuli (Mountain View, CA); Srivatsan Rajagopal (Cupertino, CA); Paul Edward Fraley (Sunnyvale, CA); Vijay Krishnaji Tapaskar (Palo Alto, CA); Daniel Sergeevich Selifonov (Mountain View, CA); Keith Anthony Low (San Mateo, CA)
Assignee: Skyport Systems, Inc.
H04L63/061G06F9/45558H04L63/0428G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,680,805
App. No.
14/705,887
Granted
Jun 13, 2017
Kind
B1
Abstract

A method and system for key management. The method includes receiving, by a control domain on a server, a request for a tenant key, and obtaining an authorization secret from a management service, where the management service is external to the server. The method further includes, in response to the request, decrypting, after obtaining the authorization secret, an encrypted platform master key to obtain a platform master key, decrypting an encrypted tenant key to obtain the tenant key using the platform master key, and providing the tenant key to an entity that issued the request.

Claims (64)

1. A method for key management, the method comprising:

obtaining, by a control domain on a server, an authorization secret from a management service, wherein the management service is external to the server;

generating, after obtaining the authorization secret, a platform master key;

encrypting a tenant key with the platform master key to obtain an encrypted tenant key;

encrypting the platform master key using a storage root key to obtain an encrypted platform master key;

storing the encrypted tenant key and the encrypted platform master key in a key store on the server;

removing the authorization secret from the server;

after removing the authorization secret from the server;

receiving, by the control domain, a request for the tenant key;

obtaining the authorization secret from the management service;

in response to the request:

decrypting, after obtaining the authorization secret, the encrypted platform master key to obtain the platform master key;

decrypting the encrypted tenant key to obtain the tenant key using the platform master key; and

providing the tenant key to an entity that issued the request.

2. The method of claim 1 , further comprising:

providing at least one integrity measurement for the server to the management service prior to obtaining the authorization secret.

3. The method of claim 1 , further comprising:

providing at least one integrity measurement for the server to the management service prior to receiving the request and prior to obtaining the authorization secret, wherein the control domain is executing on the server.

4. The method of claim 1 , wherein decryption of the encrypted tenant key to obtain the tenant key using the platform master key is performed in a trusted platform module (TPM), wherein the TPM is located on the server.

5. The method of claim 1 , wherein decrypting the encrypted tenant key comprises;

decrypting an encrypted tenant master key to obtain a tenant master key; and

decrypting the encrypted tenant key using the tenant master key.

6. The method of claim 1 , wherein the encrypted platform master key is decrypted using the storage root key in a trust platform module (TPM), wherein the TPM is located on the server.

7. The method of claim 1 , wherein the entity is an application executing in an application virtual machine (AVM) and wherein AVM is executing on the server.

8. The method of claim 1 , wherein the entity is a proxy executing a service virtual machine (SVM) and the SVM is executing on the server.

9. The method of claim 1 , wherein obtaining the authorization secret comprises generating the authorization secret by a random number generator on the server.

10. The method of claim 1 , wherein obtaining the authorization secret comprises obtaining the authorization secret from the management service.

11. The method of claim 1 , further comprising:

after obtaining the authorization secret, storing the authorization secret in a protected storage location in the server.

12. The method of claim 1 , further comprising:

after obtaining the authorization secret, storing the authorization secret in memory in the server.

13. A system, comprising:

a server comprising:

storage, wherein the storage comprises a key store,

a first trusted platform module (TPM);

a control domain executing on the server configured to:

receive a request for a tenant key, wherein an encrypted tenant key is stored in the key store;

obtain an authorization secret from a management service, wherein the management service is external to the server;

in response to the request:

initiate, after obtaining the authorization secret, decryption of an encrypted platform master key by the first TPM in order to obtain a platform master key, wherein the encrypted platform master key is stored in the key store;

initiate decryption of the encrypted tenant key to obtain the tenant key using the platform master key; and

provide the tenant key to an entity that issued the request;

wherein the server is configured to provide at least one integrity measurement for the server to the management service prior to obtaining the authorization secret, and

a network adaptor operatively connected to the server comprising a second TPM,

wherein the network adaptor is configured to provide at least one integrity measurement for the network adaptor to the management service prior to obtaining the authorization secret.

14. The system of claim 13 , wherein the entity is an application executing in an application virtual machine (AVM) and wherein AVM is executing on the server.

15. The system of claim 13 , wherein the entity is a proxy executing a service virtual machine (SVM) and the SVM is executing on the server.

16. The system of claim 13 , further comprising:

a debug register on a processor in the server configured to store the authorization secret.

17. A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to:

obtain, by a control domain on a server an authorization secret from a management service, wherein the management service is external to the server;

generate, after obtaining the authorization secret, a platform master key;

encrypt a tenant key with the platform master key to obtain an encrypted tenant key;

encrypt the platform master key using a storage root key to obtain an encrypted platform master key;

store the encrypted tenant key and the encrypted platform master key in a key store on the server;

remove the authorization secret from the server;

after removing the authorization secret from the server;

receive, by the control domain, a request for the tenant key;

provide at least one integrity measurement for the server to the management service prior to receiving the request and prior to obtaining the authorization secret;

obtain the authorization secret from the management service;

in response to the request:

decrypt, after obtaining the authorization secret, the encrypted platform master key to obtain the platform master key;

decrypt the encrypted tenant key to obtain the tenant key using the platform master key; and

provide the tenant key to an entity that issued the request.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2018
From: SKYPORT SYSTEMS LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 046985/0381 →
CHANGE OF NAME Recorded Sep 26, 2018
From: SKYPORT SYSTEMS, INC.
To: SKYPORT SYSTEMS LLC
Reel/Frame 047156/0673 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2015
From: RODGERS, ROBERT STEPHEN; EATHERTON, WILLIAM NORMAN; BEESLEY, MICHAEL JOHN; DYCKERHOFF, STEFAN ALEXANDER; LACROUTE, PHILIPPE GILBERT; SWIERK, EDWARD RONALD; GERAGHTY, NEIL VINCENT; HOLLEMAN, KEITH ERIC; GIULI, THOMAS JOHN; RAJAGOPAL, SRIVATSAN; FRALEY, PAUL EDWARD; TAPASKAR, VIJAY KRISHNAJI; SELIFONOV, DANIEL SERGEEVICH; LOW, KEITH ANTHONY
To: SKYPORT SYSTEMS, INC.
Reel/Frame 035959/0363 →
Continuity (1)
Provisional Application 61989957 · May 7, 2014