IP Library Granted Patent US 10,075,296
Granted Patent B2
US 10,075,296 · App. 14/791,203 · Granted Sep 11, 2018

Loading and virtualizing cryptographic keys

Inventors: Jason W Brandt (Austin, TX); Vedvyas Shanbhogue (Austin, TX)
Assignee: Intel Corporation
H04L9/0894G06F21/53G06F9/45533G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,075,296
App. No.
14/791,203
Granted
Sep 11, 2018
Kind
B2
Abstract

Embodiments of an invention for loading and virtualizing cryptographic keys are disclosed. In one embodiment, a processor includes a local key storage location, a backup key storage location, and execution hardware. Neither the local key storage location nor the backup key storage location is readable by software. The execution hardware is to perform a first operation and a second operation. The first operation includes loading a cryptographic key into the local key storage location. The second operation includes copying the cryptographic key from the local key storage location to the backup key storage location.

Claims (14)

1. A system comprising:

a memory; and

a processor including

a register;

a local key storage location not readable outside of the processor;

a backup key storage location not readable outside of the processor;

instruction hardware to receive a first instruction, a second instruction, and a third instruction, the first instruction having an operand to specify the register as a source;

execution hardware to perform a first operation in response to the first instruction, a second operation in response to the second instruction, and a third operation in response to the third instruction, the first operation including loading a cryptographic key from the register into the local key storage location, the second operation including copying the cryptographic key from the local key storage location to the backup key storage location, and the third operation including copying the cryptographic key from the backup key storage location to the local key storage location;

control logic to cause a virtual machine exit in response to an attempt to execute the first instruction in a virtual machine; and

a virtual machine monitor to respond to the virtual machine exit by copying the cryptographic key from the register to the memory;

the virtual machine monitor to protect the memory using an access control mechanism including one of an extended page table and a nested page table;

wherein a processor state maintains the content of the backup key storage location while the local key storage location is unpowered.

2. The system of claim 1 , wherein the copying the cryptographic key from the register to the memory includes storing the cryptographic key in a guest key field in a virtual machine control structure.

3. The system of claim 2 , wherein, in connection with a virtual machine entry, the cryptographic key is to be copied from the guest key field in the virtual machine control structure to the local key storage location.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2015
From: BRANDT, JASON W.; SHANBHOGUE, VEDVYAS
To: INTEL CORPORATION
Reel/Frame 036252/0180 →
Continuity (1)
Related Publication 20170063547A1 · Mar 2, 2017