IP Library Granted Patent US 10,212,147
Granted Patent B2
US 10,212,147 · App. 15/825,223 · Granted Feb 19, 2019

Extending shrouding capability of hosting system

Inventors: Reinhard T. Buendgen (Tuebingen, DE); Jeffrey A. Frey (New Paltz, NY); Jeb R. Linton (Manassas, VA); James A. O'Connor (Ulster Park, NY); William J. Rooney (Hopewell Junction, NY); George C. Wilson (Austin, TX)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/08G06F9/45558G06F21/44H04L9/14H04L9/30H04L9/3236H04L9/3263H04L41/0803H04L41/28H04L63/06H04L63/061G06F2009/4557G06F2009/45562G06F2009/45595H04L63/045H04L63/0428H04L63/0823H04L63/0853H04L63/10H04L63/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,212,147
App. No.
15/825,223
Granted
Feb 19, 2019
Kind
B2
Abstract

Technical solutions are described for extending shrouding capability of a virtual server hosting system. An example method includes receiving a request to deploy a shrouded virtual server using a predetermined set of hardware components, and using a shrouded mode. The method also includes adding a guest server to the hosting system, the guest server including the predetermined set of hardware components. The method also includes deploying a preconfigured hypervisor on the guest server, where the preconfigured hypervisor is deployed in an immutable mode that disables changes to security settings of the preconfigured hypervisor. The method also includes deploying, by the preconfigured hypervisor, a preconfigured boot image as an instance of the virtual server on the preconfigured hypervisor. The method also includes sending an identifier of the virtual server for receipt by the client device.

Claims (31)

1. A computer implemented method for extending shrouding capability of a virtual server hosting system, the method comprising:

adding, by a host manager, a guest server to the hosting system in response to receiving a request to deploy a virtual server using a shrouded mode, the shrouded mode preventing an administrator of a hosting system from accessing data or applications of the virtual server, the request being sent by a client device;

deploying, by the host manager, a preconfigured boot image as an instance of the virtual server on a hypervisor for the guest server, the deploying comprising initiating a new disk partition on the guest server and deploying the preconfigured boot image on the new disk partition and restricting the hypervisor to loading a clear memory dump that was generated without a system failure; and

sending, by the host manager, an identifier of the virtual server for receipt by the client device.

2. The computer implemented method of claim 1 , wherein the guest server is a physical server comprising different hardware components from an existing server in the hosting system.

3. The computer implemented method of claim 1 , wherein the host manager configures the hypervisor to encrypt the data in the virtual server using a session key received from the client device.

4. The computer implemented method of claim 1 , wherein the host manager configures the hypervisor to encrypt paging data of the virtual server using a session key received from the client device.

5. The computer implemented method of claim 1 , wherein the host manager configures the hypervisor to disable access to cache lines of the guest server.

6. The computer implemented method of claim 1 further comprising, prior to deployment of the hypervisor on the guest server, determining, by the host manager, authenticity of the hypervisor by comparing a hash value of the hypervisor with a predetermined value.

7. The computer implemented method of claim 1 further comprising, prior to deployment of the preconfigured boot image, determining, by the host manager, authenticity of the preconfigured boot image by comparing a hash value of the preconfigured boot image with a predetermined value.

8. The computer implemented method of claim 1 , wherein the new disk partition is a logical disk partition.

9. The computer implemented method of claim 1 , wherein the clear memory dump further does not contain a state of from a previous execution of the shrouded virtual server.

10. A system for extending shrouding capability of a virtual server hosting system, the system comprising:

a server computer; and

a host manager console configured to:

add a guest server to the hosting system in response to receiving a request to deploy a shrouded virtual server using a shrouded mode, the shrouded mode preventing an administrator of a hosting system from accessing data or applications of the virtual server, the request being sent by a client device;

deploy, via a preconfigured hypervisor, a preconfigured boot image as an instance of the virtual server on the preconfigured hypervisor by initiating a new disk partition on the guest server and deploying the preconfigured boot image on the new disk partition and restricting the preconfigured hypervisor to loading a clear memory dump that was generated without a system failure; and

send an identifier of the virtual server for receipt by the client device.

11. The system of claim 10 , wherein the new disk partition is a logical disk partition.

12. The system of claim 10 , wherein the host manager console configures the virtual server to encrypt the data in the virtual server using a session key received from the client device.

13. The system of claim 10 , wherein the host manager console configures the virtual server to encrypt paging data using a session key received from the client device.

14. The system of claim 10 , wherein the host manager console configures the virtual server to disable access to cache lines of the guest server.

15. The system of claim 10 , wherein the clear memory dump further does not contain a state of from a previous execution of the shrouded virtual server.

16. A computer program product for extending shrouding capability of a virtual server hosting system, the computer program product comprising a computer readable storage device, the computer readable storage device comprising computer executable instructions, wherein the computer readable storage device comprises instructions to:

add a guest server to the hosting system in response to receiving a request to deploy a shrouded virtual server using a shrouded mode, the shrouded mode preventing an administrator of a hosting system from accessing data or applications of the virtual server, the request being sent by a client device;

deploy, via a preconfigured hypervisor, a preconfigured boot image as an instance of the virtual server on the preconfigured hypervisor by initiating a new disk partition on the guest server and deploying the preconfigured boot image on the new disk partition and restricting the preconfigured hypervisor to loading a clear memory dump that was generated without a system failure; and

send an identifier of the virtual server for receipt by the client device.

17. The computer program product of claim 16 , wherein the new disk partition is a logical disk partition.

18. The computer program product of claim 16 , wherein the computer readable storage device further comprises instructions to configure the virtual server to encrypt the data in the virtual server using a session key received from the client device.

19. The computer program product of claim 16 , wherein the computer readable storage device further comprises instructions to configure the virtual server to encrypt paging data using a session key received from the client device.

20. The computer program product of claim 16 , wherein the clear memory dump further does not contain a state of from a previous execution of the shrouded virtual server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2017
From: BUENDGEN, REINHARD T.; FREY, JEFFREY A.; LINTON, JEB R.; O'CONNOR, JAMES A.; ROONEY, WILLIAM J.; WILSON, GEORGE C.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044244/0655 →
Continuity (2)
Continuation 14968122 · Dec 14, 2015
Related Publication 20180083948A1 · Mar 22, 2018
Cited By (13)
US 12,395,516 US 12,401,526 US 12,401,634 US 12,401,657 US 12,425,239 US 12,425,240 US 12,432,076 US 12,438,733 US 12,495,032 US 12,562,966 US 12,563,029 US 12,719,850 US 12,726,368