IP Library › Granted Patent US 10,505,721
Granted Patent B2
US 10,505,721 · App. 15/507,840 · Granted Dec 10, 2019

Secure virtualized data volumes

Inventors: Theo Dimitrakos (London, GB); Ali Sajjad (London, GB)
Assignee: British Telecommunications Public Limited Company
H04L9/08G06F21/62G06F21/6209H04L9/0866H04L29/06H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,505,721
App. No.
15/507,840
Granted
Dec 10, 2019
Kind
B2
Abstract

A method of securing a virtual data volume storing data in a first virtualized computing environment including: deriving a cryptographic key for encrypting the data, the key being derived from first and second parameters; and encrypting the data, wherein the first parameter is generated for association with the virtualized data volume, and the second parameter is generated based on at least one characteristic of a second virtualized computing environment.

Claims (17)

1. A method of securing a virtual data volume storing data in a first virtualized computing environment comprising:

deriving a cryptographic key for encrypting the data, the key being derived from first and second parameters, the first parameter being a pseudo random number generated by a virtual machine for which the virtual data volume is instantiated; and

encrypting the data,

wherein the first parameter is generated for association with the virtual data volume, the virtual data volume corresponding to at least one data storage device provided by the first virtualized computing environment, and the second parameter is generated based on at least one characteristic of a second virtualized computing environment, wherein the first virtualized computing environment is different from the second virtualized computing environment, and wherein the virtual machine and the encrypted virtual data volume are packaged into a portable virtual machine package for transfer to the second virtualized computing environment.

2. The method of claim 1 wherein the at least one characteristic is a characteristic common to the first virtualized computing environment and the second virtualized computing environment.

3. The method of claim 2 wherein the at least one characteristic is a characteristic of a hypervisor of the second virtualized computing environment.

4. The method of claim 1 wherein the at least one characteristic is a processor identifier for the second virtualized computing environment.

5. The method of claim 1 wherein the at least one characteristic is a hash value associated with the second virtualized computing environment.

6. The method of claim 1 wherein the portable virtual machine package is encrypted for the transfer.

7. A data volume security system to secure a virtual data volume storing data in a first virtualized computing environment, the system comprising:

at least one processor and memory configured to derive a cryptographic key for encrypting the data, the cryptographic key being derived from first and second parameters, the first parameter being a pseudo-random number generated by a virtual machine for which the virtual data volume is instantiated,

wherein the first parameter is generated for association with the virtual data volume, the virtual data volume corresponding to at least one data storage device provided by the first virtualized computing environment, and the second parameter is generated based on at least one characteristic of a second virtualized computing environment, wherein the first virtualized computing environment is different from the second virtualized computing environment, and wherein the virtual machine and the encrypted virtual data volume are packaged into a portable virtual machine package for transfer to the second virtualized computing environment.

8. The system of claim 7 wherein the at least one characteristic is a characteristic common to the first virtualized computing environment and the second virtualized computing environment.

9. A non-transitory computer-readable storage medium comprising computer-executable code which, when executed on a computer, causes the computer to:

derive a cryptographic key for encrypting the data, the key being derived from first and second parameters, the first parameter being a pseudo random number generated by a virtual machine for which the virtual data volume is instantiated; and

encrypt the data,

wherein the first parameter is generated for association with the virtual data volume, the virtual data volume corresponding to at least one data storage device provided by the first virtualized computing environment, and the second parameter is generated based on at least one characteristic of a second virtualized computing environment, wherein the first virtualized computing environment is different from the second virtualized computing environment, and wherein the virtual machine and the encrypted virtual data volume are packaged into a portable virtual machine package for transfer to the second virtualized computing environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2017
From: DIMITRAKOS, THEO; SAJJAD, ALI
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 041421/0459 →
Priority Claims (1)
EP 14250107 · Sep 26, 2014 · regional
Continuity (1)
Related Publication 20170288863A1 · Oct 5, 2017
Cited By (1)
US 12,244,651