IP Library Granted Patent US 11,620,411
Granted Patent B2
US 11,620,411 · App. 16/828,229 · Granted Apr 4, 2023

Elastic launch for trusted execution environments

Inventor: Michael Tsirkin (Westford, MA)
Assignee: Red Hat, Inc.
G06F21/71G06F9/45558H04L9/0816H04L9/0894H04L9/3226G06F2009/45587G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,620,411
App. No.
16/828,229
Granted
Apr 4, 2023
Kind
B2
Abstract

A system includes a memory, a processor in communication with the memory, and a first TEE instance. The first TEE instance is configured to maintain an encrypted secret, obtain a cryptographic measurement associated with a second TEE instance, validate the cryptographic measurement, and provision the second TEE instance with the encrypted secret. Additionally, the first TEE instance and the second TEE instance are both configured to service at least a first type of request.

Claims (42)

1. A system comprising:

a memory;

a processor in communication with the memory; and

a first trusted execution environment (“TEE”) instance configured to:

maintain an encrypted secret that is used to launch the first TEE instance,

obtain a cryptographic measurement associated with a second TEE instance, validate the cryptographic measurement, and

provision the second TEE instance with the encrypted secret, wherein the first TEE instance and the second TEE instance are each configured to maintain the encrypted secret to independently validate a future TEE instance.

2. The system of claim 1 , wherein the memory is encrypted memory and the encrypted secret is maintained in the encrypted memory.

3. The system of claim 1 , wherein the first TEE instance is a virtual machine.

4. The system of claim 3 , wherein the virtual machine is an encrypted virtual machine.

5. The system of claim 1 , wherein obtaining the cryptographic measurement includes at least one of taking the cryptographic measurement or receiving the cryptographic measurement from the second TEE instance.

6. The system of claim 1 , wherein the cryptographic measurement identifies characteristics of the second TEE instance including at least one of a type of the TEE instance, a version of the TEE instance, and a description of software components loaded into the TEE instance.

7. The system of claim 6 , wherein the cryptographic measurement further includes an integrity code to validate the cryptographic measurement.

8. The system of claim 1 , further comprising an application, the application configured to:

launch the first TEE instance;

send the cryptographic measurement to the first TEE instance;

receive the encrypted secret from the first TEE instance; and

launch the second TEE instance.

9. The system of claim 1 , wherein the first TEE instance is configured to receive a request to clone the first TEE instance.

10. The system of claim 9 , wherein the first TEE instance is configured to obtain a cryptographic measurement associated with a second TEE instance, validate the cryptographic measurement, and provision the encrypted secret to the second TEE instance responsive to receiving the request to clone the first TEE instance.

11. A method comprising:

maintaining, by a first TEE instance, an encrypted secret that is used to launch the first TEE instance;

obtaining, by the first TEE instance, a cryptographic measurement associated with a second TEE instance;

validating, by the first TEE instance, the cryptographic measurement; and

provisioning, by the first TEE instance, the second TEE instance with the encrypted secret, wherein the first TEE instance and the second TEE instance are each configured to maintain the encrypted secret to independently validate a future TEE instance.

12. The method of claim 11 , wherein the encrypted secret is maintained in encrypted memory.

13. The method of claim 11 , wherein the first TEE instance is a first encrypted virtual machine and the second TEE instance is a second encrypted virtual machine.

14. The method of claim 11 , wherein the obtaining, validating, and provisioning occur responsive to receiving a request to clone the first TEE instance.

15. The method of claim 11 , wherein obtaining the cryptographic measurement includes at least one of taking the cryptographic measurement or receiving the cryptographic measurement from the second TEE instance.

16. The method of claim 11 , wherein the cryptographic measurement identifies characteristics of the second TEE instance including at least one of a type of the TEE instance, a version of the TEE instance, and a description of software components loaded into the TEE instance.

17. The method of claim 16 , wherein the cryptographic measurement further includes an integrity code to validate the cryptographic measurement.

18. The method of claim 11 , further comprising:

launching, by an application, the first TEE instance;

sending, by the application, the cryptographic measurement to the first TEE instance;

receiving, by the application, the encrypted secret from the first TEE instance; and

launching, by the application, the second TEE instance.

19. A non-transitory machine-readable medium storing code, which when executed by a processor is configured to:

maintain an encrypted secret in a memory associated with a first TEE instance, the encrypted secret being used to launch the first TEE instance;

obtain a cryptographic measurement associated with a second TEE instance;

validate the cryptographic measurement; and

provision the second TEE instance with the encrypted secret, wherein the first TEE instance and the second TEE instance are each configured to maintain the encrypted secret to independently validate a future TEE instance.

20. The non-transitory machine-readable medium of claim 17 , wherein the obtaining, validating, and provisioning occur responsive to receiving a request to clone the first TEE instance.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2020
From: TSIRKIN, MICHAEL
To: RED HAT, INC.
Reel/Frame 052225/0627 →
Continuity (1)
Related Publication 20210303734A1 · Sep 30, 2021