IP Library › Granted Patent US 11,824,984
Granted Patent B2
US 11,824,984 · App. 17/572,687 · Granted Nov 21, 2023

Storage encryption for a trusted execution environment

Inventors: Angel Nunez Mencias (Stuttgart, DE); Nicolas Maeding (Holzgerlingen, DE); Peter Morjan (Boeblingen, DE); Dirk Herrendoerfer (Sindelfingen, DE); James Robert Magowan (Woking, GB); Anbazhagan Mani (Bangalore, IN)
Assignee: International Business Machines Corporation
H04L9/14G06F12/1408G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,824,984
App. No.
17/572,687
Granted
Nov 21, 2023
Kind
B2
Abstract

Aspects of the invention include loading an image of a virtual server onto a boot partition of a trusted execution environment (TEE), wherein a first key is embedded in the image. A second key is received from an end customer of an application. Data is received from an independent software vendor (ISV) of the application, wherein the data includes a third key. The second key and the third key are combined inside the TEE to create a fourth key. An available memory space in an independent memory device is encrypted using the fourth key to create a secure data volume. Encrypted data is stored in the secure data volume.

Claims (61)

1. A computer-implemented method comprising:

loading, by a processor, an image of a virtual server onto a boot partition of a trusted execution environment (TEE), wherein a first key is embedded in the image;

receiving, by the processor, a second key from an end customer of an application;

receiving, by the processor, data from an independent software vendor (ISV) of the application, wherein the data includes a third key;

combining, by the processor and in the TEE, the second key and the third key to create a fourth key;

encrypting, by the processor, an available memory space in an independent memory device using the fourth key to create a secure data volume; and

storing encrypted data in the secure data volume.

2. The computer-implemented method of claim 1 , wherein the method further comprises:

retrieving a request for the available memory space from the data from the ISV;

requesting the available memory space from the independent memory device;

receiving the available memory space from the independent memory device; and

encrypting the available memory space using the fourth key to create the secure data volume.

3. The computer-implemented method of claim 1 , wherein the method further comprises retrieving the encrypted data from the secure data volume.

4. The computer-implemented method of claim 1 , wherein the second key is stored in a key store, the method further comprises:

receiving a token for accessing the key store storing the second key;

executing a daemon of the trusted bootloader to communicate the token to the key store; and

receiving the second key from the key store.

5. The computer-implemented method of claim 1 , wherein the image is a containerized image.

6. The computer-implemented method of claim 1 , wherein the data from the ISV of the application has been encrypted using the first key.

7. The computer-implemented method of claim 1 , wherein the second key is an application programming interface (API) key.

8. A system comprising:

a memory having computer readable instructions; and

one or more processors for executing the computer readable instructions, the computer readable instructions controlling the one or more processors to perform operations comprising:

loading an image of a virtual server onto a boot partition of a trusted execution environment (TEE), wherein a first key is embedded in the image;

receiving a second key from an end customer of an application;

receiving data from an independent software vendor (ISV) of the application, wherein the data includes a third key;

combining, in the TEE, the second key and the third key to create a fourth key;

encrypting an available memory space in an independent memory device using the fourth key to create a secure data volume; and

storing encrypted data in the secure data volume.

9. The system of claim 8 , wherein the operations further comprise:

retrieving a request for the available memory space from the data from the ISV;

requesting the available memory space from the independent memory device;

receiving the available memory space from the independent memory device; and

encrypting the available memory space using the fourth key to create the secure data volume.

10. The system of claim 8 , wherein the operations further comprise retrieving the encrypted data from the secure data volume.

11. The system of claim 8 , wherein the second key is stored in a key store, the operations further comprise:

receiving a token for accessing the key store storing the second key;

executing a daemon of the trusted bootloader to communicate the token to the key store; and

receiving the second key from the key store.

12. The system of claim 8 , wherein the image is a containerized image.

13. The system of claim 8 , wherein the data from the ISV of the application has been encrypted using the first key.

14. The system of claim 8 , wherein the second key is an application programming interface (API) key.

15. A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause the processor to perform operations comprising:

loading an image of a virtual server onto a boot partition of a trusted execution environment (TEE), wherein a first key is embedded in the image;

receiving a second key from an end customer of an application;

receiving data from an independent software vendor (ISV) of the application, wherein the data includes a third key;

combining, in the TEE, the second key and the third key to create a fourth key;

encrypting an available memory space in an independent memory device using the fourth key to create a secure data volume; and

storing encrypted data in the secure data volume.

16. The computer program product of claim 15 , wherein the operations further comprise:

retrieving a request for the available memory space from the data from the ISV;

requesting the available memory space from the independent memory device;

receiving the available memory space from the independent memory device; and

encrypting the available memory space using the fourth key to create the secure data volume.

17. The computer program product of claim 15 , wherein the operations further comprise retrieving the encrypted data from the secure data volume.

18. The computer program product of claim 15 , wherein the second key is stored in a key store, the operations further comprise:

receiving a token for accessing the key store storing the second key;

executing a daemon of the trusted bootloader to communicate the token to the key store; and

receiving the second key from the key store.

19. The computer program product of claim 15 , wherein the image is a containerized image.

20. The computer program product of claim 15 , wherein the data from the ISV of the application has been encrypted using the first key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2022
From: NUNEZ MENCIAS, ANGEL; MAEDING, NICOLAS; MORJAN, PETER; HERRENDOERFER, DIRK; MAGOWAN, JAMES ROBERT; MANI, ANBAZHAGAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058614/0381 →
Continuity (1)
Related Publication 20230224156A1 · Jul 13, 2023