IP Library › Granted Patent US 12,197,596
Granted Patent B2
US 12,197,596 · App. 18/200,648 · Granted Jan 14, 2025

Enclave fork support

Inventors: Keith Moyer (Kirkland, WA); Uday Savagaonkar (Redmond, WA); Chong Cai (Kirkland, WA); Matthew Gingell (Woodinville, WA); Anna Sapek (Kirkland, WA)
Assignee: Google LLC
G06F21/602G06F21/6245H04L9/0861H04L9/14H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,596
App. No.
18/200,648
Granted
Jan 14, 2025
Kind
B2
Abstract

A fork support is provided for duplicating an application running inside an enclave entity. In this regard, a request to duplicate an application running inside a first enclave may be received by one or more processors of a host computing device of the first enclave. A snapshot of the first enclave including the application may be generated. The snapshot may be encrypted with a snapshot key and copied to untrusted memory of the host. A second enclave may be generated. The snapshot key may be sent from the first enclave to the second enclave through a secure communication channel. The encrypted snapshot may be copied from the untrusted memory of the host into the second enclave. The encrypted snapshot may be decrypted inside the second enclave with the snapshot key.

Claims (34)

1. A method comprising: encrypting, by one or more processors, an enclave instance with a first key inside a first enclave;

generating, by the one or more processors, a shared secret key inside the first enclave;

encrypting, by the one or more processors, the first key with the shared secret key inside the first enclave;

establishing, by the one or more processors, a secure communication channel between the first enclave and a second enclave using the shared secret key;

sending, by the one or more processors, the encrypted first key to the second enclave;

and copying, by the one or more processors, the encrypted enclave instance to the second enclave.

2. The method of claim 1 , further comprising outputting, by the one or more processors, the encrypted first key from the first enclave to a first process of a host.

3. The method of claim 1 , wherein the encrypted first key is sent to the second enclave through the secure communication channel.

4. The method of claim 1 , wherein the shared secret key comprises a public key paired with a private key.

5. The method of claim 1 , wherein the encrypted enclave instance is copied to untrusted memory allocated to a first process of a host.

6. The method of claim 5 , further comprising copying, by the one or more processors, the encrypted enclave instance from the untrusted memory allocated to the first process to untrusted memory allocated to a second process of the host.

7. The method of claim 5 , further comprising deleting, by the one or more processors, the encrypted enclave instance from the untrusted memory allocated to the first process.

8. The method of claim 1 , further comprising: decrypting, by the one or more processors, the encrypted first key with the shared secret key inside the second enclave; and decrypting, by the one or more processors, the encrypted enclave instance with the first key inside the second enclave.

9. A system comprising: one or more processors; and

one or more storage devices coupled to the one or more processors and storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

encrypting an enclave instance with a first key inside a first enclave;

generating a shared secret key inside the first enclave;

encrypting the first key with the shared secret key inside the first enclave;

establishing, by the one or more processors, a secure communication channel between the first enclave and a second enclave using the shared secret key;

sending the encrypted first key to the second enclave;

and copying the encrypted enclave instance to the second enclave.

10. The system of claim 9 , wherein the operations further comprise outputting the encrypted first key from the first enclave to a first process of a host.

11. The system of claim 1 , wherein the encrypted first key is sent to the second enclave through the secure communication channel.

12. The system of claim 9 , wherein the shared secret key comprises a public key paired with a private key.

13. The system of claim 9 , wherein the encrypted enclave instance is copied to untrusted memory allocated to a first process of a host.

14. The system of claim 13 , wherein the operations further comprise copying the encrypted enclave instance from the untrusted memory allocated to the first process to untrusted memory allocated to a second process of the host.

15. The system of claim 13 , wherein the operations further comprise deleting the encrypted enclave instance from the untrusted memory allocated to the first process.

16. The system of claim 9 , wherein the operations further comprise: decrypting the encrypted first key with the shared secret key inside the second enclave; and decrypting the encrypted enclave instance with the first key inside the second enclave.

17. A non-transitory computer readable medium for storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising: encrypting an enclave instance with a first key inside a first enclave; generating a shared secret key inside the first enclave;

encrypting the first key with the shared secret key inside the first enclave;

establishing, by the one or more processors, a secure communication channel between the first enclave and a second enclave using the shared secret key;

sending the encrypted first key to a second enclave;

and copying the encrypted enclave instance to the second enclave.

18. The non-transitory computer readable medium of claim 17 , wherein the encrypted first key is sent to the second enclave through the secure communication channel.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2023
From: MOYER, KEITH; SAVAGAONKAR, UDAY; CAI, CHONG; GINGELL, MATTHEW; SAPEK, ANNA
To: GOOGLE LLC
Reel/Frame 063726/0481 →
Continuity (3)
Continuation 17201741 · Mar 15, 2021
Continuation 16153039 · Oct 5, 2018
Related Publication 20230297697A1 · Sep 21, 2023
References Cited (43)
US 5970250A · England et al. · 1999 [cited by applicant]
US 6085217A · Ault et al. · 2000 [cited by applicant]
US 6769119B1 · England · 2004 [cited by examiner]
US 9442752B1 · Roth et al. · 2016 [cited by applicant]
US 10223538B1 · Cignetti · 2019 [cited by examiner]
US 10877785B2 · Costa · 2020 [cited by examiner]
US 10924275B1 · Kumar · 2021 [cited by examiner]
US 10929415B1 · Shcherbakov · 2021 [cited by examiner]
US 11475147B2 · Lewis · 2022 [cited by examiner]
US 20040096058A1 · Cho · 2004 [cited by examiner]
US 20050005103A1 · Atkin · 2005 [cited by examiner]
US 20110246767A1 · Chaturvedi · 2011 [cited by examiner]
US 20110283113A1 · Moffat · 2011 [cited by examiner]
US 20150052596A1 · Ayanam · 2015 [cited by examiner]
US 20150371063A1 · Van Antwerpen et al. · 2015 [cited by applicant]
US 20160148001A1 · Bacher · 2016 [cited by examiner]
US 20160246720A1 · Pandey · 2016 [cited by examiner]
US 20160283409A1 · Pandey et al. · 2016 [cited by applicant]
US 20170289109A1 · Caragea · 2017 [cited by examiner]
US 20180137294A1 · Van Antwerpen · 2018 [cited by examiner]
US 20190095879A1 · Eyal et al. · 2019 [cited by applicant]
US 20190213319A1 · Gerebe · 2019 [cited by examiner]
US 20190362083A1 · Ortiz · 2019 [cited by examiner]
US 20190369262A1 · Fernandez Hernandez · 2019 [cited by examiner]
US 20200012527A1 · Hartsock · 2020 [cited by examiner]
US 20200204346A1 · Trevethan · 2020 [cited by applicant]
EP 3336737A1 · 2018 [cited by applicant]
KR 20090017538A · 2009 [cited by applicant]
KR 20170120096A · 2017 [cited by applicant]
KR 20180060876A · 2018 [cited by applicant]
Marcus Brandenburger ; Rollback and Forking Detection for Trusted Execution Environments using Lightweight Collective Memory; IEEE: Year:2017; pp. 157-168. [cited by examiner]
Hearing Notice for Indian Patent Application No. 202147000158 dated Jun. 24, 2024. 3 pages. [cited by applicant]
Office Action for Chinese Patent Application No. 201980025775.5 dated Oct. 30, 2023. 6 pages. [cited by applicant]
Chia-Che Tsai et al. “Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX.” The Proceedings of the 2017 USENIX Annual Technical Conference (USENIX ATC '17). USENIX Association. Jul. 12-14, 2017. pp. … [cited by applicant]
Chia-Che Tsai. “A Library Operating System for Compatibility.” A Dissertation presented by Chia-Che Tsai to The Graduate School in Partial Fulfillment of the Requirements for the Degree of Doctor of Philosophy in Comput… [cited by applicant]
First Examination Report for Indian Patent Application No. 202147000158 dated Jan. 3, 2022. 7 pages. [cited by applicant]
Gu J, Hua Z, Xia Y, Chen H, Zang B, Guan H, Li J. Secure live migration of SGX enclaves on untrusted cloud. In2017 47th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) Jun. 2, 20176 (p… [cited by applicant]
International Search Report including Written Opinion for PCT/US2019/051219 dated Nov. 15, 2019. [cited by applicant]
James Litton et al. “Light-weight Contexts: An OS Abstraction for Safety and Performance.” 12th USENIX Symposium on Operating Systems Design and Implementation. USENIX Association. Savannah, GA, USA. Nov. 2-4, 2016. pp.… [cited by applicant]
Jinyuan Li,; Secure Untrusted Data Repository (SUN DR); USENIX: Year:2004; pp. 121-136. [cited by applicant]
Mustafa Al-Bassam et al. “Airtnt: Fair Exchange Payment for Outsourced Secure Enclave Computations.” May 16, 2018. Conference'17, Jul. 2017, Washington, DC, USA. 12 pages. [cited by applicant]
Notice of Allowance for Korean Patent Application No. 10-2021-7007581 dated Jan. 6, 2023. 2 pages. [cited by applicant]
Office Action for Korean Patent Application No. 10-2021-7007581 dated Jul. 4, 2022. 6 pages. [cited by applicant]