IP Library › Granted Patent US 12,399,732
Granted Patent B2
US 12,399,732 · App. 17/644,598 · Granted Aug 26, 2025

Adjunct processor (AP) domain zeroize

Inventors: Louis P. Gomes (Poughkeepsie, NY); Richard John Moore (Waterlooville, GB); Klaus Paul Werner (Moetzingen, DE)
Assignee: International Business Machines Corporation
G06F9/45558G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,399,732
App. No.
17/644,598
Granted
Aug 26, 2025
Kind
B2
Abstract

A method, computer program product, and computer system are provided. A machine hypervisor builds and enqueue a zeroize adjunct processor (AP) domain (ZAPD) common command request message to a target AP domain queue. Machine firmware validates the enqueued common command request message on the target AP domain queue. The machine firmware converts the ZAPD command request to the mode-specific form of the domain zeroize request. A command request message is executed at an AP crypto adapter of the target AP domain. Executing includes zeroizing a storage area of the AP crypto adapter. The execution results are returned to the machine firmware. The machine firmware converts the crypto card mode's ZAPD command reply message into the common ZAPD command reply message. The final execution results including the converted common ZAPD command reply message are returned to the machine hypervisor.

Claims (91)

1. A method, comprising:

a machine hypervisor building and enqueuing a zeroize adjunct processor (AP) domain (ZAPD) common command request message to a target AP domain queue;

machine firmware validating the enqueued ZAPD common command request message on the target AP domain queue;

processor millicode converting the enqueued ZAPD common command request message to a format corresponding to a configured mode of an AP crypto adapter command request message;

executing the converted enqueued ZAPD common command request message at an AP crypto adapter of the target AP domain, wherein the crypto adapter is assigned to a virtual machine, and wherein the executing includes zeroizing a storage area of the AP crypto adapter by deleting secret keys assigned to the virtual machine from the AP crypto adapter; and

returning execution results to the machine hypervisor.

2. The method of claim 1 , wherein building and enqueuing the ZAPD command request message further comprises:

verifying a ZAPD command is installed for the target AP domain, and that a control domain and a usage domain are enabled for the target AP domain;

building, by the machine hypervisor, an abstracted common command request message wherein a format of the ZAPD common command request message is independent of a configuration mode of an AP crypto adapter;

setting an indicator in the ZAPD common command request message to bypass parsing of the ZAPD common command request message; and

setting an AP queue index to target AP domain, wherein the AP queue index corresponds to a domain number within the AP crypto adapter.

3. The method of claim 1 , wherein the validating further comprises:

based on having both control domain and usage domain access, storing the ZAPD common command request message on the AP crypto adapter of the target AP domain;

in response to a mismatch between the setting of the indicator in the ZAPD common command request message and the ZAPD common command request being ZAPD, generating a common command reply message, wherein a header of the common command reply message includes an error reply code; and

storing the ZAPD common command request message on the AP crypto adapter of the target AP domain.

4. The method of claim 1 , wherein the converting the enqueued ZAPD common command request message further comprises:

based on a configuration mode of the AP crypto adapter being accelerator mode, simulating the ZAPD common command request as a non-operation;

generating a common command reply message, wherein a normal completion reply code is stored in a header of the common command reply message; and

storing the common command reply message on the AP crypto adapter of the target AP domain.

5. The method of claim 4 , further comprising:

based on the configuration mode of the AP crypto adapter being other than accelerator mode, executing the ZAPD common command request message; and

firmware parsing the ZAPD common command request message and generating a resulting ZAPD command request message in a format corresponding to the configuration mode of the AP crypto adapter.

6. The method of claim 1 , wherein executing the command request message at an AP crypto adapter of the target AP domain further comprises:

validating, then executing, contents of the command request message;

in response to an error in the executing, the AP crypto adapter storing an error reply code in a connectivity programming request block of the command reply message;

based on the command request message being ZAPD, converting the command reply message to a common command reply message format corresponding to the configuration mode of the AP crypto adapter;

in response to a machine failure being returned for a ZAPD error, storing the machine failure in a header of the common command reply message; and dequeuing the command reply message from the AP crypto adapter of the target domain.

7. The method of claim 1 , wherein the configuration mode of an AP crypto adapter includes accelerator, Common Cryptographic Architecture (CCA, and Public-Key Cryptographic Standards (PKCS) #11 (XCP).

8. A computer program product, the computer program product comprising a non-transitory tangible storage device having program code embodied therewith, the program code executable by a processor of a computer to perform a method, the method comprising:

a machine hypervisor building and enqueuing a zeroize adjunct processor (AP) domain (ZAPD) common command request message to a target AP domain queue;

machine firmware validating the enqueued common command request message on the target AP domain queue;

machine firmware converting the enqueued common ZAPD command request message to a mode-specific form of the domain zeroize request;

executing the converted enqueued ZAPD command request message at an AP crypto adapter of the target AP domain, wherein the crypto adapter is assigned to a virtual machine, and wherein the executing includes zeroizing a storage area of the AP crypto adapter by deleting secret keys assigned to the virtual machine from the AP crypto adapter;

the AP crypto adapter returning execution results to the machine firmware;

machine firmware converting the AP crypto adapter ZAPD command reply message into the common ZAPD command reply message; and

returning final execution results including the converted common ZAPD command reply message to the machine hypervisor.

9. The computer program product of claim 8 , wherein building and enqueuing the ZAPD command request message further comprises:

verifying a ZAPD command is installed for the target AP domain, and that a control domain and a usage domain are enabled for the target AP domain;

building, by the machine hypervisor, an abstracted common command request message wherein a format of the ZAPD common command request message is independent of a configuration mode of an AP crypto adapter;

setting an indicator in the ZAPD common command request message to bypass parsing of the ZAPD common command request message; and

setting an AP queue index to target AP domain, wherein the AP queue index corresponds to a domain number within the AP crypto adapter.

10. The computer program product of claim 8 , wherein the validating further comprises:

based on having both control domain and usage domain access, storing the ZAPD common command request message on the AP crypto adapter of the target AP domain;

in response to a mismatch between the setting of the indicator in the ZAPD common command request message and the ZAPD common command request being ZAPD, generating a common command reply message, wherein a header of the common command reply message includes an error reply code; and

storing the ZAPD common command request message on the AP crypto adapter of the target AP domain.

11. The computer program product of claim 8 , wherein the converting the enqueued ZAPD common command request message further comprises:

based on a configuration mode of the AP crypto adapter being accelerator mode, simulating the ZAPD common command request as a non-operation;

generating the ZAPD common command reply message, wherein a normal completion reply code is stored in a header of the common command reply message; and

storing the common command reply message on the AP crypto adapter of the target AP domain.

12. The computer program product of claim 11 , further comprising:

based on the configuration mode of the AP crypto adapter being other than accelerator mode, executing the ZAPD common command request message;

firmware parsing the ZAPD common command request message and generating a resulting ZAPD command request message in a format corresponding to the configuration mode of the AP crypto adapter; and

firmware signing the ZAPD command request message using secret keys of the AP target domain.

13. The computer program product of claim 8 , wherein executing the command request message at an AP crypto adapter of the target AP domain further comprises:

validating, then executing, contents of the command request message;

in response to an error in the executing, the AP crypto adapter storing an error reply code in a connectivity programming request block of the command reply message;

based on the command request message being ZAPD, converting the command reply message to the ZAPD common command reply message format corresponding to a configuration mode of the AP crypto adapter;

in response to a machine failure being returned for a ZAPD error, storing the machine failure in in the a header of the common command reply message; and

dequeuing the command reply message from the AP crypto adapter of the target domain.

14. A computer system, comprising:

one or more processors;

a memory coupled to at least one of the processors;

a set of computer program instructions stored in the memory and executed by at least one of the processors in order to perform actions of:

a machine hypervisor building and enqueuing a zeroize adjunct processor (AP) domain (ZAPD) common command request message to a target AP domain queue;

machine firmware validating the enqueued ZAPD common command request message on the target AP domain queue;

processor millicode converting the enqueued ZAPD common command request message to a format corresponding to a configured mode of an AP crypto adapter command request message;

executing the converted enqueued ZAPD common command request message, including executing the converted enqueued ZAPD common request message at an AP crypto adapter of the target AP domain, wherein the crypto adapter is assigned to a virtual machine, and wherein the executing includes zeroizing a storage area of the AP crypto adapter by deleting secret keys assigned to the virtual machine from the AP crypto adapter; and

returning execution results to the machine hypervisor.

15. The computer system of claim 14 , wherein building and enqueuing the ZAPD command request message further comprises:

verifying a ZAPD command is installed for the target AP domain, and that a control domain and a usage domain are enabled for the target AP domain;

building, by the machine hypervisor, an abstracted ZAPD common command request message wherein a format of the ZAPD common command request message is independent of a configuration mode of an AP crypto adapter;

setting an indicator in the ZAPD common command request message to bypass parsing of the ZAPD common command request message; and

setting an AP queue index to target AP domain, wherein the AP queue index corresponds to a domain number within the AP crypto adapter.

16. The computer system of claim 14 , wherein the validating and further comprises:

based on having both control domain and usage domain access, storing the ZAPD common command request message on the AP crypto adapter of the target AP domain;

in response to a mismatch between the setting of the indicator and the ZAPD common command request being ZAPD, generating a common command reply message, wherein a header of the common command reply message includes an error reply code; and

storing the ZAPD common command request message on the AP crypto adapter of the target AP domain.

17. The computer system of claim 14 , wherein the converting the enqueued ZAPD common command request message further comprises:

based on the configuration mode of the AP crypto adapter being accelerator mode, simulating the ZAPD common command request as a non-operation;

generating a common command reply message, wherein a normal completion reply code is stored in a header of the common command reply message; and

storing the common command reply message on the AP crypto adapter of the target AP domain.

18. The computer system of claim 17 , further comprising:

based on the configuration mode of the AP crypto adapter being other than accelerator mode, executing the ZAPD common command request message; and

firmware parsing the ZAPD common command request message and generating a resulting ZAPD command request message in a format corresponding to the configuration mode of the AP crypto adapter.

19. The computer system of claim 14 , wherein executing the command request message at an AP crypto adapter of the target AP domain further comprises:

validating, then executing, contents of the command request message;

in response to an error in the executing, the AP crypto adapter storing an error reply code in a connectivity programming request block of the command reply message;

based on the command request message being ZAPD, converting the command reply message to the ZAPD common command reply message format corresponding to the configuration mode of the AP crypto adapter;

in response to a machine failure being returned for a ZAPD error, storing the machine failure in in the a header of the common command reply message; and

dequeuing the command reply message from the AP crypto adapter of the target domain.

20. The computer system of claim 14 , wherein the configuration mode of an AP crypto adapter includes accelerator, Common Cryptographic Architecture (CCA, and Public-Key Cryptographic Standards (PKCS) #11 (XCP).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2021
From: GOMES, LOUIS P.; MOORE, RICHARD JOHN; WERNER, KLAUS PAUL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058404/0888 →
Continuity (1)
Related Publication 20230195490A1 · Jun 22, 2023
References Cited (19)
US 6108425A · Smith, Sr. · 2000 [cited by applicant]
US 9160539B1 · Juels · 2015 [cited by applicant]
US 9405708B1 · Pohlack · 2016 [cited by applicant]
US 20110055560A1 · Meissner · 2011 [cited by examiner]
US 20160127336A1 · Cignetti · 2016 [cited by examiner]
US 20160127663A1 · Natori · 2016 [cited by applicant]
US 20190228163A1 · Lang · 2019 [cited by applicant]
TW 334540B · 2010 [cited by applicant]
International Searching Authority, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or Declaration,” Patent Cooperation Treaty, Mar. 17, 2… [cited by applicant]
Gomes, et al., “Adjunct Processor (AP) Domain Zeroize,” Application and Drawings, Filed on Dec. 9, 2022, 30 Pages, Related US Patent Application Serial No. PCT/EP2022/085094. [cited by applicant]
IBM, “Getting started with TKE at your enterprise,” Apr. 6, 2021, 50 pages, V2, IBM Corp., Retrieved from the Internet: <URL: https://www-40.ibm.com/servers/resourcelink/svc00100.nsf/pages/zOSV2R4izst100/$file/izst100_v… [cited by applicant]
Intellectual Property Office, Ministry of Economic Affairs, “Notification of Office Action,” May 19, 2023, 8 pages, Related TW Patent Application Serial No. 111133128, [Machine Tranlsated]. [cited by applicant]
Ben-Menahem, et al., “Multi-Cryptosystem Secure Token Interface,” IP.com, Jan. 17, 2006, 9 pages, IP.com No. IPCOM000133194D. [cited by applicant]
Bobinac, “SafeNet HSM solutions for secure virtual amd physical environments,” SafeNet, Oct. 1, 2013, 23 pages, Prague, CZ, retrieved from the Internet: <URL: https://www3.thalesgroup.com/events/2013/SafeNetExecDayPragu… [cited by applicant]
Disclosed Anonymously, “Live Migration of Crypto Domains of local HSMs,” IP.com, Dec. 16, 2014, 4 pages, IP.com No. IPCOM000239930D. [cited by applicant]
Disclosed Anonymously, “Master Key synchronization and replication,” IP.com, Oct. 30, 2020, 3 pages, IP.com No. IPCOM000264005D. [cited by applicant]
Disclosed Anonymously, “Support for Secure Virtual Machines and for Secure Applications,” IP.com, Nov. 5, 2019, 5 pages, IP.com No. IPCOM000260232D. [cited by applicant]
Inci, et al., “Seriously, get off my cloud! Cross-VM RSA Key Recovery in a Public Cloud,” IACR Cryptology ePrint Archive, 2015, 15 pages, Retrieved from the Internet: <URL: https://eprint.iacr.org/2015/898.pdf>. [cited by applicant]
Ramakrishna, “Virtualization Security Issues and Mitigations in Cloud Computing, ” Proceedings of the First International Conference on Computational Intelligence and Informatics, Jan. 2017, 13 pages, ResearchGate, Retr… [cited by applicant]