Invention Grant
- Patent Title: Secure public cloud with protected guest-verified host control
-
Application No.: US16792941Application Date: 2020-02-18
-
Publication No.: US11163911B2Publication Date: 2021-11-02
- Inventor: David M. Durham , Gilbert Neiger , Barry E. Huntley , Ravi L. Sahita , Baiju V. Patel
- Applicant: Intel Corporation
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Agency: Trop, Pruner & Hu, P.C.
- Main IPC: H04L9/00
- IPC: H04L9/00 ; G06F21/71 ; G06F9/455 ; G06F21/53 ; G06F21/57 ; G06F21/78 ; G06F8/61 ; H04L9/08

Abstract:
According to one embodiment, a method comprises executing an untrusted host virtual machine monitor (VMM) to manage execution of at least one guest virtual machine (VM). The VMM receives an encrypted key domain key, an encrypted guest code image, and an encrypted guest control structure. The VM also issues a create command. In response, a processor creates a first key domain comprising a region of memory to be encrypted by a key domain key. The encrypted key domain key is decrypted to produce the key domain key, which is inaccessible to the VMM. The VMM issues a launch command. In response, a first guest VM is launched within the first key domain. In response to a second launch command, a second guest VM is launched within the first key domain. The second guest VM provides an agent to act on behalf of the VMM. Other embodiments are described and claimed.
Public/Granted literature
- US20200257828A1 Secure Public Cloud with Protected Guest-Verified Host Control Public/Granted day:2020-08-13
Information query