Virtual machine memory compartmentalization in multi-core architectures
    2.
    发明授权
    Virtual machine memory compartmentalization in multi-core architectures 有权
    多核架构虚拟机内存分区

    公开(公告)号:US08990582B2

    公开(公告)日:2015-03-24

    申请号:US12789207

    申请日:2010-05-27

    摘要: Techniques for memory compartmentalization for trusted execution of a virtual machine (VM) on a multi-core processing architecture are described. Memory compartmentalization may be achieved by encrypting layer 3 (L3) cache lines using a key under the control of a given VM within the trust boundaries of the processing core on which that VMs is executed. Further, embodiments described herein provide an efficient method for storing and processing encryption related metadata associated with each encrypt/decrypt operation performed for the L3 cache lines.

    摘要翻译: 描述了用于多核处理架构上的虚拟机(VM)的可信执行的用于存储器区分的技术。 可以通过使用在执行VM的处理核心的信任边界内的给定VM的控制下的密钥来加密层3(L3)高速缓存线来实现内存区分。 此外,本文描述的实施例提供了一种用于存储和处理与针对L3高速缓存行执行的每个加密/解密操作相关联的加密相关元数据的有效方法。

    Method and apparatus for trusted execution in infrastructure as a service cloud environments
    3.
    发明授权
    Method and apparatus for trusted execution in infrastructure as a service cloud environments 有权
    在基础架构中作为服务云环境中的可信执行的方法和装置

    公开(公告)号:US08812871B2

    公开(公告)日:2014-08-19

    申请号:US12789189

    申请日:2010-05-27

    IPC分类号: G06F21/00

    摘要: The present disclosure presents a method and apparatus configured to provide for the trusted execution of virtual machines (VMs) on a virtualization server, e.g., for executing VMs on a virtualization server provided within Infrastructure as a Service (IaaS) cloud environment. A physical multi-core CPU may be configured with a hardware trust anchor. The trust anchor itself may be configured to manage session keys used to encrypt/decrypt instructions and data when a VM (or hypervisor) is executed on one of the CPU cores. When a context switch occurs due to an exception, the trust anchor swaps the session key used to encrypt/decrypt the contents of memory and cache allocated to a VM (or hypervisor).

    摘要翻译: 本公开提供了一种方法和装置,被配置为提供虚拟化服务器上​​虚拟机(VM)的可信执行,例如用于在基础架构即服务(IaaS)云环境中提供的虚拟化服务器上​​执行虚拟机。 物理多核CPU可以配置有硬件信任锚点。 当在其中一个CPU核上执行VM(或管理程序)时,信任锚本身可以被配置为管理用于加密/解密指令和数据的会话密钥。 当由于异常而发生上下文切换时,信任锚转换用于加密/解密分配给VM(或管理程序)的内存和缓存内容的会话密钥。

    METHOD AND APPARATUS FOR TRUSTED EXECUTION IN INFRASTRUCTURE AS A SERVICE CLOUD ENVIRONMENTS
    5.
    发明申请
    METHOD AND APPARATUS FOR TRUSTED EXECUTION IN INFRASTRUCTURE AS A SERVICE CLOUD ENVIRONMENTS 有权
    作为服务云环境的基础设施执行的方法和装置

    公开(公告)号:US20110296201A1

    公开(公告)日:2011-12-01

    申请号:US12789189

    申请日:2010-05-27

    IPC分类号: G06F21/22 G06F9/455

    摘要: The present disclosure presents a method and apparatus configured to provide for the trusted execution of virtual machines (VMs) on a virtualization server, e.g., for executing VMs on a virtualization server provided within Infrastructure as a Service (IaaS) cloud environment. A physical multi-core CPU may be configured with a hardware trust anchor. The trust anchor itself may be configured to manage session keys used to encrypt/decrypt instructions and data when a VM (or hypervisor) is executed on one of the CPU cores. When a context switch occurs due to an exception, the trust anchor swaps the session key used to encrypt/decrypt the contents of memory and cache allocated to a VM (or hypervisor).

    摘要翻译: 本公开提供了一种方法和装置,被配置为提供虚拟化服务器上​​虚拟机(VM)的可信执行,例如用于在基础架构即服务(IaaS)云环境中提供的虚拟化服务器上​​执行虚拟机。 物理多核CPU可以配置有硬件信任锚点。 当在其中一个CPU核上执行VM(或管理程序)时,信任锚本身可以被配置为管理用于加密/解密指令和数据的会话密钥。 当由于异常而发生上下文切换时,信任锚转换用于加密/解密分配给VM(或管理程序)的内存和缓存内容的会话密钥。

    Methods and apparatus for confidentiality protection for Fibre Channel Common Transport
    7.
    发明授权
    Methods and apparatus for confidentiality protection for Fibre Channel Common Transport 有权
    光纤通道共同运输机密保护方法与装置

    公开(公告)号:US07333612B2

    公开(公告)日:2008-02-19

    申请号:US10805111

    申请日:2004-03-19

    IPC分类号: H04K1/00 H04L9/00

    摘要: Methods and apparatus are provided for improving message-based security in a Fibre Channel network. More specifically, the present invention relates to methods and apparatus for providing confidentiality for Fibre Channel control messages encapsulated within Common Transport Information Units. Control messages transported with the Fibre Channel Common Transport protocol, and passed between Fibre Channel network entities, can be encrypted providing confidentiality combined with data origin authentication, integrity and anti-replay protection provided by existing Fibre Channel security mechanisms.

    摘要翻译: 提供了用于在光纤通道网络中改进基于消息的安全性的方法和装置。 更具体地,本发明涉及用于为公共传输信息单元中封装的光纤通道控制消息提供保密性的方法和装置。 通过光纤通道公共传输协议传输的光纤通道公共传输协议传输的控制消息可以通过光纤通道网络实体进行加密,从而提供机密性,并结合现有光纤通道安全机制提供的数据源认证,完整性和防重放保护。

    Key transport in authentication or cryptography
    8.
    发明授权
    Key transport in authentication or cryptography 有权
    密钥传输在认证或加密

    公开(公告)号:US08356177B2

    公开(公告)日:2013-01-15

    申请号:US12604221

    申请日:2009-10-22

    IPC分类号: H04L9/00

    摘要: A computer system for authenticating, encrypting, and transmitting a secret communication, where the encryption key is transmitted along with the encrypted message, is disclosed. In an embodiment, a first transmitting processor encrypts a plaintext message to a ciphertext message using a data key, encrypts the data key using a key encrypting key, and sends a communication comprising the encrypted data key and the ciphertext message. A second receiving processor receives the communication and then decrypts the encrypted data key using the key encrypting key and decrypts the ciphertext message using the data key to recover the plaintext message.

    摘要翻译: 公开了一种用于认证,加密和发送秘密通信的计算机系统,其中加密密钥与加密消息一起发送。 在一个实施例中,第一发送处理器使用数据密钥将明文消息加密为密文消息,使用密钥加密密钥加密数据密钥,并发送包括加密数据密钥和密文消息的通信。 第二接收处理器接收通信,然后使用密钥加密密钥解密加密的数据密钥,并使用数据密钥解密密文消息以恢复明文消息。

    Method and apparatus for performing encryption of data at rest at a port of a network device
    9.
    发明授权
    Method and apparatus for performing encryption of data at rest at a port of a network device 有权
    用于在网络设备的端口处静止地进行数据的加密的方法和装置

    公开(公告)号:US08266431B2

    公开(公告)日:2012-09-11

    申请号:US11264191

    申请日:2005-10-31

    IPC分类号: G06F21/00

    摘要: Methods and apparatus for performing encryption for data at rest at a port of a network device such as a switch are disclosed. Specifically, when data is received from a host during a write to a storage medium such as a disk, the data is encrypted by the port prior to transmitting the encrypted data to the storage medium. Similarly, when a host attempts to read data from the storage medium, the port of the network device receives the encrypted data from the storage medium, decrypts the data, and transmits the decrypted data to the host. In this manner, encryption and decryption of data at rest are supported by the port of the network device.

    摘要翻译: 公开了用于在诸如交换机的网络设备的端口处静止的数据执行加密的方法和装置。 具体地说,当在向诸如盘的存储介质的写入期间从主机接收到数据时,在将加密数据发送到存储介质之前,数据被端口加密。 类似地,当主机尝试从存储介质读取数据时,网络设备的端口从存储介质接收加密的数据,解密数据,并将解密的数据发送到主机。 以这种方式,网络设备的端口支持静止数据的加密和解密。

    Methods and apparatus for security over fibre channel
    10.
    发明授权
    Methods and apparatus for security over fibre channel 有权
    光纤通道安全的方法和装置

    公开(公告)号:US07965843B1

    公开(公告)日:2011-06-21

    申请号:US10034367

    申请日:2001-12-27

    IPC分类号: H04L9/12

    摘要: Methods and apparatus are provided for improving both node-based and message-based security in a fibre channel network. Entity to entity authentication and key exchange services can be included in existing initialization messages used for introducing fibre channel network entities into a fibre channel fabric, or with specific messages exchanged over an already initialized communication channel. Both per-message authentication and encryption mechanisms can be activated using the authentication and key exchange services. Messages passed between fibre channel network entities can be encrypted and authenticated using information provided during the authentication sequence. Security services such as per-message authentication, confidentiality, integrity protection, and anti-replay protection can be implemented.

    摘要翻译: 提供了用于改进光纤通道网络中的基于节点和基于消息的安全性的方法和装置。 可以将实体认证和密钥交换服务的实体包括在用于将光纤信道网络实体引入光纤信道结构的现有初始化消息中,或者通过已经初始化的通信信道交换的特定消息。 可以使用认证和密钥交换服务来激活每消息认证和加密机制。 在光纤通道网络实体之间通过的消息可以使用在认证序列期间提供的信息进行加密和认证。 可以实现诸如每消息认证,机密性,完整性保护和反重放保护等安全服务。