Quorum-based virtual machine security
Abstract
Technologies related to quorum-based Virtual Machine (VM) security are generally described. In some examples, VM data, such as a VM payload or other VM data, may be quorum-encrypted, such that a quorum of decryption keys may be used to decrypt the data. Decryption keys may be distributed among multiple VMs, with different decryption keys provided to different VMs, so that single VMs may not decrypt the VM data without decryption keys held by other VMs. To decrypt its data, a VM may assemble a quorum of decryption keys by requesting decryption keys held by other operational VMs, and the VM may then decrypt its data using the assembled quorum of decryption keys. The VM may be prevented from decrypting its data without a sufficient quorum of other operational VMs.
Claims
exact text as granted — not AI-modified1 . A virtual machine method to assemble decryption keys to decrypt an item of quorum-encrypted data, comprising:
assembling, by a virtual machine, a quorum of decryption keys to decrypt the item of quorum-encrypted data, the assembling comprising:
determining a number of decryption keys to decrypt the item of quorum-encrypted data, wherein the number of decryption keys comprises more than one decryption key;
sending one or more decryption key requests for decryption keys for the item of quorum-encrypted data held by one or more other virtual machines;
receiving one or more decryption keys for the item of quorum-encrypted data in response to the one or more decryption key requests; and
assembling the received decryption keys as the quorum of decryption keys to decrypt the item of quorum-encrypted data when a number of received decryption keys for the item of quorum-encrypted data is equal to or greater than the number of decryption keys to decrypt the item of quorum-encrypted data; and
decrypting, by the virtual machine, the item of quorum-encrypted data with the assembled quorum of decryption keys.
2 - 3 . (canceled)
4 . The method of claim 1 , wherein the virtual machine comprises a decryption key collection comprising decryption keys for use by the one or more other virtual machines in decrypting other items of quorum-encrypted data, and further comprising receiving a decryption key request and providing, in response to the received decryption key request, a decryption key from the decryption key collection for use by at least one other virtual machine to decrypt at least one other item of quorum-encrypted data.
5 - 9 . (canceled)
10 . The method of claim 1 , wherein the virtual machine and the one or more other virtual machines comprise virtual machines at a same data center and corresponding to a same data center customer.
11 . A non-transitory computer readable storage medium having computer executable instructions executable by a processor, the instructions that, when executed by the processor, cause the processor to:
assemble, at a virtual machine, a quorum of decryption keys to decrypt an item of quorum-encrypted data, the assembling comprising:
determining a number of decryption keys to decrypt the item of quorum-encrypted data, wherein the number of decryption keys comprises more than one decryption key;
sending one or more decryption key requests for decryption keys for the item of quorum-encrypted data held by one or more other virtual machines;
receiving one or more decryption keys for the item of quorum-encrypted data in response to the one or more decryption key requests; and
assembling the received decryption keys as the quorum of decryption keys to decrypt the item of quorum-encrypted data when a number of received decryption keys for the item of quorum-encrypted data is equal to or greater than the number of decryption keys to decrypt the item of quorum-encrypted data; and
decrypt the item of quorum-encrypted data with the assembled quorum of decryption keys.
12 - 13 . (canceled)
14 . The non-transitory computer readable storage medium of claim 11 , wherein the virtual machine comprises a decryption key collection comprising decryption keys for use by the one or more other virtual machines in decrypting other items of quorum-encrypted data, and further comprising instructions which cause the processor to receive a decryption key request and provide, in response to the received decryption key request, a decryption key from the decryption key collection for use by at least one other virtual machine to decrypt at least one other item of quorum-encrypted data.
15 - 20 . (canceled)
21 . A computing device configured to provide a virtual machine, comprising:
a processor; a memory; and a virtual machine stored in the memory and executable by the processor, wherein the virtual machine is configured to:
assemble a quorum of decryption keys to decrypt an item of quorum-encrypted data, the assembling comprising:
determining a number of decryption keys to decrypt the item of quorum-encrypted data, wherein the number of decryption keys comprises more than one decryption key;
sending one or more decryption key requests for decryption keys for the item of quorum-encrypted data held by one or more other virtual machines;
receiving one or more decryption keys for the item of quorum-encrypted data in response to the one or more decryption key requests; and
assembling the received decryption keys as the quorum of decryption keys to decrypt the item of quorum-encrypted data when a number of received decryption keys for the item of quorum-encrypted data is equal to or greater than the number of decryption keys to decrypt the item of quorum-encrypted data; and
decrypt the item of quorum-encrypted data with the assembled quorum of decryption keys.
22 . The computing device of claim 21 , wherein the virtual machine is configured to include, in the assembled quorum of decryption keys, a local decryption key stored at the virtual machine.
23 . The computing device of claim 22 , wherein the local decryption key is a necessary member of any assembled quorum of decryption keys to decrypt the item of quorum-encrypted data.
24 . The computing device of claim 21 , wherein the virtual machine comprises a decryption key collection comprising decryption keys for use by the one or more other virtual machines in decrypting other items of quorum-encrypted data, and wherein the virtual machine is configured to receive a decryption key request and provide, in response to the received decryption key request, a decryption key from the decryption key collection for use by at least one other virtual machine to decrypt at least one other item of quorum-encrypted data.
25 . The computing device of claim 24 , wherein the virtual machine is configured to receive one or more re-generated decryption keys for the decryption key collection, and replace decryption keys in the decryption key collection with the one or more re-generated decryption keys.
26 . The computing device of claim 24 , wherein the decryption keys in the decryption key collection are encrypted.
27 . The computing device of claim 24 , wherein the virtual machine is configured to authenticate the received decryption key request, and provide the decryption key from the decryption key collection in response to the received decryption key request when the decryption key request is authenticated.
28 . The computing device of claim 24 , wherein the virtual machine is configured to certify the one or more decryption key requests to allow the one or more other virtual machines to authenticate the decryption key requests.
29 . The computing device of claim 24 , wherein the virtual machine and the one or more other virtual machines comprise virtual machines at a same data center.
30 . The computing device of claim 24 , wherein the virtual machine and the one or more other virtual machines comprise virtual machines at a same data center and corresponding to a same data center customer.
31 - 60 . (canceled)
61 . The computing device of claim 24 , wherein the decryption key collection comprises a number of decryption keys that is commensurate with a security level associated with the virtual machine, such that the decryption key collection holds more decryption keys when the virtual machine is associated with a stronger security level.
62 . The computing device of claim 25 , wherein the one or more re-generated decryption keys comprise an increased number of decryption keys, wherein the increased number of decryption keys is responsive to a vulnerability at the virtual machine.
63 . The computing device of claim 21 , wherein the virtual machine is configured to re-assemble the quorum of decryption keys in order to decrypt the item of quorum-encrypted data in connection with a subsequent access to the quorum-encrypted data.
64 . The computing device of claim 21 , wherein the virtual machine and the one or more other virtual machines comprise virtual machines at a same computing device.
65 . The computing device of claim 21 , wherein the virtual machine and the one or more other virtual machines comprise virtual machines managed at a same virtual machine manager.Join the waitlist — get patent alerts
Track US2015381356A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.