US2019052457A1PendingUtilityA1

Technologies for providing efficient sharing of encrypted data in a disaggregated architecture

Assignee: INTEL CORPPriority: Aug 30, 2017Filed: Mar 30, 2018Published: Feb 14, 2019
Est. expiryAug 30, 2037(~11.1 yrs left)· nominal 20-yr term from priority
G06F 9/4401G06F 30/34G06F 2213/0064G11C 29/38H04L 69/22G06F 2212/1052G06F 3/0613G06F 3/0644G06F 16/2237G06F 16/25H04L 41/0668G06F 2201/85G06F 3/0631H04L 47/11G06F 13/1663H04L 45/7453G06F 16/119G06F 13/4068G11C 8/12G06F 16/248G06F 12/06G06F 16/2453G06F 15/161G06F 2209/509G06F 16/24553G06F 3/0659G06F 3/0611G06F 9/4494H04L 49/30G06F 12/1054G06F 3/065G06F 3/0685G06F 13/1668G06F 16/2255G06F 16/2455G06F 13/42G06F 3/067G06F 2212/1044G06F 3/0673H04L 41/0213G06F 2212/601H04L 49/9005G11C 29/028G06F 3/0605G06F 3/0629G06F 16/9014G06F 9/28G06F 16/221G06F 9/4406G06F 9/4411G11C 29/44H04L 69/12G06F 15/17331G06F 12/14H04L 49/351G06F 12/023H04L 9/0894G06F 12/0607G06F 3/0647G06F 16/2282G06F 16/2365G06F 9/445H04L 41/0677G06F 3/0683G06F 12/1063H04L 47/125G06F 3/0632G11C 29/36G06F 12/0802G06F 9/5088H04L 45/28G06F 3/0604G06F 17/30079H04L 9/0819H04L 69/32H04L 41/14H04L 41/0893H04L 41/0896H04L 69/321H04L 47/83H04L 43/20H04L 41/149H04L 41/0895H04L 41/40H04L 41/34H04L 69/18G06F 2209/5019G06F 9/5055G06F 9/5022G06F 9/5044H04L 67/1001Y02D10/00G06F 2201/885G06F 2201/86G06F 11/3466G06F 11/3442G06F 11/3006G06F 11/3409H05K 7/1498H04L 43/0876H04L 43/065H04L 41/0816H04L 41/044G06N 3/063H04L 43/16H04L 41/5019H04L 41/5025H04L 49/40G06Q 30/0283G06Q 10/0631G06F 21/105G06F 13/4022G06F 9/5061G06F 9/4856G06F 9/44H05K 7/20736H05K 7/20209H05K 7/18H05K 7/1489H04L 67/1008H04L 63/0428G06F 2200/201G06F 15/7867G06F 9/505G06F 2213/3808G06F 2213/0026G06F 15/1735H04L 47/781H04L 41/16H04L 41/142G06F 3/0665G06F 15/173H04Q 11/0062H04Q 11/0005
71
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Technologies for providing efficient sharing of encrypted data in a disaggregated architecture include a sled. The sled includes a set of memory devices and a controller connected to the set of memory devices. The memory controller is to receive, from a first application executed by a compute sled, a data access request to share a data set between the first application and a second application. The data set is encrypted in one or more of the memory devices. Additionally, the controller is to determine, in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set. Further, the controller is to send, to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set and send, to the second application, a handle associated with an address in the set of memory devices where the data set is located.

Claims

exact text as granted — not AI-modified
1 . A sled comprising:
 a set of memory devices; and   a controller connected to the set of memory devices, wherein the controller is to:   receive, from a first application executed by a compute sled, a data access request to share a data set between the first application and a second application, wherein the data set is encrypted in one or more of the memory devices;   determine, in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set;   send, to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set; and   send, to the second application, a handle associated with an address in the set of memory devices where the data set is located.   
     
     
         2 . The sled of  claim 1 , wherein the controller is further to:
 determine whether the data set has been accessed with at least a predefined frequency over a predefined period of time;   move, in response to a determination that the data set has not been accessed with at least the predefined frequency over the predefined period of time, the data set to a data storage device; and   store, with the data set, access control data indicative of credentials that are usable to access the data set.   
     
     
         3 . The sled of  claim 1 , wherein the controller is further to:
 receive a request to migrate working data of the first application, wherein the first application is to be moved from a first compute sled to a second compute sled; and   send, to the second compute sled, a handle to the working data of the first application.   
     
     
         4 . The sled of  claim 1 , wherein sled is located in a data center and the controller is further map an address of memory that is present on at least one other sled in the data center. 
     
     
         5 . The sled of  claim 1 , wherein the controller is further to:
 receive a write request to write data to the data set;   determine, in response to the write request, whether the data set is shared by multiple applications;   fork, in response to a determination that the data set is shared by multiple applications, the data set to another location in the set of memory devices;   write the data from the write request to the forked data set; and   send, in response to the write request, a handle to the forked data set.   
     
     
         6 . The sled of  claim 1 , wherein to determine the key identifier comprises to:
 determine a memory address associated with a handle included in the data access request; and   determine the key identifier as a function of the determined memory address.   
     
     
         7 . The sled of  claim 6 , wherein to determine the key identifier as a function of the determined memory address comprises to determine the key identifier as a subset of the memory address. 
     
     
         8 . The sled of  claim 6 , wherein to determine the key identifier as a function of the determined memory address comprises to look up the key identifier in a database that associates memory addresses with key identifiers. 
     
     
         9 . The sled of  claim 1 , wherein to determine the key identifier comprises obtain the key identifier from a predefined register or a data structure associated with a compute sled on which the first application is executed. 
     
     
         10 . The sled of  claim 1 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the key identifier with the request. 
     
     
         11 . The sled of  claim 10 , wherein to send, to an encryption key manager, a request to provide the key comprises to send a request for a key that is escrowed with the encryption key manager by a memory encryption engine of a sled that sent the data access request. 
     
     
         12 . The sled of  claim 10 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the request to an encryption key manager hosted by a compute sled from which the data access request was received. 
     
     
         13 . The sled of  claim 10 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the request to an encryption key manager hosted by an orchestrator server. 
     
     
         14 . One or more non-transitory machine-readable storage media comprising a plurality of instructions stored thereon that, in response to being executed, cause a sled to:
 receive, from a first application executed by a compute sled, a data access request to share a data set between the first application and a second application, wherein the data set is encrypted in one or more memory devices of a set of memory devices connected to the sled;   determine, in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set;   send, to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set; and   send, to the second application, a handle associated with an address in the set of memory devices where the data set is located.   
     
     
         15 . The one or more non-transitory machine-readable storage media of  claim 14 , wherein, when executed, the plurality of instructions further cause the sled to:
 determine whether the data set has been accessed with at least a predefined frequency over a predefined period of time;   move, in response to a determination that the data set has not been accessed with at least the predefined frequency over the predefined period of time, the data set to a data storage device; and   store, with the data set, access control data indicative of credentials that are usable to access the data set.   
     
     
         16 . The one or more non-transitory machine-readable storage media of  claim 14 , wherein, when executed, the plurality of instructions further cause the sled to:
 receive a request to migrate working data of the first application, wherein the first application is to be moved from a first compute sled to a second compute sled; and   send, to the second compute sled, a handle to the working data of the first application.   
     
     
         17 . The one or more non-transitory machine-readable storage media of  claim 14 , wherein the sled is located in a data center and wherein, when executed, the plurality of instructions further cause the sled to map an address of memory that is present on at least one other sled in the data center. 
     
     
         18 . The one or more non-transitory machine-readable storage media of  claim 14 , wherein, when executed, the plurality of instructions further cause the sled to:
 receive a write request to write data to the data set;   determine, in response to the write request, whether the data set is shared by multiple applications;   fork, in response to a determination that the data set is shared by multiple applications, the data set to another location in the set of memory devices;   write the data from the write request to the forked data set; and   send, in response to the write request, a handle to the forked data set.   
     
     
         19 . The one or more non-transitory machine-readable storage media of  claim 14 , wherein to determine the key identifier comprises to:
 determine a memory address associated with a handle included in the data access request; and   determine the key identifier as a function of the determined memory address.   
     
     
         20 . The one or more non-transitory machine-readable storage media of  claim 19 , wherein to determine the key identifier as a function of the determined memory address comprises to determine the key identifier as a subset of the memory address. 
     
     
         21 . The one or more non-transitory machine-readable storage media of  claim 19 , wherein to determine the key identifier as a function of the determined memory address comprises to look up the key identifier in a database that associates memory addresses with key identifiers. 
     
     
         22 . A method comprising:
 receiving, by a memory controller, from a first application executed by a compute device, a data access request to share a data set between the first application and a second application, wherein the data set is encrypted in one or more memory devices of a set of memory devices connected to the memory controller;   determining, by the memory controller and in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set;   sending, by the memory controller and to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set; and   sending, by the memory controller and to the second application, a handle associated with an address in the set of memory devices where the data set is located.   
     
     
         23 . The method of  claim 22 , further comprising:
 determining, by the memory controller, whether the data set has been accessed with at least a predefined frequency over a predefined period of time;   moving, by the memory controller and in response to a determination that the data set has not been accessed with at least the predefined frequency over the predefined period of time, the data set to a data storage device; and   storing, with the data set, access control data indicative of credentials that are usable to access the data set.   
     
     
         24 . The method of  claim 22 , further comprising:
 receiving, by the memory controller, a request to migrate working data of the first application, wherein the first application is to be moved from a first compute sled to a second compute sled; and   sending, by the memory controller and to the second compute sled, a handle to the working data of the first application.   
     
     
         25 . The method of  claim 22 , wherein the memory controller is in a sled that is located in a data center, the method further comprising mapping, by the memory controller, an address of memory that is present on at least one other sled in the data center. 
     
     
         26 . A sled comprising:
 means for receiving, from a first application executed by a compute device, a data access request to share a data set between the first application and a second application, wherein the data set is encrypted in one or more memory devices of a set of memory devices connected to the sled;   means for determining, in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set;   means for sending, to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set; and   means for sending, to the second application, a handle associated with an address in the set of memory devices where the data set is located.   
     
     
         27 . A controller connected to a set of memory devices, the controller comprising:
 circuitry to:   receive, from a first application executed by a compute sled, a data access request to share a data set between the first application and a second application, wherein the data set is encrypted in one or more of the memory devices;   determine, in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set;   send, to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set; and   send, to the second application, a handle associated with an address in the set of memory devices where the data set is located.   
     
     
         28 . The controller of  claim 27 , wherein the circuitry is further to:
 determine whether the data set has been accessed with at least a predefined frequency over a predefined period of time;   move, in response to a determination that the data set has not been accessed with at least the predefined frequency over the predefined period of time, the data set to a data storage device; and   store, with the data set, access control data indicative of credentials that are usable to access the data set.   
     
     
         29 . The controller of  claim 27 , wherein the circuitry is further to:
 receive a request to migrate working data of the first application, wherein the first application is to be moved from a first compute sled to a second compute sled; and   send, to the second compute sled, a handle to the working data of the first application.   
     
     
         30 . The controller of  claim 27 , wherein the controller is located in a sled in a data center and the circuitry is further to map an address of memory that is present on at least one other sled in the data center. 
     
     
         31 . The controller of  claim 27 , wherein the circuitry is further to:
 receive a write request to write data to the data set;   determine, in response to the write request, whether the data set is shared by multiple applications;   fork, in response to a determination that the data set is shared by multiple applications, the data set to another location in the set of memory devices;   write the data from the write request to the forked data set; and   send, in response to the write request, a handle to the forked data set.   
     
     
         32 . The controller of  claim 27 , wherein to determine the key identifier comprises to:
 determine a memory address associated with a handle included in the data access request; and   determine the key identifier as a function of the determined memory address.   
     
     
         33 . The controller of  claim 32 , wherein to determine the key identifier as a function of the determined memory address comprises to determine the key identifier as a subset of the memory address. 
     
     
         34 . The controller of  claim 32 , wherein to determine the key identifier as a function of the determined memory address comprises to look up the key identifier in a database that associates memory addresses with key identifiers. 
     
     
         35 . The controller of  claim 27 , wherein to determine the key identifier comprises obtain the key identifier from a predefined register or a data structure associated with a compute sled on which the first application is executed. 
     
     
         36 . The controller of  claim 27 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the key identifier with the request. 
     
     
         37 . The controller of  claim 36 , wherein to send, to an encryption key manager, a request to provide the key comprises to send a request for a key that is escrowed with the encryption key manager by a memory encryption engine of a sled that sent the data access request. 
     
     
         38 . The controller of  claim 36 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the request to an encryption key manager hosted by a compute sled from which the data access request was received. 
     
     
         39 . The controller of  claim 36 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the request to an encryption key manager hosted by an orchestrator server.

Join the waitlist — get patent alerts

Track US2019052457A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.