Technologies for providing efficient sharing of encrypted data in a disaggregated architecture
Abstract
Technologies for providing efficient sharing of encrypted data in a disaggregated architecture include a sled. The sled includes a set of memory devices and a controller connected to the set of memory devices. The memory controller is to receive, from a first application executed by a compute sled, a data access request to share a data set between the first application and a second application. The data set is encrypted in one or more of the memory devices. Additionally, the controller is to determine, in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set. Further, the controller is to send, to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set and send, to the second application, a handle associated with an address in the set of memory devices where the data set is located.
Claims
exact text as granted — not AI-modified1 . A sled comprising:
a set of memory devices; and a controller connected to the set of memory devices, wherein the controller is to: receive, from a first application executed by a compute sled, a data access request to share a data set between the first application and a second application, wherein the data set is encrypted in one or more of the memory devices; determine, in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set; send, to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set; and send, to the second application, a handle associated with an address in the set of memory devices where the data set is located.
2 . The sled of claim 1 , wherein the controller is further to:
determine whether the data set has been accessed with at least a predefined frequency over a predefined period of time; move, in response to a determination that the data set has not been accessed with at least the predefined frequency over the predefined period of time, the data set to a data storage device; and store, with the data set, access control data indicative of credentials that are usable to access the data set.
3 . The sled of claim 1 , wherein the controller is further to:
receive a request to migrate working data of the first application, wherein the first application is to be moved from a first compute sled to a second compute sled; and send, to the second compute sled, a handle to the working data of the first application.
4 . The sled of claim 1 , wherein sled is located in a data center and the controller is further map an address of memory that is present on at least one other sled in the data center.
5 . The sled of claim 1 , wherein the controller is further to:
receive a write request to write data to the data set; determine, in response to the write request, whether the data set is shared by multiple applications; fork, in response to a determination that the data set is shared by multiple applications, the data set to another location in the set of memory devices; write the data from the write request to the forked data set; and send, in response to the write request, a handle to the forked data set.
6 . The sled of claim 1 , wherein to determine the key identifier comprises to:
determine a memory address associated with a handle included in the data access request; and determine the key identifier as a function of the determined memory address.
7 . The sled of claim 6 , wherein to determine the key identifier as a function of the determined memory address comprises to determine the key identifier as a subset of the memory address.
8 . The sled of claim 6 , wherein to determine the key identifier as a function of the determined memory address comprises to look up the key identifier in a database that associates memory addresses with key identifiers.
9 . The sled of claim 1 , wherein to determine the key identifier comprises obtain the key identifier from a predefined register or a data structure associated with a compute sled on which the first application is executed.
10 . The sled of claim 1 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the key identifier with the request.
11 . The sled of claim 10 , wherein to send, to an encryption key manager, a request to provide the key comprises to send a request for a key that is escrowed with the encryption key manager by a memory encryption engine of a sled that sent the data access request.
12 . The sled of claim 10 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the request to an encryption key manager hosted by a compute sled from which the data access request was received.
13 . The sled of claim 10 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the request to an encryption key manager hosted by an orchestrator server.
14 . One or more non-transitory machine-readable storage media comprising a plurality of instructions stored thereon that, in response to being executed, cause a sled to:
receive, from a first application executed by a compute sled, a data access request to share a data set between the first application and a second application, wherein the data set is encrypted in one or more memory devices of a set of memory devices connected to the sled; determine, in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set; send, to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set; and send, to the second application, a handle associated with an address in the set of memory devices where the data set is located.
15 . The one or more non-transitory machine-readable storage media of claim 14 , wherein, when executed, the plurality of instructions further cause the sled to:
determine whether the data set has been accessed with at least a predefined frequency over a predefined period of time; move, in response to a determination that the data set has not been accessed with at least the predefined frequency over the predefined period of time, the data set to a data storage device; and store, with the data set, access control data indicative of credentials that are usable to access the data set.
16 . The one or more non-transitory machine-readable storage media of claim 14 , wherein, when executed, the plurality of instructions further cause the sled to:
receive a request to migrate working data of the first application, wherein the first application is to be moved from a first compute sled to a second compute sled; and send, to the second compute sled, a handle to the working data of the first application.
17 . The one or more non-transitory machine-readable storage media of claim 14 , wherein the sled is located in a data center and wherein, when executed, the plurality of instructions further cause the sled to map an address of memory that is present on at least one other sled in the data center.
18 . The one or more non-transitory machine-readable storage media of claim 14 , wherein, when executed, the plurality of instructions further cause the sled to:
receive a write request to write data to the data set; determine, in response to the write request, whether the data set is shared by multiple applications; fork, in response to a determination that the data set is shared by multiple applications, the data set to another location in the set of memory devices; write the data from the write request to the forked data set; and send, in response to the write request, a handle to the forked data set.
19 . The one or more non-transitory machine-readable storage media of claim 14 , wherein to determine the key identifier comprises to:
determine a memory address associated with a handle included in the data access request; and determine the key identifier as a function of the determined memory address.
20 . The one or more non-transitory machine-readable storage media of claim 19 , wherein to determine the key identifier as a function of the determined memory address comprises to determine the key identifier as a subset of the memory address.
21 . The one or more non-transitory machine-readable storage media of claim 19 , wherein to determine the key identifier as a function of the determined memory address comprises to look up the key identifier in a database that associates memory addresses with key identifiers.
22 . A method comprising:
receiving, by a memory controller, from a first application executed by a compute device, a data access request to share a data set between the first application and a second application, wherein the data set is encrypted in one or more memory devices of a set of memory devices connected to the memory controller; determining, by the memory controller and in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set; sending, by the memory controller and to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set; and sending, by the memory controller and to the second application, a handle associated with an address in the set of memory devices where the data set is located.
23 . The method of claim 22 , further comprising:
determining, by the memory controller, whether the data set has been accessed with at least a predefined frequency over a predefined period of time; moving, by the memory controller and in response to a determination that the data set has not been accessed with at least the predefined frequency over the predefined period of time, the data set to a data storage device; and storing, with the data set, access control data indicative of credentials that are usable to access the data set.
24 . The method of claim 22 , further comprising:
receiving, by the memory controller, a request to migrate working data of the first application, wherein the first application is to be moved from a first compute sled to a second compute sled; and sending, by the memory controller and to the second compute sled, a handle to the working data of the first application.
25 . The method of claim 22 , wherein the memory controller is in a sled that is located in a data center, the method further comprising mapping, by the memory controller, an address of memory that is present on at least one other sled in the data center.
26 . A sled comprising:
means for receiving, from a first application executed by a compute device, a data access request to share a data set between the first application and a second application, wherein the data set is encrypted in one or more memory devices of a set of memory devices connected to the sled; means for determining, in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set; means for sending, to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set; and means for sending, to the second application, a handle associated with an address in the set of memory devices where the data set is located.
27 . A controller connected to a set of memory devices, the controller comprising:
circuitry to: receive, from a first application executed by a compute sled, a data access request to share a data set between the first application and a second application, wherein the data set is encrypted in one or more of the memory devices; determine, in response to the data access request, a key identifier that uniquely identifies a key that is usable to perform cryptographic operations on the data set; send, to an encryption key manager, a request to provide the key corresponding to the key identifier to be used by the second application to decrypt the data set; and send, to the second application, a handle associated with an address in the set of memory devices where the data set is located.
28 . The controller of claim 27 , wherein the circuitry is further to:
determine whether the data set has been accessed with at least a predefined frequency over a predefined period of time; move, in response to a determination that the data set has not been accessed with at least the predefined frequency over the predefined period of time, the data set to a data storage device; and store, with the data set, access control data indicative of credentials that are usable to access the data set.
29 . The controller of claim 27 , wherein the circuitry is further to:
receive a request to migrate working data of the first application, wherein the first application is to be moved from a first compute sled to a second compute sled; and send, to the second compute sled, a handle to the working data of the first application.
30 . The controller of claim 27 , wherein the controller is located in a sled in a data center and the circuitry is further to map an address of memory that is present on at least one other sled in the data center.
31 . The controller of claim 27 , wherein the circuitry is further to:
receive a write request to write data to the data set; determine, in response to the write request, whether the data set is shared by multiple applications; fork, in response to a determination that the data set is shared by multiple applications, the data set to another location in the set of memory devices; write the data from the write request to the forked data set; and send, in response to the write request, a handle to the forked data set.
32 . The controller of claim 27 , wherein to determine the key identifier comprises to:
determine a memory address associated with a handle included in the data access request; and determine the key identifier as a function of the determined memory address.
33 . The controller of claim 32 , wherein to determine the key identifier as a function of the determined memory address comprises to determine the key identifier as a subset of the memory address.
34 . The controller of claim 32 , wherein to determine the key identifier as a function of the determined memory address comprises to look up the key identifier in a database that associates memory addresses with key identifiers.
35 . The controller of claim 27 , wherein to determine the key identifier comprises obtain the key identifier from a predefined register or a data structure associated with a compute sled on which the first application is executed.
36 . The controller of claim 27 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the key identifier with the request.
37 . The controller of claim 36 , wherein to send, to an encryption key manager, a request to provide the key comprises to send a request for a key that is escrowed with the encryption key manager by a memory encryption engine of a sled that sent the data access request.
38 . The controller of claim 36 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the request to an encryption key manager hosted by a compute sled from which the data access request was received.
39 . The controller of claim 36 , wherein to send, to an encryption key manager, a request to provide the key comprises to send the request to an encryption key manager hosted by an orchestrator server.Join the waitlist — get patent alerts
Track US2019052457A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.