Authentication of virtual machine images using digital certificates
Abstract
A vendor of virtual machine images accesses a virtual computer system service to upload a digitally signed virtual machine image to a data store usable by customers of the virtual computer system service to select an image for creating a virtual machine instance. If a digital certificate is uploaded along with the virtual machine image, the virtual computer system service may determine whether the digital certificate has been trusted for use. If the digital certificate has been trusted for use, the virtual computer system service may use a public cryptographic key to decrypt a hash signature included with the image to obtain a first hash value. The service may additionally apply a hash function to the image itself to obtain a second hash value. If the two hash values match, then the virtual machine image may be deemed to be authentic.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method, comprising:
under control of one or more computer systems configured with executable instructions,
storing a virtual machine image and a digital signature;
receiving a request to launch a virtual machine using the virtual machine image;
determining whether the digital signature is valid;
determining, based at least in part on a policy relating to launching virtual machines signed by a machine image provider, whether to authorize launching of the virtual machine, the policy being configured such that evaluation of the policy is dependent at least in part on the digital signature being valid; and
as a result of determining that the policy authorizes launching of the virtual machine, using the virtual machine image to launch the virtual machine.
2 . The computer-implemented method of claim 1 , further comprising using a public key obtained from a digital certificate issued by a certificate authority to verify the digital signature prior to storing the virtual machine image.
3 . The computer-implemented method of claim 1 , wherein the virtual machine image is stored within a computing resource service provider marketplace comprising a plurality of virtual machine images that have been verified as authentic and virtual machine images that have not been verified as authentic such that a customer of a computing resource service provider can select the virtual machine image from the computing resource service provider marketplace.
4 . The computer-implemented method of claim 1 , wherein the policy specifies that only virtual machine images having a corresponding digital signature can be used to launch virtual machines within a virtual network of a user that submitted the request.
5 . The computer-implemented method of claim 1 , wherein the policy defines a level of access to virtual machine images having the digital signature.
6 . The computer-implemented method of claim 1 , wherein the virtual machine image is stored in a manner that distinguishes the virtual machine image from other virtual machine images as a result of the virtual machine image having the digital signature and being verifiable to determine that the virtual machine image originates from the machine image provider.
7 . A computer system, comprising:
one or more processors; and memory having collectively stored therein instructions that, when executed by the computer system, cause the computer system to:
receive a request to launch a virtual machine that is based on a machine image digitally signed with a key of a vendor; and
launch the virtual machine after a determination that one or more policies authorize launching virtual machines that are based on machine images digitally signed by the vendor.
8 . The computer system of claim 7 , wherein the machine image digitally signed with the key of the vendor is verifiable using a public key obtained from a digital certificate issued by a certificate authority.
9 . The computer system of claim 7 , wherein the one or more policies further specify that only machine images digitally signed by the vendor can be utilized within a virtual network associated with a user, the user having submitted the request to launch the virtual machine.
10 . The computer system of claim 7 , wherein the one or more policies further define a level of access to the machine image for one or more users.
11 . The computer system of claim 7 , wherein the machine image digitally signed with the key of the vendor is made available in a manner such that the machine image digitally signed with the key of the vendor is verifiable to determine that the machine image digitally signed with the key of the vendor originates from the vendor.
12 . The computer system of claim 7 , wherein the machine image digitally signed with the key of the vendor is obtained from a computing resource service provider marketplace that is configured to enable a customer of the computing resource service provider to select the machine image digitally signed with the key of the vendor such that the machine image digitally signed with the key of the vendor can be used to instantiate the virtual machines for use by the customer.
13 . The computer system of claim 7 , wherein the machine image digitally signed with the key is made available in a manner distinguishing the machine image digitally signed with the key from other machine images based at least in part on whether the machine image digitally signed with the key is verifiable to determine that the machine image originates from the vendor.
14 . A non-transitory computer-readable storage medium having collectively stored thereon executable instructions that, when executed by one or more processors of a computer system, cause the computer system to at least:
store a machine image comprising one or more components signed with a key of a machine image provider; and as a result of a user having selected the machine image, determine, based at least in part on one or more policies that relate to launching virtual machines signed by the machine image provider, whether the user can utilize the machine image to instantiate a virtual machine.
15 . The non-transitory computer-readable storage medium of claim 14 , wherein the one or more components signed with the key are verifiable using a public key obtained from a digital certificate issued by a certificate authority.
16 . The non-transitory computer-readable storage medium of claim 14 , wherein the one or more policies further specify that only machine images comprising one or more components digitally signed by the machine image provider can be utilized within a virtual network of the user, the user having submitted a request to launch the virtual machine within the virtual network.
17 . The non-transitory computer-readable storage medium of claim 14 , wherein the one or more policies further define a level of access to the machine images signed by the machine image provider for one or more users.
18 . The non-transitory computer-readable storage medium of claim 14 , wherein the machine image is stored in a manner such that the one or more components signed with the key of the machine image provider are verifiable to determine that the machine image originates from the machine image provider.
19 . The non-transitory computer-readable storage medium of claim 14 , wherein the machine image is stored within a computing resource service provider marketplace that is configured to enable a customer of the computing resource service provider to select the machine image such that the machine image can be used to instantiate virtual machines for use by the customer.
20 . The non-transitory computer-readable storage medium of claim 14 , wherein the machine image is stored in a manner distinguishing the machine image from other machine images based at least in part on whether the one or more components of the machine image signed with the key of the machine image provider are verifiable to determine that the machine image originates from the machine image provider.Join the waitlist — get patent alerts
Track US2020326972A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.