Dynamic sharing in secure memory environments using edge service sidecars
Abstract
Various approaches for memory encryption management within an edge computing system are described. In an edge computing system deployment, a computing device includes capabilities to store and manage encrypted data in memory, through processing circuitry configured to: allocate memory encryption keys according to a data isolation policy for a microservice domain, with respective keys used for encryption of respective sets of data within the memory (e.g., among different tenants or tenant groups); and, share data associated with a first microservice to a second microservice of the domain. Such sharing may be based on the communication of an encryption key, used to encrypt the data in memory, from a proxy (such as a sidecar) associated with the first microservice to a proxy associated with the second microservice; and maintaining the encrypted data within the memory, for use with the second microservice, as accessible with the communicated encryption key.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . An edge computing system, comprising:
memory to store data; and circuitry to perform operations that:
allocate memory encryption keys according to a data isolation policy defined for a microservice domain, wherein respective entities of the microservice domain utilize respective keys of the allocated memory encryption keys to encrypt the data within the memory, and wherein seeds that are unique to the respective entities are used to generate the allocated memory encryption keys; and
share the data within the memory from a first entity of the microservice domain to a second entity of the microservice domain, based on operations that:
communicate an encryption key, used on the encrypted data stored at a location within the memory, from a proxy associated with the first entity to a proxy associated with the second entity; and
maintain the encrypted data at the location within the memory, wherein the second entity is enabled to use the encrypted data stored at the location in the memory based on the encryption key.
3 . The edge computing system of claim 2 , wherein the first entity is a first microservice associated with a first tenant and the second entity is a second microservice associated with a second tenant, and wherein the proxy associated with the first microservice is a first sidecar established for the first microservice and the proxy associated with the second microservice is a second sidecar established for the second microservice.
4 . The edge computing system of claim 3 , wherein the first sidecar and the second sidecar utilize key management functions and key management protocols, to conduct interactions that securely exchange other data between the first microservice and the second microservice.
5 . The edge computing system of claim 3 , wherein the data isolation policy is established based on tenant assignments determined by a hypervisor, wherein microservice entities and sidecar entities are operated in virtual machines managed by the hypervisor, and wherein the microservice domain includes: a first virtual machine for the first microservice, a second virtual machine for the second microservice, and the hypervisor.
6 . The edge computing system of claim 5 , wherein microservice, sidecar, and hypervisor entities associated with each tenant are allocated with respective memory encryption keys according to the data isolation policy, and wherein the respective memory encryption keys are established in the data isolation policy based on a definition of confidentiality or sharing among the microservice, sidecar, and hypervisor entities.
7 . The edge computing system of claim 2 , wherein the circuitry is implemented by a storage controller, wherein the encryption of respective sets of data within the memory is provided from multi-key memory encryption, and wherein at least one of the respective keys of the allocated memory encryption keys corresponds to a respective tenant in the edge computing system.
8 . The edge computing system of claim 2 , wherein each of the seeds is unique to a microservice, to a sidecar of the microservice, or to a tenant of the microservice, and wherein each of the seeds is based on a compound device identifier (CDI) generated according to a Device Identity Composition Engine (DICE) specification.
9 . The edge computing system of claim 2 , wherein the microservice domain is defined among entities of a service mesh, wherein the first entity is a member of a first cluster orchestrated by a first gateway, and wherein the second entity is a member of a second cluster orchestrated by a second gateway.
10 . The edge computing system of claim 2 , wherein the microservice domain is one of a plurality of domains operated in a service mesh associated with the edge computing system, and wherein the microservice domain applies different data isolation policies than other domains in the plurality of domains.
11 . At least one non-transitory machine-readable storage medium comprising instructions, wherein the instructions, when executed by a circuitry of a computing device in an edge computing system, cause the circuitry to perform operations that:
allocate memory encryption keys according to a data isolation policy defined for a microservice domain, wherein respective entities of the microservice domain utilize respective keys of the allocated memory encryption keys to encrypt data within a memory, and wherein seeds that are unique to the respective entities are used to generate the allocated memory encryption keys; and cause the data within the memory to be shared from a first entity of the microservice domain to a second entity of the microservice domain, based on operations that:
communicate an encryption key, used on the encrypted data stored at a location within the memory, from a proxy associated with the first entity to a proxy associated with the second entity; and
maintain the encrypted data at the location within the memory, wherein the second entity is enabled to use the encrypted data stored at the location in the memory based on the encryption key.
12 . The non-transitory machine-readable storage medium of claim 11 , wherein the first entity is a first microservice associated with a first tenant and the second entity is a second microservice associated with a second tenant, and wherein the proxy associated with the first microservice is a first sidecar established for the first microservice and the proxy associated with the second microservice is a second sidecar established for the second microservice.
13 . The non-transitory machine-readable storage medium of claim 12 , wherein the first sidecar and the second sidecar utilize key management functions and key management protocols, to conduct interactions that securely exchange other data between the first microservice and the second microservice.
14 . The non-transitory machine-readable storage medium of claim 12 , wherein the data isolation policy is established based on tenant assignments determined by a hypervisor, wherein microservice entities and sidecar entities are operated in virtual machines managed by the hypervisor, and wherein the microservice domain includes: a first virtual machine for the first microservice, a second virtual machine for the second microservice, and the hypervisor.
15 . The non-transitory machine-readable storage medium of claim 14 , wherein microservice, sidecar, and hypervisor entities associated with each tenant are allocated with respective memory encryption keys according to the data isolation policy, and wherein the respective memory encryption keys are established in the data isolation policy based on a definition of confidentiality or sharing among the microservice, sidecar, and hypervisor entities.
16 . The non-transitory machine-readable storage medium of claim 11 , wherein the encryption of respective sets of data within the memory is provided from multi-key memory encryption, and wherein at least one of the respective keys of the allocated memory encryption keys corresponds to a respective tenant in the edge computing system.
17 . The non-transitory machine-readable storage medium of claim 11 , wherein each of the seeds is unique to a microservice, to a sidecar of the microservice, or to a tenant of the microservice, and wherein each of the seeds is based on a compound device identifier (CDI) generated according to a Device Identity Composition Engine (DICE) specification.
18 . The non-transitory machine-readable storage medium of claim 11 , wherein the microservice domain is one of a plurality of domains, and wherein a domain controller authorizes interactions between the microservice domain and one or more other domains of the plurality of domains based on one or more shared encryption keys.
19 . A method performed by a computing device of an edge computing system, comprising:
allocating memory encryption keys according to a data isolation policy defined for a microservice domain, wherein respective entities of the microservice domain utilize respective keys of the allocated memory encryption keys to encrypt data within a memory device, and wherein seeds that are unique to the respective entities are used to generate the allocated memory encryption keys; and sharing the data within the memory device from a first entity of the microservice domain to a second entity of the microservice domain, by performing operations including:
communicating an encryption key, used on the encrypted data stored at a location within the memory device, from a proxy associated with the first entity to a proxy associated with the second entity; and
maintaining the encrypted data at the location within the memory device, wherein the second entity is enabled to use the encrypted data stored at the location in the memory device based on the encryption key.
20 . The method of claim 19 , wherein the first entity is a first microservice associated with a first tenant and the second entity is a second microservice associated with a second tenant, and wherein the proxy associated with the first microservice is a first sidecar established for the first microservice and the proxy associated with the second microservice is a second sidecar established for the second microservice.
21 . The method of claim 20 , wherein the first sidecar and the second sidecar utilize key management functions and key management protocols, to conduct interactions that securely exchange other data between the first microservice and the second microservice.
22 . The method of claim 20 , wherein the data isolation policy is established based on tenant assignments determined by a hypervisor, wherein microservice entities and sidecar entities are operated in virtual machines managed by the hypervisor, and wherein the microservice domain includes: a first virtual machine for the first microservice, a second virtual machine for the second microservice, and the hypervisor.
23 . The method of claim 22 , wherein microservice, sidecar, and hypervisor entities associated with each tenant are allocated with respective memory encryption keys according to the data isolation policy, and wherein the respective memory encryption keys are established in the data isolation policy based on a definition of confidentiality or sharing among the microservice, sidecar, and hypervisor entities.
24 . The method of claim 19 , wherein the encryption of respective sets of data within the memory device is provided from multi-key memory encryption, and wherein at least one of the respective keys of the allocated memory encryption keys corresponds to a respective tenant in the edge computing system.
25 . The method of claim 19 , wherein each of the seeds is unique to a microservice, to a sidecar of the microservice, or to a tenant of the microservice, and wherein each of the seeds is based on a compound device identifier (CDI) generated according to a Device Identity Composition Engine (DICE) specification.
26 . The method of claim 19 , wherein the microservice domain is one of a plurality of domains, and wherein a domain controller authorizes cross-domain interactions between the microservice domain and one or more other domains of the plurality of domains by sharing the encryption key.
27 . An apparatus, operable in an edge computing system, the apparatus comprising:
means for allocating memory encryption keys according to a data isolation policy defined for a microservice domain, wherein respective entities of the microservice domain utilize respective keys of the allocated memory encryption keys to encrypt data within a memory means; means for generating the allocated memory encryption keys, using seeds that are unique to the respective entities; and means for sharing data from a first entity of the microservice domain to a second entity of the microservice domain, the means for sharing data comprising:
means for communicating an encryption key, used on the encrypted data stored at a location within the memory means, from a proxy associated with the first entity to a proxy associated with the second entity; and
means for maintaining the encrypted data at the location within the memory means, wherein the second entity is enabled to use the encrypted data stored at the location in the memory means based on the encryption key.
28 . The apparatus of claim 27 , further comprising:
means for operating a plurality of sidecars and plurality of microservices, wherein the first entity is a first microservice associated with a first tenant and the second entity is a second microservice associated with a second tenant, and wherein the proxy associated with the first microservice is a first sidecar established for the first microservice and the proxy associated with the second microservice is a second sidecar established for the second microservice.
29 . The apparatus of claim 28 , further comprising:
means for implementing the encryption of respective sets of data within the memory means via multi-key memory encryption, and wherein at least one of the respective keys of the allocated memory encryption keys corresponds to a respective tenant in the edge computing system.Join the waitlist — get patent alerts
Track US2022239507A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.