US2022239507A1PendingUtilityA1

Dynamic sharing in secure memory environments using edge service sidecars

Assignee: INTEL CORPPriority: Sep 28, 2019Filed: Feb 10, 2022Published: Jul 28, 2022
Est. expirySep 28, 2039(~13.2 yrs left)· nominal 20-yr term from priority
G06F 16/1865H04L 43/08H04L 41/0893H04L 41/0896H04L 63/108H04L 41/0894H04L 41/0895G06F 9/5038G06F 9/5077G06F 9/5016G06F 9/4881G06F 9/3836H04L 9/3297G06F 11/1004G06F 16/2322G06F 9/45533G06F 12/1408G06F 9/544H04L 9/0822G06F 16/90339G06F 9/505H04L 67/10H04L 41/5009G06F 11/3058H04L 9/0825G06F 21/6209H04L 9/0894H04L 41/5051H04L 63/20H04L 67/12H04L 63/0428G06F 21/602H04L 47/822G06F 9/44594G06F 9/5072H04L 67/141H04L 67/125Y02D10/00H04L 9/0637G16Y 40/10H04L 63/0407G06F 2209/509H04L 41/145H04L 9/0866H04L 63/06H04L 9/008H04L 63/1408G06F 8/443H04L 67/1008H04L 41/5025H04L 67/60G06F 11/3433H04L 41/142H04L 67/565H04L 47/38H04L 47/225H04L 43/0852H04L 43/0876H04L 41/147H04W 4/70
76
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Various approaches for memory encryption management within an edge computing system are described. In an edge computing system deployment, a computing device includes capabilities to store and manage encrypted data in memory, through processing circuitry configured to: allocate memory encryption keys according to a data isolation policy for a microservice domain, with respective keys used for encryption of respective sets of data within the memory (e.g., among different tenants or tenant groups); and, share data associated with a first microservice to a second microservice of the domain. Such sharing may be based on the communication of an encryption key, used to encrypt the data in memory, from a proxy (such as a sidecar) associated with the first microservice to a proxy associated with the second microservice; and maintaining the encrypted data within the memory, for use with the second microservice, as accessible with the communicated encryption key.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . An edge computing system, comprising:
 memory to store data; and   circuitry to perform operations that:
 allocate memory encryption keys according to a data isolation policy defined for a microservice domain, wherein respective entities of the microservice domain utilize respective keys of the allocated memory encryption keys to encrypt the data within the memory, and wherein seeds that are unique to the respective entities are used to generate the allocated memory encryption keys; and 
 share the data within the memory from a first entity of the microservice domain to a second entity of the microservice domain, based on operations that:
 communicate an encryption key, used on the encrypted data stored at a location within the memory, from a proxy associated with the first entity to a proxy associated with the second entity; and 
 maintain the encrypted data at the location within the memory, wherein the second entity is enabled to use the encrypted data stored at the location in the memory based on the encryption key. 
 
   
     
     
         3 . The edge computing system of  claim 2 , wherein the first entity is a first microservice associated with a first tenant and the second entity is a second microservice associated with a second tenant, and wherein the proxy associated with the first microservice is a first sidecar established for the first microservice and the proxy associated with the second microservice is a second sidecar established for the second microservice. 
     
     
         4 . The edge computing system of  claim 3 , wherein the first sidecar and the second sidecar utilize key management functions and key management protocols, to conduct interactions that securely exchange other data between the first microservice and the second microservice. 
     
     
         5 . The edge computing system of  claim 3 , wherein the data isolation policy is established based on tenant assignments determined by a hypervisor, wherein microservice entities and sidecar entities are operated in virtual machines managed by the hypervisor, and wherein the microservice domain includes: a first virtual machine for the first microservice, a second virtual machine for the second microservice, and the hypervisor. 
     
     
         6 . The edge computing system of  claim 5 , wherein microservice, sidecar, and hypervisor entities associated with each tenant are allocated with respective memory encryption keys according to the data isolation policy, and wherein the respective memory encryption keys are established in the data isolation policy based on a definition of confidentiality or sharing among the microservice, sidecar, and hypervisor entities. 
     
     
         7 . The edge computing system of  claim 2 , wherein the circuitry is implemented by a storage controller, wherein the encryption of respective sets of data within the memory is provided from multi-key memory encryption, and wherein at least one of the respective keys of the allocated memory encryption keys corresponds to a respective tenant in the edge computing system. 
     
     
         8 . The edge computing system of  claim 2 , wherein each of the seeds is unique to a microservice, to a sidecar of the microservice, or to a tenant of the microservice, and wherein each of the seeds is based on a compound device identifier (CDI) generated according to a Device Identity Composition Engine (DICE) specification. 
     
     
         9 . The edge computing system of  claim 2 , wherein the microservice domain is defined among entities of a service mesh, wherein the first entity is a member of a first cluster orchestrated by a first gateway, and wherein the second entity is a member of a second cluster orchestrated by a second gateway. 
     
     
         10 . The edge computing system of  claim 2 , wherein the microservice domain is one of a plurality of domains operated in a service mesh associated with the edge computing system, and wherein the microservice domain applies different data isolation policies than other domains in the plurality of domains. 
     
     
         11 . At least one non-transitory machine-readable storage medium comprising instructions, wherein the instructions, when executed by a circuitry of a computing device in an edge computing system, cause the circuitry to perform operations that:
 allocate memory encryption keys according to a data isolation policy defined for a microservice domain, wherein respective entities of the microservice domain utilize respective keys of the allocated memory encryption keys to encrypt data within a memory, and wherein seeds that are unique to the respective entities are used to generate the allocated memory encryption keys; and   cause the data within the memory to be shared from a first entity of the microservice domain to a second entity of the microservice domain, based on operations that:
 communicate an encryption key, used on the encrypted data stored at a location within the memory, from a proxy associated with the first entity to a proxy associated with the second entity; and 
 maintain the encrypted data at the location within the memory, wherein the second entity is enabled to use the encrypted data stored at the location in the memory based on the encryption key. 
   
     
     
         12 . The non-transitory machine-readable storage medium of  claim 11 , wherein the first entity is a first microservice associated with a first tenant and the second entity is a second microservice associated with a second tenant, and wherein the proxy associated with the first microservice is a first sidecar established for the first microservice and the proxy associated with the second microservice is a second sidecar established for the second microservice. 
     
     
         13 . The non-transitory machine-readable storage medium of  claim 12 , wherein the first sidecar and the second sidecar utilize key management functions and key management protocols, to conduct interactions that securely exchange other data between the first microservice and the second microservice. 
     
     
         14 . The non-transitory machine-readable storage medium of  claim 12 , wherein the data isolation policy is established based on tenant assignments determined by a hypervisor, wherein microservice entities and sidecar entities are operated in virtual machines managed by the hypervisor, and wherein the microservice domain includes: a first virtual machine for the first microservice, a second virtual machine for the second microservice, and the hypervisor. 
     
     
         15 . The non-transitory machine-readable storage medium of  claim 14 , wherein microservice, sidecar, and hypervisor entities associated with each tenant are allocated with respective memory encryption keys according to the data isolation policy, and wherein the respective memory encryption keys are established in the data isolation policy based on a definition of confidentiality or sharing among the microservice, sidecar, and hypervisor entities. 
     
     
         16 . The non-transitory machine-readable storage medium of  claim 11 , wherein the encryption of respective sets of data within the memory is provided from multi-key memory encryption, and wherein at least one of the respective keys of the allocated memory encryption keys corresponds to a respective tenant in the edge computing system. 
     
     
         17 . The non-transitory machine-readable storage medium of  claim 11 , wherein each of the seeds is unique to a microservice, to a sidecar of the microservice, or to a tenant of the microservice, and wherein each of the seeds is based on a compound device identifier (CDI) generated according to a Device Identity Composition Engine (DICE) specification. 
     
     
         18 . The non-transitory machine-readable storage medium of  claim 11 , wherein the microservice domain is one of a plurality of domains, and wherein a domain controller authorizes interactions between the microservice domain and one or more other domains of the plurality of domains based on one or more shared encryption keys. 
     
     
         19 . A method performed by a computing device of an edge computing system, comprising:
 allocating memory encryption keys according to a data isolation policy defined for a microservice domain, wherein respective entities of the microservice domain utilize respective keys of the allocated memory encryption keys to encrypt data within a memory device, and wherein seeds that are unique to the respective entities are used to generate the allocated memory encryption keys; and   sharing the data within the memory device from a first entity of the microservice domain to a second entity of the microservice domain, by performing operations including:
 communicating an encryption key, used on the encrypted data stored at a location within the memory device, from a proxy associated with the first entity to a proxy associated with the second entity; and 
 maintaining the encrypted data at the location within the memory device, wherein the second entity is enabled to use the encrypted data stored at the location in the memory device based on the encryption key. 
   
     
     
         20 . The method of  claim 19 , wherein the first entity is a first microservice associated with a first tenant and the second entity is a second microservice associated with a second tenant, and wherein the proxy associated with the first microservice is a first sidecar established for the first microservice and the proxy associated with the second microservice is a second sidecar established for the second microservice. 
     
     
         21 . The method of  claim 20 , wherein the first sidecar and the second sidecar utilize key management functions and key management protocols, to conduct interactions that securely exchange other data between the first microservice and the second microservice. 
     
     
         22 . The method of  claim 20 , wherein the data isolation policy is established based on tenant assignments determined by a hypervisor, wherein microservice entities and sidecar entities are operated in virtual machines managed by the hypervisor, and wherein the microservice domain includes: a first virtual machine for the first microservice, a second virtual machine for the second microservice, and the hypervisor. 
     
     
         23 . The method of  claim 22 , wherein microservice, sidecar, and hypervisor entities associated with each tenant are allocated with respective memory encryption keys according to the data isolation policy, and wherein the respective memory encryption keys are established in the data isolation policy based on a definition of confidentiality or sharing among the microservice, sidecar, and hypervisor entities. 
     
     
         24 . The method of  claim 19 , wherein the encryption of respective sets of data within the memory device is provided from multi-key memory encryption, and wherein at least one of the respective keys of the allocated memory encryption keys corresponds to a respective tenant in the edge computing system. 
     
     
         25 . The method of  claim 19 , wherein each of the seeds is unique to a microservice, to a sidecar of the microservice, or to a tenant of the microservice, and wherein each of the seeds is based on a compound device identifier (CDI) generated according to a Device Identity Composition Engine (DICE) specification. 
     
     
         26 . The method of  claim 19 , wherein the microservice domain is one of a plurality of domains, and wherein a domain controller authorizes cross-domain interactions between the microservice domain and one or more other domains of the plurality of domains by sharing the encryption key. 
     
     
         27 . An apparatus, operable in an edge computing system, the apparatus comprising:
 means for allocating memory encryption keys according to a data isolation policy defined for a microservice domain, wherein respective entities of the microservice domain utilize respective keys of the allocated memory encryption keys to encrypt data within a memory means;   means for generating the allocated memory encryption keys, using seeds that are unique to the respective entities; and   means for sharing data from a first entity of the microservice domain to a second entity of the microservice domain, the means for sharing data comprising:
 means for communicating an encryption key, used on the encrypted data stored at a location within the memory means, from a proxy associated with the first entity to a proxy associated with the second entity; and 
 means for maintaining the encrypted data at the location within the memory means, wherein the second entity is enabled to use the encrypted data stored at the location in the memory means based on the encryption key. 
   
     
     
         28 . The apparatus of  claim 27 , further comprising:
 means for operating a plurality of sidecars and plurality of microservices, wherein the first entity is a first microservice associated with a first tenant and the second entity is a second microservice associated with a second tenant, and wherein the proxy associated with the first microservice is a first sidecar established for the first microservice and the proxy associated with the second microservice is a second sidecar established for the second microservice.   
     
     
         29 . The apparatus of  claim 28 , further comprising:
 means for implementing the encryption of respective sets of data within the memory means via multi-key memory encryption, and wherein at least one of the respective keys of the allocated memory encryption keys corresponds to a respective tenant in the edge computing system.

Join the waitlist — get patent alerts

Track US2022239507A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.