US2023176891A1PendingUtilityA1
Verified isolated run-time environments for enhanced security computations within compute instances
Est. expiryMar 28, 2039(~12.7 yrs left)· nominal 20-yr term from priority
G06F 2221/2149G06F 9/45558G06F 21/53G06F 2009/45587G06F 21/57
68
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
At a virtualization host, an isolated run-time environment is established within a compute instance. The configuration of the isolated run-time environment is analyzed by a security manager of the hypervisor of the host. After the analysis, computations are performed at the isolated run-time environment.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A computer-implemented method, comprising:
obtaining, at a cloud computing environment via one or more programmatic interfaces, an indication of (a) a software container image to be utilized to perform a trusted computation using a software enclave at a server of the cloud computing environment, and (b) a memory requirement of the software enclave; causing a first portion of memory of a particular server of the cloud computing environment to be configured for private use by the software enclave, wherein the size of the first portion of memory is based at least in part on the memory requirement, and wherein after the first portion of memory is configured for private use by the software enclave, data stored in the first portion of memory cannot be accessed from processes running with administrator privileges at the server; and causing the trusted computation to be performed using the first portion of memory and the software container image.
22 . The computer-implemented method as recited in claim 21 , further comprising:
providing, to a client of the cloud computing environment, a result of an attestation of software state of the software enclave.
23 . The computer-implemented method as recited in claim 21 , further comprising:
in response to determining that a software state of the software enclave satisfies a criterion, establishing a secure channel for communication between the software enclave and one or more client programs;.
24 . The computer-implemented method as recited in claim 21 , further comprising:
configuring the first portion of memory such that the data stored in the first portion of memory cannot be accessed from outside the software enclave.
25 . The computer-implemented method as recited in claim 21 , further comprising:
assigning, to a virtual machine launched at the particular server, a second portion of memory of the particular server prior to configuring the first portion of memory for private use by the software enclave, wherein the first portion of memory is a subset of the second portion.
26 . The computer-implemented method as recited in claim 21 , further comprising:
causing the software enclave to be migrated to another server, wherein at the other server, a size of a second portion of memory configured for private use by the software enclave differs from a size of the first portion.
27 . The computer-implemented method as recited in claim 21 , further comprising:
providing, via the one or more programmatic interfaces, one or more performance metrics collected from the software enclave.
28 . A system, comprising:
one or more computing devices; wherein the one or more computing devices include instructions that upon execution on or across the one or more computing devices:
obtain, at a cloud computing environment via one or more programmatic interfaces, an indication of (a) a software container image to be utilized to perform a trusted computation using a software enclave at a server of the cloud computing environment, and (b) a memory requirement of the software enclave;
cause a first portion of memory of a particular server of the cloud computing environment to be configured for private use by the software enclave, wherein the size of the first portion of memory is based at least in part on the memory requirement, and wherein after the first portion of memory is configured for private use by the software enclave, data stored in the first portion of memory cannot be accessed from processes running with administrator privileges at the server; and
cause the trusted computation to be performed using the first portion of memory and the software container image.
29 . The system as recited in claim 28 , wherein the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:
provide, to a client of the cloud computing environment, a result of an attestation of software state of the software enclave.
30 . The system as recited in claim 28 , wherein the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:
in response to determining that a software state of the software enclave satisfies a criterion, establish a secure channel for communication between the software enclave and one or more client programs;.
31 . The system as recited in claim 28 , wherein the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:
configure the first portion of memory such that the data stored in the first portion of memory cannot be accessed from outside the software enclave.
32 . The system as recited in claim 28 , wherein the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:
assign, to a virtual machine launched at the particular server, a second portion of memory of the particular server prior to configuring the first portion of memory for private use by the software enclave, wherein the first portion of memory is a subset of the second portion.
33 . The system as recited in claim 28 , wherein the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:
cause the software enclave to be migrated to another server, wherein at the other server, the size of a second portion of memory configured for private use by the software enclave differs from the size of the first portion.
34 . The system as recited in claim 28 , wherein the one or more computing devices include further instructions that upon execution on or across the one or more computing devices:
provide, via the one or more programmatic interfaces, one or more performance metrics collected from the software enclave.
35 . One or more non-transitory computer-accessible storage media storing program instructions that when executed on or across one or more processors:
obtain, at a cloud computing environment via one or more programmatic interfaces, an indication of (a) a software container image to be utilized to perform a trusted computation using a software enclave at a server of the cloud computing environment, and (b) a memory requirement of the software enclave; cause a first portion of memory of a particular server of the cloud computing environment to be configured for private use by the software enclave, wherein the size of the first portion of memory is based at least in part on the memory requirement, and wherein after the first portion of memory is configured for private use by the software enclave, data stored in the first portion of memory cannot be accessed from processes running with administrator privileges at the server; and cause the trusted computation to be performed using the first portion of memory and the software container image.
36 . The one or more non-transitory computer-accessible storage media as recited in claim 35 , storing further program instructions that when executed on or across one or more processors:
provide, to a client of the cloud computing environment, a result of an attestation of software state of the software enclave.
37 . The one or more non-transitory computer-accessible storage media as recited in claim 35 , storing further program instructions that when executed on or across one or more processors:
in response to determining that a software state of the software enclave satisfies a criterion, establish a secure channel for communication between the software enclave and one or more client programs;.
38 . The one or more non-transitory computer-accessible storage media as recited in claim 35 , storing further program instructions that when executed on or across one or more processors:
configure the first portion of memory such that the data stored in the first portion of memory cannot be accessed from outside the software enclave.
39 . The one or more non-transitory computer-accessible storage media as recited in claim 35 , storing further program instructions that when executed on or across one or more processors:
assign, to a virtual machine launched at the particular server, a second portion of memory of the particular server prior to configuring the first portion of memory for private use by the software enclave, wherein the first portion of memory is a subset of the second portion.
40 . The one or more non-transitory computer-accessible storage media as recited in claim 35 , storing further program instructions that when executed on or across one or more processors:
cause the software enclave to be migrated to another server, wherein at the other server, the size of a second portion of memory configured for private use by the software enclave differs from the size of the first portion.Join the waitlist — get patent alerts
Track US2023176891A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.