Invention Grant
- Patent Title: Chained security systems
-
Application No.: US14960553Application Date: 2015-12-07
-
Publication No.: US10169591B2Publication Date: 2019-01-01
- Inventor: Matthew John Campagna , Gregory Alan Rubin , Eric Jason Brandwine , Matthew Shawn Wilson , Cristian M. Ilac
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US WA Seattle
- Agency: Hogan Lovells US LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/60 ; G06F9/455 ; G06F21/57

Abstract:
A tiered credentialing approach provides assurance to customers having virtual machines running in a remote environment that the virtual images for these machines are in a pristine state and running in a trusted execution environment. The environment can be divided into multiple subsystems, each having its own cryptographic boundary, secure storage, and trusted computing capabilities. A trusted, limited subsystem can handle the administrative tasks for virtual machines running on the main system of a host computing device. The limited system can receive a certificate from a certificate authority, and can act as a certificate authority to provide credentials to the main system. Upon an attestation request, the subsystems can provide attestation information using the respective credentials as well as the certificate chain. An entity having the appropriate credentials can determine the state of the system from the response and verify the state is as expected.
Public/Granted literature
- US20170161505A1 CHAINED SECURITY SYSTEMS Public/Granted day:2017-06-08
Information query