Invention Grant
- Patent Title: Restricting guest instances in a shared environment
-
Application No.: US15211277Application Date: 2016-07-15
-
Publication No.: US10237245B2Publication Date: 2019-03-19
- Inventor: Utz Bacher , Reinhard T. Buendgen , Heiko Carstens , Dominik Dingel
- Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Heslin Rothenberg Farley & Mesiti P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F9/455

Abstract:
A method includes a trusted component of a host computing system, obtaining, from a client, via a hypervisor of the host, a request to run an instance of a guest image within the hypervisor. The request includes a unique identifier of the guest image, contents of the guest image, and a communication key. The request is encrypted with a request key accessible to the owner and the trusted component and not accessible to the hypervisor. The trusted component generates an authorization request to an authorizing entity of the client requesting authorization for the hypervisor to run the instance. The authorization request includes the unique identifier, a use counter, and a unique challenge. The trusted component encrypts the authorization request with the communication key and communicates the authorization request to the authorizing entity, via the hypervisor.
Public/Granted literature
- US20180019979A1 RESTRICTING GUEST INSTANCES IN A SHARED ENVIRONMENT Public/Granted day:2018-01-18
Information query