Invention Grant
- Patent Title: Host attestation
-
Application No.: US16298867Application Date: 2019-03-11
-
Publication No.: US11036861B2Publication Date: 2021-06-15
- Inventor: Matthew John Campagna , Gregory Alan Rubin , Eric Jason Brandwine
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US WA Seattle
- Agency: Davis Wright Tremaine LLP
- Main IPC: G06F21/57
- IPC: G06F21/57 ; H04L29/06 ; H04L9/32 ; H04L9/08 ; G06F21/64 ; H04L9/14

Abstract:
A service provider provides virtual computing services using a fleet of one or more host computer systems. Each of the host computer systems may be equipped with a trusted platform module (“TPM”). The service provider, the host computer systems, and the virtual computing environments generate attestations that prove the integrity of the system. The attestations are signed with a one-time-use cryptographic key that is verifiable against the public keys of the service provider, a host computer system, and a virtual computing environment. The public key of the host computer system is integrated into a hash tree that links the public key of the host computer system to the public key of the service provider. The public key of the virtual computing environment is signed using a one-time-use graphic key issued to the host computer system that hosts the virtual computing environment.
Public/Granted literature
- US20190205540A1 HOST ATTESTATION Public/Granted day:2019-07-04
Information query