Invention Grant
- Patent Title: Apparatus and method for efficient and secure process formation on secure runtime hardware resources
-
Application No.: US17189683Application Date: 2021-03-02
-
Publication No.: US11354450B1Publication Date: 2022-06-07
- Inventor: Yan Michalevsky , Boris Mittelberg , Thomas Aprelev
- Applicant: Anjuna Security, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: Anjuna Security, Inc.
- Current Assignee: Anjuna Security, Inc.
- Current Assignee Address: US CA Palo Alto
- Agency: Cooley LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/71 ; H04L9/08 ; G06F21/76

Abstract:
A non-transitory computer readable storage medium has instructions executed by a processor to define a parent application executing on a secure runtime hardware resource. A state snapshot of the secure runtime hardware resource is maintained. A fork request for a child application to be derived from the parent application is received. An updated state snapshot of the state snapshot is formed. The child application is instantiated. Encrypted state is transferred from the parent application to the child application. The encrypted state is used to derive an encryption key shared by the parent application and the child application. The encrypted state in the child application is decrypted using the encryption key to spawn an independent child application operative as an additional secure runtime instance. The parent application on the secure runtime hardware resource and the child application operative as the additional secure runtime instance are executed independently.
Information query