Invention Grant
- Patent Title: Network bound encryption for recovery of trusted execution environments
-
Application No.: US16918153Application Date: 2020-07-01
-
Publication No.: US11611431B2Publication Date: 2023-03-21
- Inventor: Michael Hingston McLaughlin Bursell , Nathaniel Philip McCallum
- Applicant: Red Hat, Inc.
- Applicant Address: US NC Raleigh
- Assignee: Red Hat, Inc.
- Current Assignee: Red Hat, Inc.
- Current Assignee Address: US NC Raleigh
- Agency: Lowenstein Sandler LLP
- Main IPC: H04L9/08
- IPC: H04L9/08 ; G06F21/54 ; G06F21/57

Abstract:
The technology disclosed herein provides network bound encryption that enables a trusted execution environment to persistently store and access recovery data without persistently storing the decryption key. An example method may include: establishing a trusted execution environment in a first computing device, the trusted execution environment comprising an encrypted memory area; loading cryptographic key data of a second computing device and executable code into the trusted execution environment; transmitting combined key data that is based on the cryptographic key data to a third computing device; deriving a cryptographic key from combined key data received from the third computing device, the received combined key data being based on the cryptographic key data of the second computing device and cryptographic key data of the third computing device; and causing the trusted execution environment to execute the executable code and use the cryptographic key to access sensitive data on a persistent storage device.
Public/Granted literature
- US20220006620A1 NETWORK BOUND ENCRYPTION FOR RECOVERY OF TRUSTED EXECUTION ENVIRONMENTS Public/Granted day:2022-01-06
Information query