Invention Grant
- Patent Title: Leveraging hardware-based attestation to grant workloads access to confidential data
-
Application No.: US17118978Application Date: 2020-12-11
-
Publication No.: US11886223B2Publication Date: 2024-01-30
- Inventor: Abhishek Srivastava , David Dunn , Jesse Pool , Adrian Drzewiecki
- Applicant: VMware LLC
- Applicant Address: US CA Palo Alto
- Assignee: VMware LLC
- Current Assignee: VMware LLC
- Current Assignee Address: US CA Palo Alto
- Agency: Quarles & Brady LLP
- Main IPC: G06F9/455
- IPC: G06F9/455 ; H04L9/32 ; H04L9/08 ; G06F21/62 ; G06F21/64 ; G06F21/33

Abstract:
In one set of embodiments, confidential data needed by a workload component running within a worker VM can be placed on an encrypted virtual disk that is attached to the worker VM and hardware-based attestation can be used to validate the worker VM's software and isolate its guest memory from its hypervisor. Upon successful completion of this attestation process, a data decryption key can be delivered to the worker VM via a secure channel established via the attestation, such that the hypervisor cannot read or alter the key. The worker VM can then decrypt the contents of the encrypted virtual disk using the data decryption key, thereby granting the workload component access to the confidential data.
Public/Granted literature
- US20220191025A1 Leveraging Hardware-Based Attestation to Grant Workloads Access to Confidential Data Public/Granted day:2022-06-16
Information query