Invention Grant
- Patent Title: Hypervisor level signature checks for encrypted trusted execution environments
-
Application No.: US17967152Application Date: 2022-10-17
-
Publication No.: US11977631B2Publication Date: 2024-05-07
- Inventor: Michael Tsirkin
- Applicant: Red Hat, Inc.
- Applicant Address: US NC Raleigh
- Assignee: Red Hat, Inc.
- Current Assignee: Red Hat, Inc.
- Current Assignee Address: US NC Raleigh
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F9/455 ; G06F21/56 ; G06F21/57 ; G06F21/60

Abstract:
A system includes a hypervisor, a memory, and boot firmware stored in the memory. The boot firmware is configured to execute on a processor to load a trusted code that includes a condition checker from the hypervisor, check a signature of the trusted code, and verify the signature is trusted by a guest. The boot firmware is also configured to load the trusted code into an encrypted memory at a known guest address. The hypervisor is configured to protect the known guest address. The trusted code includes a first instruction, one or more intermediate instructions, and a final instruction. The first instruction and the final instruction are exits to the hypervisor. The hypervisor is also configured to execute the condition checker and detect an inconsistency in guest memory.
Public/Granted literature
- US20230039602A1 HYPERVISOR LEVEL SIGNATURE CHECKS FOR ENCRYPTED TRUSTED EXECUTION ENVIRONMENTS Public/Granted day:2023-02-09
Information query