Invention Grant
- Patent Title: Privileged cryptographic services in a virtualized environment
- Patent Title (中): 虚拟化环境中的特权加密服务
-
Application No.: US13746924Application Date: 2013-01-22
-
Publication No.: US09037854B2Publication Date: 2015-05-19
- Inventor: Gregory Branchek Roth , Nachiketh Rao Potlapally
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US NV Reno
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US NV Reno
- Agency: Hogan Lovells US LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/72

Abstract:
A privileged cryptographic service is described, such as a service running in system management mode (SMM). The privileged service is operable to store and manage cryptographic keys and/or other security resources in a multitenant remote program execution environment. The privileged service can receive requests to use the cryptographic keys and issue responses to these requests. In addition, the privileged service can measure the hypervisor at runtime (e.g., either periodically or in response to the requests) in an attempt to detect evidence of tampering with the hypervisor. Because the privileged service is operating in system management mode that is more privileged than the hypervisor, the privileged service can be robust against virtual machine escape and other hypervisor attacks.
Public/Granted literature
- US20140208123A1 PRIVILEGED CRYPTOGRAPHIC SERVICES IN A VIRTUALIZED ENVIRONMENT Public/Granted day:2014-07-24
Information query