Method and apparatus for protecting computing data in a computing environment

By configuring isolated memory areas in a computing environment and using secure hardware abstractions, using signed data and key exchange protocols, the problem of computing data protection in the prior art is solved, and data efficiency and security protection is achieved.

CN112948871BActive Publication Date: 2025-06-13MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110453686.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2015-09-25
Filing Date
2016-07-15
Publication Date
2025-06-13
Estimated Expiration
2036-07-15

AI Technical Summary

Technical Problem

In computing environments, prior art is difficult to effectively protect computing data, especially when facing complex security threats and attack opportunities provided by code partitioning schemes.

Method used

By configuring isolated memory areas in a computing environment, secure computing is provided using secure hardware abstractions, verifying the trustworthiness of code packets with signed data, and establishing a secure communication channel through a key exchange protocol.

Benefits of technology

Effective protection of computed data is achieved, the confidentiality and integrity of the data is ensured, and even when privileged software is compromised, it can prevent attackers from accessing data and code in isolated memory areas.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112948871B_ABST
    Figure CN112948871B_ABST
Patent Text Reader

Abstract

The present disclosure relates to techniques for protecting computing data in a computing environment. These techniques relate to an isolated environment within the computing environment and an application programming interface (API) component for performing a key exchange protocol that ensures data integrity and data confidentiality of data communicated from the isolated environment. The isolated environment includes an isolated memory region for storing a code package. The key exchange protocol also relates to a verification process for the code package stored in the isolated environment to determine whether one or more of the exchanged encryption keys have been compromised. If the signature successfully authenticates one or more keys, a secure communication channel to the isolated environment is established and access to the functionality of the code package is enabled. Other embodiments are described and claimed.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of a patent application for an invention titled "Techniques for Protecting Computation Data in a Computing Environment", with an international filing date of July 15, 2016, entering the Chinese national phase on January 29, 2018, and a Chinese national application number of 201680044488.5. Technical Field

[0002] The present disclosure relates to the field of information technology. More specifically, the present disclosure relates to techniques for protecting computation data in a computing environment. Background Art

[0003] For developers (e.g., software application developers), it has become increasingly important to ensure the confidentiality and integrity of the data they use, especially when their programs involve sensitive data. Complex security threats have caused governments and private organizations to spend a large amount of money due to delays and expenditures for preventing / mitigating these threats. As these organizations move towards using cloud-based services over the network rather than maintaining on-premises hardware, attackers have more opportunities to exploit software vulnerabilities and endanger the security of other organizations. Due to the hierarchical privilege structure of cloud computing environments, programs running on such computing bases may inherit software vulnerabilities from privileged software code, such as operating system components or hypervisor components.

[0004] Various code partitioning schemes provide a significant number of opportunities for malicious attacks and reduce the benefits and practicality of executing these parts in separate execution environments with different privilege levels. A large amount of trusted code also inhibits any meaningful checks for correctness. Furthermore, code partitioning schemes typically require substantially manual tasks, which have proven to be error-prone and slow.

[0005] In view of these and other considerations, current improvements are needed. Summary of the Invention

[0006] The following presents a simplified summary of the invention in order to provide a basic understanding of some of the novel embodiments described herein. This summary of the invention is not an extensive overview nor is it intended to identify key / important elements or delineate its scope. Its sole purpose is to present some concepts in a simplified form as a prelude to the detailed description that follows.

[0007] Various embodiments generally relate to techniques for providing secure computing in a computing environment via secure hardware abstraction. As described herein, the computing environment is controlled by a secure computing provider and can refer to a cloud-based environment or an on-premises (e.g., local) computing environment. The secure computing provider typically includes suitable secure hardware components, such as a secure processor. In an isolated memory region of the computing environment, a code package that is agnostic to the secure hardware and operates with any secure computing provider can be stored. According to various embodiments described herein, techniques for using signed data to verify the code package as trusted code and authenticate that message data originated from the isolated memory region enable secure computing by different providers. The message data generated by the code package can be used to share secrets between trusted code in the isolated memory region and trusted code remotely stored in a remote machine using various mechanisms, such as those described herein and those also encompassing those with similar characteristics).

[0008] Some embodiments specifically relate to techniques for enabling access to a code package stored in an isolated memory region. The code package can implement functionality that is configured to perform a set of computations on data stored in an external storage device. Providing secure computing for the code package involves isolating some or all of the data and code of the package from untrusted code components (e.g., privileged software, such as operating system components or hypervisor components) while maintaining a primitive programming model for communicating between the isolated memory region and the untrusted code components. Generally, the primitive programming model is an abstraction of the underlying (secure) hardware that still provides secure computing for the stored data. Secure computing can be enhanced by establishing one or more secure communication channels between the isolated code package and one or more remote trusted components running on a remote machine. Since the isolated code package operates independently of the underlying hardware, software, and / or firmware, the various embodiments described herein can be implemented in any hardware configuration.

[0009] In one embodiment, for example, an apparatus can include logic that operates on a logic circuit to configure an isolated memory region in a computing environment for secure communication with code running outside the isolated memory region; generate signed data using an attestation key corresponding to the computing environment, the signed data including a protected encryption key and a signature for authenticating the protected encryption key; and communicate the signed data to a remote trusted component to access a secret code stored in the isolated memory region. Other embodiments are described and claimed.

[0010] To achieve the foregoing and related purposes, certain illustrative aspects are described herein in connection with the following description and the accompanying drawings. These aspects indicate various ways in which the principles disclosed herein may be practiced, and all aspects and equivalents thereof are intended to be within the scope of the claimed subject matter. Other advantages and novel features will become apparent from the following detailed description when considered in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 An embodiment of a system for protecting computing data in a computing environment is illustrated.

[0012] Figure 2 An embodiment of an operating environment for a trusted component is illustrated.

[0013] Figure 3 An embodiment of an operating environment for a trusted component having a support region is illustrated.

[0014] Figure 4 An embodiment of a key exchange protocol between a trusted component and a remote trusted component is illustrated.

[0015] Figure 5 An embodiment of a secure communication channel between a trusted component and a remote trusted component is illustrated.

[0016] Figure 6 An embodiment of an isolation environment for trusted code in an isolated memory region is illustrated.

[0017] Figure 7 An embodiment of a system for a secure computing provider is illustrated.

[0018] Figure 8 An embodiment of a centralized system for a Figure 1 system is illustrated.

[0019] Figure 9 An embodiment of a logical flow for a Figure 1 system is illustrated.

[0020] Figure 10 An embodiment of a logical flow for a Figure 5 trusted component is illustrated.

[0021] Figure 11 An embodiment of a logical flow for a Figure 4 remote trusted component is illustrated.

[0022] Figure 12 An embodiment of a computing architecture is illustrated.

[0023] Figure 13 An embodiment of a communication architecture is illustrated. DETAILED DESCRIPTION

[0024]

[0024] Various embodiments are directed to an application programming interface (API) component in a computing environment that operates to isolate trusted code from untrusted code in the computing environment and to protect data generated by the trusted code when such data is being processed by the untrusted code. Generally, the API component provides a secure hardware abstraction layer by implementing a primitive programming model through which the untrusted code and the trusted code establish a secure connection or communication channel. Both the untrusted code and the trusted code can use the primitive functions of the primitive programming model to generate and manage an isolated environment. Via the primitive programming model, the trusted code implements an encryption protocol for protecting network data communication between the isolated environment and the untrusted code.

[0025]

[0025] As described herein, the isolated environment can include various computer codes and data stored in an isolated memory region of the memory of the computing device. In some embodiments, the primitive programming model of the API component is used by the untrusted code to configure the isolated memory region that has a secure communication channel to code that can execute in a memory region different from the isolated memory region, the code including a privileged code component running outside of the isolated memory region. Among other things, the primitive programming model can enable secure conveyance of data to the untrusted code for processing by one of the functions of the untrusted code, for storage in an external storage device, and / or for transmission over a network to a remote machine. The primitive programming model implemented by the API component can also implement additional management functions such as file system operations, threading, synchronization, memory allocation, and / or similar functions. In some embodiments, the computed data is conveyed to the remote machine along with a signature (or another authentication code) and protected with an encryption key generated through the primitive programming model. The signature ensures the integrity of the encryption key and authenticates to the remote machine that the computer code in the isolated memory region has not been compromised or corrupted.

[0026]

[0026] An application development framework (e.g., Secure Hadoop) partitions its data and code such that a portion is isolated from privileged software (e.g., an operating system) but needs to be compatible with the underlying hardware within the computing environment. The primitive programming model of the API component provides interoperability with any underlying hardware. In some embodiments, the API component implements functions that generate communication primitives to securely convey data. Although some of these communication primitives can include or be similar to primitives of known inter-process communication, the embodiments contemplated by the present disclosure are not limited to any particular construct. The API component implements a minimal number of functions to achieve secure computing and secure communication while restricting access to the isolated memory region to the code within that region. Thus, even if the privileged software is compromised or manipulated by a malicious administrator, an attacker cannot access the data and code in the isolated memory region.

[0027] Accordingly, embodiments can improve affordability, scalability, modularity, extensibility, or interoperability for an operator, a device, or a network.

[0028] We describe how untrusted code in the cloud can create an isolated region using some code provided by a user, and how trusted code inside the isolated region can communicate with code outside. We also describe how trusted code in a remote machine can establish a secure channel with trusted code inside the isolated region.

[0029] Generally referring to the symbols and terms used herein, the following detailed description may be presented according to a program flow executed on a computer or a computer network. Those skilled in the art use these flow descriptions and representations to most effectively convey the essence of their work to other technicians in the field.

[0030] A process is generally conceived herein as a self-consistent sequence of operations leading to a desired result. These operations are those that require physical manipulation of physical quantities. Usually, but not necessarily, these quantities take the form of electrical, magnetic, or optical signals capable of being stored, transmitted, combined, compared, and otherwise manipulated. Mainly due to convention, it is sometimes convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc. However, it should be noted that all these and similar terms are to be associated with appropriate physical quantities and are merely convenient labels applied to those quantities.

[0031] Furthermore, the manipulations performed are often referred to in terms that are usually associated with mental operations performed by a human operator, such as adding or comparing. In most cases, in any of the operations forming part of one or more embodiments described herein, this ability of a human operator is not required or desired. Instead, these operations are machine operations. Useful machines for performing the operations of the various embodiments include general-purpose digital computers or similar devices.

[0032] The various embodiments also relate to apparatus or systems for performing these operations. The device may be specially constructed for the required purpose or may include a general-purpose computer selectively activated or reconfigured by a computer program stored in the computer. The processes presented herein are not inherently related to a particular computer or other device. Various general-purpose machines may be used with programs written in accordance with the teachings herein, or it may prove convenient to construct more specialized apparatus to perform the required method steps. The required structure for a variety of these machines can be seen from the description given.

[0033] Reference is now made to the accompanying drawings, in which like reference numerals are always used to refer to like elements. In the following description, numerous specific details are set forth for purposes of explanation in order to provide a thorough understanding thereof. It is evident, however, that novel embodiments may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form in order to facilitate their description. The intention is to cover all modifications, equivalents, and alternatives consistent with the claimed subject matter.

[0034] Figure 1 A block diagram is illustrated for system 100. In one embodiment, system 100 may include a computer-implemented system 100 having a secure computing provider 120 and one or more components 122-a. Although Figure 1 system 100 as shown in has a finite number of elements in a particular topology, it will be appreciated that system 100 may include more or fewer elements in alternative topologies depending on the needs for a given implementation.

[0035] It is worth noting that as used herein, "a" and "b" and "c" and similar identifiers are variables intended to represent any positive integer. Thus, for example, if an implementation sets a value of a = 5, the complete set of components 122-a may include components 122-1, 122-2, 122-3, and 122-4. The embodiments are not limited in this context.

[0036] System 100 may include a secure computing provider 120 that controls the computing environment. The secure computing provider 120 may generally be arranged to provide computing services to a number of computing devices operating locally or remotely. An example of a computing environment includes a configuration of processing resources and storage resources in the form of virtual machines running various applications. One physical computer may be abstracted into several virtual machines, and alternatively, two or more physical computing devices may allocate processing power and / or storage space to execution processing jobs on a computing framework, e.g., a large set of parallel computations on large data sets.

[0037] The various embodiments described herein refer to an application design interface (API) component 122-1 that operates to generate a primitive programming service including a number of primitive functions. The primitive functions may represent the minimum number of primitives that are suitable for supporting different secure computing providers and facilitating interaction with the functionality of each provider. The API component 122-1 may further operate to provide access to the primitive programming service, e.g., access to a trusted code component within an isolated memory region 122-2. Via the API component 122-1, trusted code running within the isolated memory region 122-2 may perform a key exchange protocol with a remote trusted component running on a remote machine.

[0038] A feature of the key exchange protocol is the proof key 122-3, which is private to the secure computing provider 120 and is used to authenticate data communicated from the isolated memory region 122-2. The proof key 122-3 can specifically correspond to the secure computing provider 120; thus, using this key to generate a digital signature for some data ensures the integrity of the data when it is communicated from the computing environment controlled by the secure computing provider 120. This data can be verified using the public key corresponding to the proof key 122-3. Since the remote trusted component can confirm the authenticity of the data, the secure computing provider 120 can ensure that the data has not been compromised when it is outside the isolated memory region 122-2.

[0039] The combination of the digital signature from the proof key 122-3 and the protected encryption key from the API component 122-1 provides additional data confidentiality and integrity for the data communicated between the isolated memory region 122-2 and any trusted component outside of this region. In an embodiment where the trusted component includes remotely stored code, since the protected encryption key is encrypted by a scheme known to the code, the encryption key is less likely to be compromised. Thus, the remotely stored code can ensure secure communication with the isolated memory region 122-2.

[0040] According to one embodiment, the untrusted code 122-4 is executed in a memory region outside the isolated memory region 122-2 and communicates with this region through the API component 122-1. Once the key exchange protocol is successfully completed, the application code can, for example, run a set of computations on the stored data in parallel with other trusted components. The application code running in the isolated memory region can use I / O control code to instruct the untrusted code 122-4 to perform various computational tasks. Thus, the API component 122-1 provides secure communication between the code running in the isolated memory region 122-2 and the components running in the memory region outside the isolated memory region 122-2. These components can include remotely stored code on a remote machine or the untrusted code 122-4.

[0041] The untrusted code 122-4 can create an isolated environment within the memory and configure this isolated environment with computer code and / or data. By way of example, the API component 122-1 implements the following function IsolatedRegionCreate(), which when called, creates an isolated environment and loads the computer code package specified by the packagePath argument into this environment:

[0042] In the above example, isolationProvider identifies the underlying provider of the secure computing service, e.g., VSM. The packagePath argument may refer to file data in a global or cloud file system rather than a local file system. The callOutHandler identifies a function in the untrusted code that can process IO control codes sent from inside the enclave. The package is a container for code (e.g., trusted application code) and data. An example package is a mobile application package that can be downloaded from a mobile application platform. The package also includes configuration parameters such as the size of the enclave.

[0043] The untrusted code 122-4 can call code in the isolated memory enclave 122-2. One way to achieve this is to send input / output (IO) control codes (e.g., IOCTL codes) to the isolated memory enclave 122-2:

[0044]

[0045] The enclave argument defines the address or location of the isolated memory enclave 122-2. The callInID argument identifies a function in the isolated memory enclave 122-2 that is configured to process control codes (or other communication primitives) from the untrusted code 122-4. The callInID argument can be provided by information attached to the code package. The inputBuffer argument and the outputBuffer argument are memory buffers that store the control code and the return result, respectively. Finally, the untrusted code 122-4 can destroy the isolated memory enclave by calling, for example, the following function: VOID IsolatedRegionClose(_In_HANDLE region)

[0046] As noted herein, the functionality implemented by the API component 122-1 can be extended to perform additional tasks such as memory management functions. As an example, VirtualAlloc() and VirtualFree() can be implemented inside the isolated memory enclave 122-2 to dynamically allocate / free virtual memory.

[0047] Figure 2 An embodiment of an operating environment 200 for the system 100 is illustrated. As Figure 2 shown, the API component 122-1 receives control instructions such as communication primitives from the trusted code 202 running inside the isolated memory enclave 122-2. Some control instructions direct the API component 122-1 to convey the signed data 214 to a remote machine. The remote trusted component 206 running on the remote machine can perform a verification process on the signed data 122-3 to determine whether such data has been compromised and / or protect the remote machine from malicious activities.

[0048] According to one example embodiment, the trusted code 202 and the remote trusted component 206 participate in a key exchange protocol through which one or more encryption keys are securely communicated via untrusted code. One example implementation of the trusted code 202 calls a communication primitive via a function call to instruct the API component 122-1 to generate an encryption key. The trusted code 202 protects the encryption key, for example, by encrypting the encryption key using the public key of the remote trusted component 206. The trusted code 202 calls another primitive function to request a signature for the protected encryption key, which is then stored in the signed data 214. It should be appreciated that many alternative key exchange protocols may be implemented. For example, as an alternative, the trusted code 202 may use another encryption scheme.

[0049] In one embodiment, the remote trusted component 206 encrypts code (e.g., a function library) and data and binds them into a code package 208. The encryption key used to generate the encrypted code package 208 is referred to as the user key 210. A part of the code package 208 may be public code and may be stored in the trusted code 202. Another part may include support code files and may also be stored in the trusted code. Another part may be kept secure as the secret code 212 in the isolated memory area 122-2 until a secure communication channel is established. In some embodiments, the code package 208 includes metadata for identifying one or more functions that process communication primitives (e.g., I / O code) from code executing in a memory area other than the isolated memory area 122-2. Each function definition in the metadata may implement instant communication and control the application functionality for untrusted code.

[0050] In one embodiment, the remote trusted component 206 uses an encryption key to protect the user key 210, which is the encryption key that initially encrypts the secret code 212 before transferring the secret code 212 to the isolated memory area 122-2. As described herein with respect to Figure 1 The secret code 212 may form part of a computer code package 208, which may be placed in the isolated memory area 122-2 to perform secure computations on data stored in an external storage device. According to one embodiment, the secret code 212 includes parallel processing jobs (e.g., map functions and reduce functions) to be performed on a substantial data set for a significant number of client computing devices.

[0051] Trusted code 202 receives user key 210 and decrypts secret code 212 to access parallel processing job information that defines a set of computations to be performed on stored data. Secret code 212 distributes the parallel processing job across one or more resources within isolated memory region 122-2 to generate computed data, which is protected using an encryption key generated during a key exchange protocol. Trusted code 202 requests a signature for the protected computed data, and both the signature and the protected computed data are communicated as signed data 214 to remote trusted component 206. Using one or more communication primitives (e.g., I / O control codes), trusted code 202 generates a message to store signed data 214 and writes the message to a memory buffer for communication to API component 122-1. It should be appreciated that the message content can be used to establish shared secret data between trusted code 202 and remote trusted component 206 in various ways (e.g., Diffie-Hellman key exchange). The embodiments described herein support several secure channel establishment mechanisms among these secure channel establishment mechanisms and provide a mechanism for selecting a particular mechanism.

[0052] Remote trusted component 206 in turn uses API component 122-1 to verify the integrity and confidentiality of the message content. One example implementation determines whether the signature is generated by a private proof key corresponding to a secure computing provider 120 of the computing environment (e.g., as opposed to a malicious provider), and whether the message content is generated by trusted code 202. Another example implementation determines whether the protected computed data is generated by secret code 212 (e.g., as opposed to a compromised code package). Using one or more communication primitives (e.g., I / O control codes), trusted code 202 writes and / or reads signed data 214 to / from a memory buffer, which is communicated to API component 122-1.

[0053] Signed data 214 can include a signature or another authentication code generated by a proof key of the secure computing provider. In some embodiments, the key can be a private key under a public key cryptography scheme and specifically corresponds to an associated secure computing provider. In some embodiments, the signed data further includes an encryption key unknown to untrusted code components operating at the secure computing provider. Because the encryption key is protected from untrusted components, the key can be communicated to code running outside the isolated memory region without being compromised. If the code runs on a remote computer, the code can verify the key by checking the signature to determine whether the key is compromised when outside the isolated memory region. Thus, signed data 214 verifies the integrity and confidentiality of the key to the system of the remote machine.

[0054] Figure 3An embodiment of an operating environment 300 is illustrated that has a support region for supporting component 304 and isolates memory region 122-2. In this embodiment, trusted code 202 operates with support component 304 to enable secure computing for data stored in an external storage device.

[0055] For illustration by example, a secure computing provider 120 may operate a cloud computing environment where each machine creates a support region 302 in memory that is isolated from untrusted code running elsewhere on the machine. For example, using API component 122-1, untrusted code may create support region 302 with IsolatedRegionCreate() and load the region with support component 304. Support component 304 implements one or more administrative functions that allow a remote trusted component 206 to securely send private computer code to the cloud computing environment for storage in isolated memory region 122-2. The code for implementing support component 304 is unimportant and may be public.

[0056] As described herein, untrusted code invokes functions in support component 304 via an IsolatedRegionIOControl() function call. Support component 304 generates a public-private key pair according to an encryption scheme unknown to another code component. This public-private encryption key pair may be specific to the processing resources that have been allocated to isolated memory region 122-2. Support component 304 invokes primitive functions on API component 122-1 to generate a sealed key for encrypting the private key. Support component 304 invokes another primitive function to generate a signature for the public key. Using the signature and the protected private encryption key, support component 304 participates in a key exchange protocol with a remote machine.

[0057] For illustration by example, consider that isolated memory region 122-2 is depicted in Figure 3 as having a secret code 212, which is protected computer code for performing a set of calculations on stored data. Functions within secret code 212 may be encrypted with a secret key known to remote trusted component 206. After API component 122-1 verifies the evidence of the public key mentioned above, remote trusted component 206 encrypts the secret key for secret code 212 using the public key. Thus, this secret key may be referred to as a user key, which is similar to Figure 2 user key 208.

[0058] To protect the communication between the support area 302 and the isolated memory area 122-2 (in this example, the support component 304 is configured as code that runs outside the isolated memory area 122-2), the support component 304 and the trusted code 202 initiate a key exchange protocol so that the trusted code 202 receives the secret key for decrypting the secret code 212, and the support component 304 receives the private key for protecting the secret key and potentially other future communications. Once decrypted, the functions of the secret code 212 are incorporated into the trusted code 202, and the private key can be used by those functions to protect data written to or read from the untrusted code (e.g., encrypted value pairs).

[0059] Figure 4 An embodiment of a key exchange protocol 400 between the trusted code 202 and the remote trusted component 206 is illustrated.

[0060] As described herein, the untrusted code running in the computing environment 120 calls a function on the API component 122-1 to create an isolated memory area and load computer code into that area. Executing the computer code generates the trusted code 202 and initiates the key exchange protocol 400. One example implementation of the API component 122-1 loads the package into the isolated memory area and sends the public key for the remote trusted component to the trusted code 202. The API component 122-1 can store the public key in the memory buffer of the message that is communicated to the trusted code 202 to initiate the setup process 402. The public key can be specific to a particular remote machine. The message also includes configuration parameters such as the size of the area.

[0061] To start the setup process 402, the trusted code 202 can call the primitive function 404 call, and in response, the API component 122-1 generates and returns an encryption key to protect the communication between the trusted code 202 and the remote trusted component. These keys allow the trusted code to encrypt data, save it in an external storage device, and then decrypt it during subsequent execution.

[0062] In the following example implementation of the primitive function 404, a function call to IsolatedAppGetKey requests a key corresponding to the KeyID, with parameters keyBufferBytesRequired and keyBufferBytes in the buffer keyBuffer:

[0063]

[0064] In another operation, the trusted code 202 can protect the encryption key with a public key and call the primitive function 406, and in response, the API component 122 generates and returns a digital signature of the protected encryption key. In yet another operation, the trusted code 202 can call the primitive function 408 to write the digital signature and the protected encryption key into a memory buffer, and convey a message to the API component 122-1. In response, the API component 122-1 sends the message to the remote trusted component 206.

[0065] In the following example implementation of the primitive function 404, the function call to IsolatedAppSignMessage instructs the API component to generate a digital signature for the message content and store the digital signature in the outputBuffer.

[0066]

[0067] The remote trusted component 206 can read data from the memory buffer and extract the digital signature and the protected encryption key. In one operation, the remote trusted component calls the primitive function 410 to generate a cryptographic digest of the true copy of the packet. In another operation, the remote trusted component 206 calls the primitive function 412 to determine whether the digital signature is generated by the packet with the cryptographic digest. The API component 122-1 can send a verification result, which indicates that the data in the memory buffer is secure, or indicates that the data has been misappropriated, or at least is incorrect.

[0068] In the following example implementation of the primitive function 404, the function call to IsolatedAppIoControl conveys the IO control code in the inputBuffer, and the API component 122-1 executes the IO control code and returns the result in the outputBuffer:

[0069]

[0070] The trusted code 202 calls the above primitive function to instruct the API component 122-1 to convey the message in the memory buffer inputBuffer to the remote trusted component.

[0071] An example mechanism for establishing a secure communication channel operates these functions to verify that the message originates from the trusted code 202 in the isolated memory region:

[0072]

[0073] The IsolatedRegionGetDigest() function returns a cryptographic digest that deterministically identifies the code package at the address indicated in packagePath, which is located in the local file system or a global or cloud-based file system. The code package can indicate a clean or undamaged version of the application. The cryptographic digest can be passed as the regionDigest argument, along with the identifier of the secure computing provider 120, to the primitive function IsolatedRegionCheckSignature(). If the message in the buffer was produced by the code on the isolated region, which was created by the secure computing provider, the function returns the boolean value "true". For example, the function can authenticate the signature using the public proof key corresponding to the secure computing provider 120 to confirm that the message content has not been compromised. As another example, the function can verify that the code running inside the isolated memory region has not been compromised by comparing the above cryptographic digest with the digest produced for such code, and a match indicates an unchanged copy of the code package. However, a mismatch indicates that the code inside the isolated memory region is not the same as the clean version. Thus, the content of the signed message / evidence message can be used to share secret data between the trusted code 202 and the remote trusted component 206 in various ways (e.g., Diffie-Hellman key exchange). The embodiments described herein support several of these secure channel establishment mechanisms and allow the user to choose which one to use.

[0074] Except for the isolated memory region 122-2, the following description applies to one or more example embodiments of implementing support components, such as Figure 3 the support component 304. The support component calls the primitive function IsolatedAppGetKey() on the API component 122-1 to generate an encryption key to be used as the sealing key for the encryption processor private key. The support component can call the primitive function IsolatedAppSignMessage() to sign the processor public key and then publish the key.

[0075] When the user develops application code (e.g., map and reduce functions), the remote trusted component compiles and encrypts the application code using a secret key and binds the encrypted application code with the public code to produce a code package (e.g., a code library, such as a dynamic link library (DLL) file). The remote trusted component 206 can verify the evidence of the processor public key using the function IsolatedRegionCheckSignature() and then encrypt the secret key used to encrypt the application code using the processor public key.

[0076] Un-trusted code in a cloud computing environment loads a code package into an isolated memory region via the function IsolatedRegionCreate(), and uses the function IsolatedRegionIOControl() to instruct the open code to generate a new random symmetric key to establish a secure communication channel with the isolated memory region. The new key for the region is encrypted using the processor public key, and the user region obtains a signature by calling the function IsolatedAppSignMessage(). Then, the encrypted new key is sent to the support region. The support region uses IsolatedRegionCheckSignature() to verify the signature and decrypt the encrypted new key. Then, the support region decrypts the secret key for the application code (which has been encrypted using the processor public key), encrypts the secret key using the new key from the isolated memory region, and sends the encrypted secret key to the isolated memory region. The trusted code running within the region decrypts the secret key and decrypts the application code, and then calls a function in the application code by calling the function IsolatedRegionIOControl() to convey primitive IO control code (or another control instruction) to a handler for processing the IO control code pointing to the application code. The trusted code prepares protected compute data for an external storage device by pointing the IO control code to a specific handler in the un-trusted code. For example, the trusted code calls the function IsolatedAppIOControl() to point the IO control code to a handler in the un-trusted code to instruct the handler to read encrypted key-value pairs; and after performing computations on those "pairs", the trusted code calls the function IsolatedAppIOControl() to point the IO control code to a handler in the un-trusted code to instruct the handler to write encrypted key-value pairs.

[0077] Figure 5 An embodiment of a secure communication channel 500 between trusted code 202 and a remote trusted component 206 is illustrated. When application code running in an isolated memory region is performing a set of computations for a parallel processing job, the trusted code 202 calls a primitive function 502 to read data (e.g., encrypted value pairs) from un-trusted code 122-4. The un-trusted code 122-4 returns the encrypted value pairs. The trusted code 202 may call the function and perform one or more computations on the encrypted value pairs. In another operation, the trusted code 202 calls a primitive function to write the encrypted value pairs to an external storage device, and the un-trusted code 122-4 returns an acknowledgement upon completion.

[0078] To send these "pairs" to a remote trusted component, the trusted code 202 invokes the primitive function 404 to process the digital signature for authenticating the encrypted value pairs. To send a message with a digital signature and an encrypted value pair, the trusted code 202 invokes the primitive function 406 to convey the message to the remote trusted component. Before decrypting the protected compute data, the remote trusted component invokes the primitive function 412 to verify the digital signature.

[0079] Figure 6 An embodiment of an isolation environment 600 for isolating trusted code and data in a memory region 122-2 is illustrated. The application code 602 may be a secret code in encrypted form. The public code 604 includes an interface for the application code 602 to perform a set of computations on stored data to generate compute data 606. The application code 602 may use the public code 604 to protect the compute data 606 with an encryption key 608 and convey the secure compute data 606 to untrusted code external to the isolation memory region 122-2. The public code 604 may also pass the signature 610 to code executing in a memory region different from the isolation memory 122-2 by requesting a signature 610 from an API component and conveying the signature 610 in a memory buffer of the message. As described herein, code executing in different storage regions may refer to untrusted code running in a cloud computing environment or remotely stored code executed by a remote machine.

[0080] In some embodiments, the public code 604 may utilize metadata 612 to identify the memory region of the application code 602 that includes one or more functions configured to process control instructions (e.g., communication primitives such as I / O control codes) from untrusted code running external to the isolation memory region 122-2. Via an application programming interface component such as those described herein, the untrusted code may invoke primitive functions to convey control instructions to call some of these functions. Thus, the metadata 612 enables access to complex functionality implemented by the application code 602 via (e.g., lower-level) interprocess communication primitives.

[0081] Figure 7 An embodiment of a computing environment 700 for a secure compute provider 720 is illustrated. The secure compute provider 720 depicts Figure 1 an alternative to the secure compute provider 120 of. In this embodiment, Figure 1 the support component 3 of can access the application code running in the processing unit. It should be appreciated that the computing environment 700 represents Figure 1 an alternative to the system 100 of, and other alternatives and modifications are contemplated in the present disclosure.

[0082] A secure computing provider 720 under the control of a computing environment 700 includes a processor circuit 730 and an isolated memory region 750, which also includes support components 304 and a processor key 752. The isolated memory region 750 can be configured to be similar to Figure 1 the isolated memory region 122-2. Application code 602 uses the processor circuit 730 to perform a set of calculations on data. As described herein, the support components 304 generate one or more processor keys 752 to protect the calculations at the processing unit level. Thus, the protected compute data 608 can be quickly decrypted / encrypted, enhancing the compute throughput with little or no security risk.

[0083] Figure 8 A block diagram of a centralized system 800 is illustrated. The centralized system 800 can implement some or all of the structures and / or operations for system 100 within a single computing entity (such as entirely within a single device 820).

[0084] The device 820 can include any electronic device capable of receiving, processing, and transmitting information for system 100. Examples of electronic devices can include, but are not limited to, ultra-mobile devices, mobile devices, personal digital assistants (PDAs), mobile computing devices, smartphones, telephones, digital telephones, cellular telephones, e-book readers, mobile phones, one-way pagers, two-way pagers, messaging devices, computers, personal computers (PCs), desktop computers, laptop computers, notebook computers, netbook computers, handheld computers, tablet computers, servers, server arrays or server farms, web servers, network servers, Internet servers, workstations, minicomputers, mainframe computers, supercomputers, network appliances, web appliances, distributed computing systems, multiprocessor systems, processor-based systems, consumer electronics, programmable consumer electronics, gaming devices, televisions, digital televisions, set-top boxes, wireless access points, base stations, user stations, mobile user centers, radio network controllers, routers, hubs, gateways, bridges, switches, machines, or combinations thereof. This embodiment is not limited in this context.

[0085] Device 820 may use processing component 830 to perform processing operations or logic for system 100. Processing component 830 may include various hardware elements, software elements, or a combination of both. Examples of hardware elements may include devices, logic devices, components, processors, microprocessors, circuits, processor circuits, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, application specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field programmable gate arrays (FPGAs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), memory units, logic gates, registers, semiconductor devices, chips, microchips, chip sets, etc. Examples of software elements may include software components, programs, applications, computer programs, application programs, system programs, software development programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, programs, software interfaces, application programming interfaces (APIs), instruction sets, computing code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. Determining whether to use hardware elements and / or software elements to implement embodiments may vary according to any number of factors, such as desired computing rate, power level, heat tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints, as desired for a given implementation.

[0086] Device 820 may use communication component 840 to perform communication operations or logic for system 100. Communication component 840 may implement any well-known communication technologies and protocols, such as those suitable for use with packet switched networks (e.g., public networks such as the Internet, private networks such as enterprise intranets, etc.), circuit switched networks (e.g., public switched telephone networks), or a combination of packet switched networks and circuit switched networks (with appropriate gateways and converters). Communication component 840 may include various types of standard communication elements, such as one or more communication interfaces, network interfaces, network interface cards (NICs), radios, wireless transmitters / receivers (transceivers), wired and / or wireless communication media, physical connectors, etc. By way of example and not limitation, communication media 812, 842 include wired communication media and wireless communication media. Examples of wired communication media may include wires, cables, metal leads, printed circuit boards (PCBs), backplanes, switch fabrics, semiconductor materials, twisted pairs, coaxial cables, optical fibers, propagating signals, etc. Examples of wireless communication media may include acoustic, radio frequency (RF) spectrum, infrared, and other wireless media.

[0087] Device 820 may communicate with other devices 810, 850 via communication components 840 using communication signals 814, 844 respectively over communication media 812, 842. Devices 810, 850 may be located inside or outside of device 820 depending on the needs of a given implementation.

[0088] As described herein, a trusted component running on a remote machine expects a secure communication channel that has application code running in an isolated memory region of the computing environment. The API component of a secure computing provider may establish a secure communication channel with an isolated memory region via a primitive programming model. Using function calls that invoke communication primitives, untrusted code and trusted code establish a secure connection or communication channel by implementing an encryption protocol that protects network data traffic such as Transport Layer Security (TLS), Secure Sockets Layer (SSL), and / or the like. Figure 8

[0089] Included herein is a collection of flowcharts representing exemplary methods for performing novel aspects of the disclosed architecture. Although, for purposes of simplified explanation, one or more of the methods shown herein (e.g., in the form of a flow diagram or flowchart) are shown and described as a series of acts, it should be understood and appreciated that the methods are not limited by the order of the acts, as some acts may occur in a different order and / or concurrently with other acts other than those shown and described herein. For example, those skilled in the art will understand and appreciate that the methods may alternatively be represented as a series of related states or events on a state diagram. Additionally, novel implementations may not require all of the acts illustrated in the methods.

[0090] Figure 9 Illustrated is Figure 1 an embodiment of a logical flow 900 for a system for Figure 9 The logical flow 900 may represent some or all of the operations performed by one or more of the embodiments described herein. In the illustrated embodiment shown in Figure 1 the API component 122-1 may perform the logical flow 900 to establish a secure communication channel between trusted code and code running outside of an isolated memory region at block 906.

[0091] For example, when untrusted code in a computing environment calls a primitive function to configure an isolated memory region based on certain parameters (e.g., size), at block 902, the logical flow 900 may generate an isolated memory region in the computing environment and store a code package in that region. The logical flow 900 may use a private attestation key to generate a signature that specifically corresponds to the secure computing provider 120 that controls the computing environment. ​

[0092] The logic flow 900 may perform a verification process at block 906, during which the code package is authenticated as a remote trusted component running in a remote machine. The logic flow 900 may perform the verification process to complete a key exchange protocol such that the trusted code provides an encryption key protected by a public key and a signature to the remote trusted component to authenticate the encryption key. For example, the public key may correspond to a certificate that corresponds to the remote machine that has requested the computing service. In response, the remote trusted component returns data on how to access the code package, such as protecting the user key with the encryption key and communicating the protected user key to the trusted code via a function call to an API component. The function call may cause control code to be communicated to the trusted code, which prompts the code to read the protected user key, decrypt the user key, and then decrypt the secret code in the code package to access the functionality of the code package.

[0093] For example, the API component and the untrusted code may instruct the trusted code in the isolated memory region to initiate a setup process for the key exchange protocol. The API component may generate an encryption key and communicate it to the isolated memory region. After the trusted code protects the encryption key, the trusted code requests the API component to generate a signature using the private key corresponding to the secure computing provider that controls the computing environment. The API component communicates the message including the signature to the remote trusted component running on the remote machine. After the key exchange protocol, the API component performs a verification process on the message to extract the content of the message and determine how to access the code package. If successful, the verification process proves that the signed message / evidence message originated from the trusted code in the isolated memory region. The API component may communicate the protected user key to the trusted code running in the isolated memory region. The API component may generate a cryptographic digest for the clean code package and perform a comparison between this digest and the cryptographic digest of the code package that originated the message.

[0094] The logic flow 900 may continue to communicate the verification result to the remote trusted component running on the remote machine at block 908. The logic flow at block 908 completes the establishment of a secure communication channel for the isolated memory region and the code running in that region. At least for this reason, the logic flow 900 may continue to perform higher-level computations. These computations involve control instructions that are more complex than inter-process communication primitives (e.g., IO control codes). By way of illustration, as an option, the logic flow may continue to block 908 and store secure data (e.g., encrypted value pairs) in a cloud file system where the external storage device appears as a file system. As another option, the logic flow 900 may communicate IO control codes to the untrusted code and call functions (e.g., hardware driver functions). The embodiments are not limited to this example.

[0095] Figure 10 An embodiment of a logic flow 1000 is illustrated. The logic flow 1000 may represent some or all of the operations performed by one or more embodiments described herein.

[0096] In Figure 10 the illustrated embodiment, the logic flow 1000 may process a user key at block 1002 and decrypt a secret code package stored in an isolated memory region. The mapping and reduction functions in the decrypted code package (i.e., now trusted code) may define a set of computations. The logic flow 1000 may run the mapping and reduction functions at block 1004 to perform a set of computations on the stored data and generate computed data. The logic flow 1000 may protect the computed data using an encryption key unknown to untrusted code running outside the isolated memory region. The logic flow 1000 may call a primitive function at block 1006 to generate a signature for the securely computed data. The logic flow 1000 calls a communication primitive at block 1008, which operates to write the protected computed data to untrusted code. For example, the logic flow 1000 may instruct the untrusted code to store the protected computed data in an external storage device. The embodiment is not limited to this example.

[0097] Figure 11 An embodiment of a logic flow for a Figure 4 remote trusted component is illustrated. The logic flow 1100 may represent some or all of the operations performed by one or more embodiments described herein.

[0098] In Figure 11 the illustrated embodiment, the logic flow 1100 begins at block 1102, where the logic flow 1100 encrypts a code package and conveys the encrypted code package along with a public key to a computing environment. The logic flow 1100 may process a signed message / evidence message at block 1104 and extract signed data from a memory buffer in the message. The logic flow 1100 initiates a process at block 1106 to verify that the signed data originated from the secret code package and has thus not been tampered with or compromised. If verified, the content of the signed message / evidence message may be used to share secret data between trusted code in an isolated environment and a remote trusted component in a remote machine in various ways (e.g., Diffie-Hellman key exchange). The embodiments described herein support several of these secure channel establishment mechanisms and allow the user to choose which one to use.

[0099] The logic flow 1100 can perform a determination at block 1106 as to whether the signed data has been compromised and either reject the connection to the isolated environment at block 1108 or accept the connection at block 1110. Multiple example embodiments for the verification process are described herein, and any one of these examples can be used to implement such a determination. For example, if the signed data cannot be verified using the public proof key for the secure computing provider, then it would appear that the message content has been tainted. As another example, if the cryptographic digest of the secret code package does not match the digest of the version stored on the remote machine, then the code package may have been altered, indicating that the isolated environment has been compromised. If the logic flow 1100 determines that the signed data is secure, then the logic flow 1000 can decrypt the cryptographic key stored in the message and protect the user key for conveyance to the trusted code at block 1110. As described herein, the user key includes the encryption key for decrypting the secret code package. The embodiments are not limited to this example.

[0100] Figure 12 An embodiment of an exemplary computing architecture 1200 suitable for implementing the various embodiments described previously is illustrated. In one embodiment, the computing architecture 1200 can include or be implemented as part of an electronic device. Examples of electronic devices can include those devices described with reference to Figure 8 those described, and so on. The embodiments are not limited in this context.

[0101] As used in this application, the terms "system" and "component" are intended to refer to computer-related entities, which can be hardware, a combination of hardware and software, software, or software in execution, examples of which are provided by the exemplary computing architecture 1200. For example, a component can be, but is not limited to, a process running on a processor, a processor, a hard disk drive, multiple storage drives (of optical and / or magnetic storage media), an object, an executable file, an execution thread, a program, and / or a computer. By way of illustration, an application running on a server and the server can both be components. One or more components can reside within a process and / or an execution thread, and a component can be located on one computer and / or distributed between two or more computers. Further, components can be communicatively coupled to each other via various types of communication media to coordinate operations. The coordination may involve a one-way or two-way exchange of information. For example, components can convey information in the form of signals communicated via the communication media. This information can be implemented as signals assigned to various signal lines. In such an assignment, each message is a signal. However, other embodiments can alternatively employ data messages. Such data messages can be sent via various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.

[0102] The computing architecture 1200 includes various general computing elements, such as one or more processors, multi-core processors, coprocessors, memory units, chip sets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, sound cards, multimedia input / output (I / O) components, power supplies, etc. However, the embodiments are not limited to being implemented by the computing architecture 1200.

[0103] As Figure 12 shown, the computing architecture 1200 includes a processing unit 1204, a system memory 1206, and a system bus 1208. The processing unit 1204 can be any one of various commercially available processors, including but not limited to and processors; application, embedded, and security processors; and and processors; IBM and Cell processors; Core(2) and processors; and similar processors. Dual microprocessors, multi-core processors, and other multi-processor architectures can also be employed as the processing unit 1204.

[0104] The system bus 1208 provides an interface to the processing unit 1204 for system components, which includes but is not limited to the system memory 1206. The system bus 1208 can be any one of several types of bus structures, which can further interconnect to a memory bus (with or without a memory controller), a peripheral bus, and a local bus using any one of a variety of commercially available bus architectures. Interface adapters can be connected to the system bus 1208 via a slot architecture. Example slot architectures can include but are not limited to Accelerated Graphics Port (AGP), Card Bus, (Extended) Industry Standard Architecture ((E)ISA), Micro Channel Architecture (MCA), NuBus, Peripheral Component Interconnect (Extended) (PCI(X)), PCI Express, Personal Computer Memory Card International Association (PCMCIA), etc.

[0105] The computing architecture 1200 may include or implement various articles of manufacture. An article of manufacture may include a computer-readable storage medium for storing logic. Examples of computer-readable storage media may include any tangible medium capable of storing electronic data, including volatile or non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, writable or rewritable memory, and the like. Examples of logic may include executable computer program instructions implemented using any suitable type of code such as source code, compiled code, interpreted code, executable code, static code, dynamic code, object-oriented code, visual code, and the like. Embodiments may also be at least partially implemented as instructions included in or on a non-transitory computer-readable medium that may be read and executed by one or more processors to enable performance of the operations described herein.

[0106] The system memory 1206 may include various types of computer-readable storage media in the form of one or more higher-speed memory units, such as read-only memory (ROM), random access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, polymer memory (such as ferroelectric polymer memory), ovonic memory, phase change or ferroelectric memory, silicon oxide nitride oxide silicon (SONOS) memory, magnetic or optical cards, arrays of devices (such as redundant arrays of independent disks (RAID) drives), solid-state memory devices (e.g., USB memory, solid-state drive (SSD)), and any other type of storage medium suitable for storing information. In Figure 12 the illustrated embodiment, the system memory 1206 may include non-volatile memory 1210 and / or volatile memory 1212. The basic input / output system (BIOS) may be stored in the non-volatile memory 1210.

[0107] The computer 1202 may include various types of computer-readable storage media in the form of one or more lower-speed memory units, including an internal (or external) hard disk drive (HDD) 1214, a magnetic floppy disk drive (FDD) 1216 that reads from and writes to a removable magnetic disk 1218, and an optical disk drive 1220 that reads from and writes to a removable optical disk 1222 (e.g., CD-ROM or DVD). The HDD 1214, FDD 1216, and optical disk drive 1220 may be connected to the system bus 1208 through an HDD interface 1224, an FDD interface 1226, and an optical drive interface 1228, respectively. The HDD interface 1224 for external drive implementations may include at least one or both of Universal Serial Bus (USB) and IEEE 1394 interface technologies.

[0108] The drives and associated computer-readable media provide volatile and / or non-volatile storage of data, data structures, computer-executable instructions, etc. For example, several program modules may be stored in the drives and memory units (e.g., non-volatile memory 1210, volatile memory 1212, etc.), including an operating system 1230, one or more application programs 1232, other program modules 1234, and program data 1236. In one embodiment, one or more application programs 1232, other program modules 1234, and program data 1236 may include, for example, various applications and / or components of the system 100.

[0109] The user may enter commands and information into the computer 1202 through one or more wired / wireless input devices (e.g., a keyboard 1238 and an indicating device such as a mouse 1240). Other input devices may include a microphone, an infrared (IR) remote control, a radio frequency (RF) remote control, a game pad, a stylus, a card reader, a dongle, a fingerprint reader, a glove, a graphics tablet, a joystick, a keyboard, a retina reader, a touch screen (e.g., capacitive, resistive, etc.), a trackball, a touchpad, a sensor, a stylus, etc. These and other input devices are typically connected to the processing unit 1204 through an input device interface 1242 coupled to the system bus 1208, but may be connected through other interfaces (such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, an IR interface, etc.).

[0110] A monitor 1244 or other type of display device is also connected to the system bus 1208 through an interface such as a video adapter 1246. The monitor 1244 may be internal or external to the computer 1202. In addition to the monitor 1244, the computer typically includes other peripheral output devices, such as speakers, printers, etc.

[0111] Computer 1202 can operate in a networked environment using logical connections via wired and / or wireless communication to one or more remote computers, such as remote computer 1248. Remote computer 1248 can be a workstation, server computer, router, personal computer, portable computer, microprocessor-based entertainment device, peer device, or other common network node, and typically includes many or all of the elements described relative to computer 1202, although for simplicity only memory / storage device 1250 is illustrated. The depicted logical connections include wired / wireless connections to a local area network (LAN) 1252 and / or a larger network, such as a wide area network (WAN) 1254. Such LAN and WAN networking environments are commonplace in offices and companies and facilitate enterprise-wide computer networks, such as intranets, all of which can be connected to a global communications network, such as the Internet.

[0112] When used in a LAN networking environment, computer 1202 is connected to LAN 1252 via a wired and / or wireless communication network interface or adapter 1256. Adapter 1256 can facilitate wired and / or wireless communication to LAN 1252, which may also include a wireless access point disposed thereon for communicating with the wireless functionality of adapter 1256.

[0113] When used in a WAN networking environment, computer 1202 can include a modem 1258, or be connected to a communication server on WAN 1254, or have other means for establishing communications via WAN 1254, such as via the Internet. Modem 1258, which can be internal or external and can be a wired device and / or a wireless device, is connected to system bus 1208 via input device interface 1242. In a networked environment, program modules depicted relative to computer 1202 or portions thereof can be stored in remote memory / storage device 1250. It should be appreciated that the network connections shown are exemplary and other means of establishing a communication link between computers can be used.

[0114] Computer 1202 is operable to communicate with wired and wireless devices or entities using IEEE 802 series standards, such as wireless devices that are operatively set up for wireless communication (e.g., IEEE 802.11 over-the-air modulation techniques). This includes at least Wi-Fi (or Wireless Fidelity), WiMax, and Bluetooth TMWireless technologies and so on. Therefore, communication can be a predefined structure as in the case of a conventional network, or merely ad-hoc communication between at least two devices. Wi-Fi networks use radio technologies known as IEEE 802.11x (a, b, g, n, etc.) to provide secure, reliable, and fast wireless connections. Wi-Fi networks can be used to connect computers to each other, to the Internet, and to wired networks (which use IEEE 802.3-related media and functions).

[0115] Figure 13 A block diagram illustrates an exemplary communication architecture 1300 suitable for implementing the various embodiments described previously. The communication architecture 1300 includes various common communication elements, such as transmitters, receivers, transceivers, radios, network interfaces, baseband processors, antennas, amplifiers, filters, power supplies, etc. However, the embodiments are not limited to being implemented by the communication architecture 1300.

[0116] As Figure 13 shown, the communication architecture 1300 includes one or more clients 1302 and a server 1304. The client 1302 can implement the client device 910. The server 1304 can implement the server device 950. The client 1302 and the server 1304 are operatively connected to one or more respective client data storage devices 1308 and server data storage devices 1310, which can be used to store the respective local information of the client 1302 and the server 1304, such as cookies and / or associated context information.

[0117] The client 1302 and the server 1304 can communicate information with each other using the communication framework 1306. The communication framework 1306 can implement any well-known communication technologies and protocols. The communication framework 1306 can be implemented as a packet-switched network (e.g., a public network such as the Internet, a private network such as an enterprise intranet, etc.), a circuit-switched network (e.g., a public switched telephone network), or a combination of a packet-switched network and a circuit-switched network (with appropriate gateways and converters).

[0118] The communication framework 1306 can implement various network interfaces that are arranged to receive, convey, and connect to a communication network. The network interfaces can be considered a specialized form of input / output interfaces. The network interfaces can adopt connection protocols, which include but are not limited to direct connection, Ethernet (e.g., thick, thin, twisted pair 10 / 100 / 1000Base T, etc.), Token Ring, wireless network interfaces, cellular network interfaces, IEEE 802.11ax network interfaces, IEEE 802.16 network interfaces, IEEE 802.20 network interfaces, etc. Further, multiple network interfaces can be used to interface with various communication network types. For example, multiple network interfaces can be used to allow communication over broadcast, multicast, and unicast networks. If processing requirements indicate greater speed and capacity, a distributed network controller architecture can similarly be used to aggregate, load balance, and otherwise increase the communication bandwidth required by the client 1302 and the server 1304. The communication network can be either a wired network and / or a wireless network and combinations thereof, which include but are not limited to direct interconnection, secure custom connections, private networks (e.g., enterprise intranets), public networks (e.g., the Internet), personal area networks (PAN), local area networks (LAN), metropolitan area networks (MAN), operational mission on the Internet as a node (OMNI), wide area networks (WAN), wireless networks, cellular networks, and other communication networks.

[0119] Various embodiments of the present disclosure include an apparatus that includes logic circuitry and logic that operates on the logic circuitry to configure an isolated memory region in a computing environment for protecting communication with code that can be executed in a memory region different from the isolated memory region; generate signed data using an evidence key corresponding to the computing environment, the signed data including a protected encryption key and a signature for authenticating the protected encryption key; and communicate the signed data to a remote trusted component to access secret code stored in the isolated memory region.

[0120] The apparatus of the previous paragraph may include logic that further operates to generate a signature using a private attestation key specifically corresponding to a secure computing provider that controls a computing environment. The apparatus of the previous paragraph may include logic that further operates to generate an encryption key for trusted code running in an isolated memory region. The apparatus of the previous paragraph may include logic that further operates to store a key-value pair in a buffer, the key-value pair being communicated to trusted code running in an isolated memory region or a remote trusted component. The apparatus of the previous paragraph may include logic that is further configured to generate a cryptographic digest of a code package on a distributed file system and use the cryptographic digest to verify a signature of a protected encryption key. The apparatus of the previous paragraph may include logic that further operates to process communication primitives that point to trusted code running inside an isolated memory region or untrusted code running outside the isolated memory region. The apparatus of the previous paragraph may include logic that further operates to process communication primitives that operate to call a function on untrusted code running outside the isolated memory region or trusted code running inside the isolated memory region. The apparatus of the previous paragraph may include logic that further operates to verify a signature using a public attestation key and decrypt a protected encryption key to extract the encryption key. The embodiments described in the previous paragraphs may also be combined with one or more of the alternative options specifically disclosed in this paragraph.

[0121] Various embodiments of the present disclosure also include a product that includes at least one computer-readable storage medium that includes instructions that, when executed, cause a system to generate computed data by performing a set of computations within an isolated memory region of a computing environment, protect the computed data using an encryption key to generate protected computed data, and invoke a primitive to communicate the protected computed data to code running outside the isolated memory region.

[0122] The product of the previous paragraph may further include instructions that, when executed, cause the system to process a signature of secure data generated using a private key associated with a computing environment and to invoke a primitive to communicate the protected computing data and the signature to a remote trusted component. The product of the previous paragraph may further include instructions that, when executed, cause the system to invoke a primitive function to generate an encryption key and to invoke another primitive function to generate a signature using the encryption key. The product of the previous paragraph may further include instructions that, when executed, cause the system to protect the encryption key using a public key corresponding to a remote trusted component running on a remote machine. In one or more embodiments of the product described above, the public key communicates with the product. The product of the previous paragraph may further include instructions that, when executed, cause the system to decrypt a protected user key using the encryption key to extract the user key and to use the user key to decrypt a secret code in an isolated memory region. The embodiments described in the previous paragraphs may also be combined with one or more of the alternative options specifically disclosed in this paragraph.

[0123] Various embodiments of the present disclosure also include a method that includes the steps of: generating an isolated memory region in a computing environment to store a code package, where the isolated memory region is only accessible by code running in the isolated memory region; generating a signature using a private attestation key corresponding to the computing environment, performing a verification process on the code package using the signature and cryptographic digest of the code package; and communicating the verification result of the code package to a remote trusted component.

[0124] The method of the previous paragraph may further include the step of communicating a protected user key to transform the secret code of the code package into application code. The method of the previous paragraph may further include the step of loading the encrypted code package into the isolated memory region. The method of the previous paragraph may further include the step of generating an encryption key to protect communication between the application code and code running outside the isolated memory region. The method of the previous paragraph may further include the step of generating an encryption key to protect communication between the application code and code running outside the isolated memory region. The method of the previous paragraph may further include the steps of: processing a message including signed data using a public key corresponding to the computing environment and generating a verification result indicating whether the message originated from a trusted component in the isolated memory region. The embodiments described in the previous paragraphs may also be combined with one or more of the alternative options specifically disclosed in this paragraph.

[0125] Some embodiments may be described using the expressions "one embodiment" or "an embodiment" and their derivatives. These terms mean that the particular features, structures, or characteristics described in connection with the embodiment are included in at least one embodiment. The phrase "in one embodiment" that appears throughout the specification is not necessarily referring to the same embodiment. Further, the expressions "coupled" and "connected" and their derivatives may be used to describe some embodiments. These terms are not necessarily intended as synonyms for each other. For example, the terms "connected" and / or "coupled" may be used to describe some embodiments to indicate that two or more elements are in direct physical or electrical contact with each other. However, the term "coupled" may also mean that two or more elements are not in direct contact with each other, but still cooperate or interact with each other.

[0126] It should be emphasized that the abstract of the disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. Submitting this abstract, it is understood that it will not be used to interpret or limit the scope or meaning of the claims. Additionally, in the foregoing detailed description, it can be seen that for the purpose of making the disclosure flow and concise, various features are combined in a single embodiment. The method of the disclosure is not to be construed as reflecting an intention that the claimed embodiments require more features than are expressly recited in each claim. Rather, as reflected in the following claims, the inventive subject matter lies in less than all of the features of a single disclosed embodiment. Accordingly, the following claims are hereby incorporated into the detailed description, with each claim standing on its own as a separate embodiment. In the appended claims, the terms "including" and "in which" are used as the plain-English equivalents of the respective terms "comprising" and "wherein". Additionally, the terms "first", "second", "third", etc. are used merely as labels and are not intended to impose numerical requirements on their objects.

[0127] The foregoing description includes examples of the disclosed architectures. Of course, it is not possible to describe every conceivable combination of components and / or methods, but one of ordinary skill in the art will recognize that many other combinations and permutations are possible. Thus, the novel architectures are intended to cover all such changes, modifications, and variations that fall within the spirit and scope of the appended claims.

Claims

1. An apparatus for protecting data in a computing environment, comprising: logic circuitry; and a computer-readable storage device including a tangible storage medium, the computer-readable storage device including instructions that are executed by the logic circuitry to: generate computed data by executing, within an isolated memory region of the computing environment, a parallel processing job received from outside the isolated memory region, the computed data corresponding to the execution of a set of computations within the isolated memory region; protect the computed data using an encryption key to generate protected computed data; protect the encryption key using a public key associated with code running outside the isolated memory region to generate a protected encryption key; invoke a primitive of a primitive programming model to configure a secure communication channel for the isolated memory region to the code running outside the isolated memory region; and communicate the protected computed data and the protected encryption key to the code running outside the isolated memory region using the secure communication channel.

2. The apparatus according to claim 1, wherein the instructions are further executed to process a signature of the protected computed data generated using a private key associated with the computing environment.

3. The apparatus according to claim 1, wherein the instructions are further executed to invoke a primitive function for generating the encryption key and a primitive function for generating a signature using the encryption key.

4. The apparatus according to claim 1, wherein the instructions are further executed to protect the encryption key using a public key corresponding to a remote trusted component running on a remote machine.

5. The apparatus according to claim 1, wherein the instructions are further executed to: generate a cryptographic digest of a code package on a distributed file system and use the cryptographic digest to verify a signature of the protected encryption key.

6. The apparatus according to claim 1, wherein the instructions are further executed to decrypt a protected user key using the encryption key to extract the user key and use the user key to decrypt a secret code in the isolated memory region.

7. The apparatus according to claim 1, wherein the instructions are further executed to process communication primitives that operate to invoke a function on untrusted code running outside the isolated memory region or on trusted code running inside the isolated memory region.

8. A computer-implemented method, comprising: generate computed data by executing, within an isolated memory region of the computing environment, a parallel processing job received from outside the isolated memory region, the computed data corresponding to the execution of a set of computations within the isolated memory region; protect the computed data using an encryption key to generate protected computed data; protect the encryption key using a public key associated with code running outside the isolated memory region to generate a protected encryption key; Invoke a primitive of the original programming model to configure a secure communication channel for the isolated memory region, the secure communication channel going to the code running outside the isolated memory region; and Use the secure communication channel to convey the protected computing data and the protected encryption key to the code running outside the isolated memory region.

9. The computer-implemented method according to claim 8, further comprising: Process a signature of the protected computing data generated using a private key associated with the computing environment.

10. The computer-implemented method according to claim 8, further comprising: Invoke a primitive function for generating the encryption key and a primitive function for generating a signature using the encryption key.

11. The computer-implemented method according to claim 8, wherein protecting the encryption key comprises: Protect the encryption key using a public key corresponding to a remote trusted component running on a remote machine.

12. The computer-implemented method according to claim 8, further comprising: Generate a cryptographic digest of a code package on a distributed file system and use the cryptographic digest to verify a signature of the protected encryption key.

13. The computer-implemented method according to claim 8, further comprising: Use the encryption key to decrypt a protected user key to extract the user key and use the user key to decrypt a secret code in the isolated memory region.

14. The computer-implemented method according to claim 8, further comprising: Process communication primitives that operate to invoke a function on untrusted code running outside the isolated memory region or on trusted code running inside the isolated memory region.

Citation Information

Patent Citations

  • Securing data in a networked environment

    CN101512490A

  • Hardware supported virtualized cryptographic service

    CN102208001A