Incremental Decryption and Integrity Verification of Secure Operating System Images

Through the methods of incremental decryption and integrity verification, decryption and verification of operating system images page by page, the problems of operating system security and integrity in the virtual machine environment are solved, and a secure execution environment is realized to prevent attacks and tampering.

CN113544679BActive Publication Date: 2025-07-22INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080019498.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-03-08
Filing Date
2020-02-17
Publication Date
2025-07-22
Estimated Expiration
2040-02-17

AI Technical Summary

Technical Problem

In computing environments, the security and integrity of the guest operating system are difficult to guarantee, especially in virtual machine environments, where hypervisors may tamper or attack application data, resulting in trust issues.

Method used

Decrypt the secure operating system image incrementally, decrypt the memory page contents page by page using image encryption keys and unique fine-tuning values, and verify image integrity, protect the operating system image from hypervisors and other programs with security interface controls.

Benefits of technology

Provides a secure execution environment that prevents statistical analysis attacks on operating system images, ensures the confidentiality and integrity of the operating system, and protects the guest operating system and its applications from hypervisors and other programs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113544679B_ABST
    Figure CN113544679B_ABST
Patent Text Reader

Abstract

Providing secure processing within a computing environment by incrementally decrypting a secure operating system image, including receiving a page address and a tweak value used during encryption of a page for a secure operating system image. Processing determines that the tweak value has not been previously used during decryption of another page of the secure operating system image and uses an image encryption key and the tweak value to decrypt the memory page content at the page address to facilitate obtaining the decrypted secure operating system image. Further, the integrity of the secure operating system image is verified, and based on verifying the integrity of the secure operating system image, execution of the decrypted secure operating system image is commenced.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] A client operating system refers to, for example, operating system software installed on a virtual machine. In computing, a virtual machine is an emulation of a computer system. A virtual machine, which can be created by a virtual machine supervisor, is based on a computer architecture and provides the functionality of a physical computer. The implementation of a virtual machine can involve dedicated hardware, software, or a combination thereof. Virtualization technology allows a computer to run more than one operating system at a time.

[0002] In the current computing environment, system software such as an operating system must be trusted because it has complete control over the applications and data to be executed. Traditionally, an operating system (and a virtual machine supervisor) can access or modify the data of any application, or potentially tamper with the security features implemented by an application without being detected. Therefore, the underlying software should be part of a trusted computing library.

[0003] In a shared environment, the customers of an application are forced to trust that the entity that develops, configures, deploys, and controls the system software is not malicious. The customer application must also trust that the system software is not vulnerable to attacks that escalate privileges and compromise the integrity of the application's information. Such a broad trust requirement can sometimes be difficult to justify and carries significant risks, especially for customers of applications that use, for example, public cloud services. Summary of the Invention

[0004] Certain disadvantages of the prior art are overcome and additional advantages are provided by a computer system that facilitates secure processing within a computing environment. The computer system includes a memory and a processor coupled to the memory, and the computer system is configured to execute a method. The method includes incrementally decrypting a secure operating system image. Incremental decryption includes, for one of a plurality of pages of the secure operating system image: receiving the page address of the page and a tweak value used during encryption of the page; determining that the tweak value has not been used during a previous decryption of another one of the plurality of pages of the secure operating system image; and using an image encryption key used when encrypting the page and the tweak value to decrypt the memory page content at the page address to facilitate obtaining a decrypted secure operating system image. The method further includes verifying the integrity of the secure operating system image, and based on verifying the integrity of the secure operating system image, starting to execute the decrypted secure operating system image. Advantageously, incremental decryption of pages of the secure operating system image, where the pages are individually encrypted using an image encryption key and a unique tweak value (also known as an initialization vector), provides enhanced security within the computing environment by, for example, preventing statistical analysis of the secure operating system image to obtain meaningful data. Further, the general method also allows for differently encrypting data stored in different locations.

[0005] In one or more embodiments, incremental decryption and verification of integrity are performed by a security interface control of a computer system. The security interface control is a secure and trusted entity of the computer system, and the page address and the tweak value are received by the security interface control from the hypervisor. Advantageously, the security interface control presents a secure execution environment in which the memory of the guest operating system and its applications running in the secure virtual machine are protected from the hypervisor, as well as other virtual machines and any programs running on the same host system as the virtual machine.

[0006] In one or more embodiments, the page addresses of multiple pages have a fixed order (e.g., from low to high), and incremental decryption of the secure operating system image includes determining any previous page address for which the page address is different from (e.g., greater than in the case of sorting from low to high) the previous page address of the multiple pages of the secure operating system image that have been previously decrypted. Further, in one or more implementations, incremental decryption of the secure operating system image further includes determining that the tweak value is different from (e.g., greater than in the case of sorting from low to high) any previous tweak value used during decryption of the previously decrypted pages of the multiple pages of the secure operating system image.

[0007] In one embodiment, verifying integrity includes in part employing a cumulative content hash obtained using the memory page contents of the multiple pages and a cumulative address hash obtained using the page addresses of the multiple pages. For example, verifying the integrity of the secure operating system image may include comparing the cumulative content hash with an integrity content hash received by the security interface control along with metadata from the hypervisor, and comparing the cumulative address hash with an integrity address hash received by the security interface control along with metadata from the hypervisor. For example, the security interface control may extract the integrity content hash, the integrity address hash, and the image encryption key from the metadata received from the hypervisor. Advantageously, the security interface control (i.e., the secure entity of the host system) is able to verify the integrity of the operating system image to prevent the execution of an image that has been tampered with. For this purpose, hash values calculated based on the contents of the memory pages and hash values calculated based on a list of the memory page addresses of the operating system image are used and compared with the corresponding integrity hash values of the content and addresses provided in the order of the page addresses. Note that, in this regard, sorting the page addresses from low to high facilitates the effectiveness and integrity check of the tweak value. Also note that the memory pages do not need to be contiguous when employing the above process.

[0008] In one or more embodiments, the secure interface control includes a firmware element of a computer system, and the secure operating system image will operate as a secure guest operating system image within a computing environment. In one or more specific embodiments, a private-public key pair is associated with the computer system, where the private key is known only to the secure interface control and is inaccessible to software running on the computer system. The public key is used by the owner of the secure operating system image to generate key agreement data in order to securely transfer an image encryption key for encrypting the secure operating system image with the secure interface control and store the key agreement data in a metadata structure. The metadata structure can be received by the secure interface control along with a call from a hypervisor. The metadata structure can further include an integrity hash value used when verifying the integrity of the secure operating system image. Advantageously, this process results in a secure execution environment where the confidentiality of the secure operating system image is preserved and at the same time the integrity of the operating system is verified. In this process, the owner of the secure operating system image selects a key, i.e., the image encryption key, and assuming that all components of the operating system are encrypted, the static data used by the operating system image is also encrypted after the operating system image has been booted.

[0009] Computer program products and computer-implemented methods related to one or more aspects are also described and claimed herein. Further, services related to one or more aspects are also described and may be claimed herein.

[0010] Additional features and advantages are realized through the techniques of the present invention. Other embodiments and aspects of the present invention are described in detail herein and are considered to be part of the claimed invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] One or more aspects of the invention are particularly pointed out and distinctly claimed as examples at the end of the specification in the claims. The above and other objects, features and advantages of the present invention are apparent from the following detailed description in conjunction with the accompanying drawings, in which:

[0012] Figure 1 An example of a computing environment including and using one or more aspects of decryption and integrity verification of a secure operating system image in accordance with one or more aspects of the present invention is depicted;

[0013] Figure 2 An embodiment of a process for incremental decryption and integrity verification of a secure operating system image in accordance with one or more aspects of the present invention is depicted;

[0014] Figure 3A An embodiment of the virtual machine (VM) memory contents after a secure operating system image has been loaded in accordance with one or more aspects of the present invention is depicted;

[0015] Figure 3B Depicts an embodiment of metadata for unpacking a secure operating system image according to an incremental decryption and integrity verification process, in accordance with one or more aspects of the present invention;

[0016] Figure 4A Depicts an embodiment of starting the image unpacking process, showing the data structures and operations of the guest address space, hypervisor, and hyper manager (or secure interface control) according to the incremental decryption and integrity verification process, in accordance with one or more aspects of the present invention;

[0017] Figure 4B Depicts, in accordance with one or more aspects of the present invention, the Figure 4A Further details of an embodiment of the unpacking process between the guest address space, hypervisor, and hyper manager;

[0018] Figure 4C Depicts, in accordance with one or more aspects of the present invention, the Figure 4A and 4B An embodiment of the guest address space, hypervisor, and hyper manager upon completion of the operating system image unpacking;

[0019] Figure 5A-5B Depicts an example of incremental decryption and integrity verification of a secure operating system image, in accordance with one or more aspects of the present invention;

[0020] Figure 6A Depicts another example of a computing environment that includes or uses one or more aspects of the present invention;

[0021] Figure 6B Depicts, in accordance with one or more aspects of the present invention, the Figure 6A Further details of the memory;

[0022] Figure 7 Depicts an embodiment of a cloud computing environment; and

[0023] Figure 8 Depicts examples of the abstract model layer. Detailed Description

[0024] According to one aspect of the present invention, there is provided an ability to facilitate secure processing within a computing environment. In one example, the ability includes incrementally decrypting a secure operating system image page by page, where it is assumed that each page has been encrypted using an image encryption key (i.e., a secret key) and a corresponding unique tweak value. The incremental decryption includes determining that the unique tweak value for a particular page has not been previously used during the decryption of another page of the secure operating system image. Additionally, integrity verification of the secure operating system image is performed commensurately with the decryption of the encrypted pages of the image. Further, based on verifying the integrity of the secure operating system image, the execution of the image is commenced.

[0025] See Figure 1 An example of a computing environment that includes and uses one or more aspects such as the incremental decryption and integrity verification processes disclosed herein is described. See Figure 1 , in one example, the computing environment 100 is based on the z / Architecture provided by International Business Machines Corporation of Armonk, New York, USA. A description of the z / Architecture can be found in the IBM publication "z / Architecture Principles of Operation" ( Publication No. SA22-7832-11, 12th Edition, September 2017), which is hereby incorporated by reference in its entirety. Z / ARCHITECTURE, IBM, Z / VM, and Z / OS (as cited herein) are registered trademarks of International Business Machines Corporation of Armonk, New York, USA. Other names used herein may be registered trademarks, trademarks, or product names of International Business Machines Corporation or other companies.

[0026] In another example, the computing environment is based on the Power Architecture provided by International Business Machines Corporation of Armonk, New York, USA. A description of an embodiment of the Power Architecture can be found in "Power ISA TM Version 2.07B" (International Business Machines Corporation, April 9, 2015), which is hereby incorporated by reference in its entirety. POWER ARCHITECTURE is a registered trademark of International Business Machines Corporation of Armonk, New York, USA.

[0027] The computing environment 100 includes a Central Processor Complex (CPC) 102 that provides virtual machine support. The CPC 102 is coupled to one or more input / output (I / O) devices 106 via one or more control units 108. The Central Processor Complex 102 includes, for example, a processor memory 104 (also known as main memory, primary storage, central storage) and an input / output subsystem 111 that are coupled to one or more central processors (also known as central processing units (CPUs)) 110, each of which will be described below.

[0028] The processor memory 104 includes, for example, one or more virtual machines 112, a virtual machine manager such as a hypervisor 114 that manages the virtual machines, an ultravisor 115 (or security interface control), and processor firmware 116. An example of the hypervisor 114 is provided by International Business Machines Corporation of Armonk, New York The hypervisor is sometimes referred to as the host. Further, as used herein, firmware includes, for example, the microcode and / or nano-code of the processor. It includes, for example, hardware-level instructions and / or data structures used in the implementation of higher-level machine code. In one embodiment, it includes, for example, proprietary code that is typically delivered as microcode, the microcode including trusted software or microcode specific to the underlying hardware and controlling access to the system hardware by the operating system. In one or more embodiments, the security interface control (ultravisor 115) can be implemented at least in part in hardware and / or firmware that is configured to perform, for example, the processes described herein.

[0029] The virtual machine support of the CPC provides the ability to operate a large number of virtual machines 112, each of which is capable of operating with a different program 120 and running a guest operating system 122, such as Linux. Each virtual machine 112 can act as a separate system. That is, each virtual machine can be independently reset, run the guest operating system, and operate with different programs. The operating system or application running in the virtual machine may appear to have access to the entire system, but in fact, only a portion of it is available.

[0030] The processor memory 104 is coupled to the central processing unit (CPU) 110, which is a physical processor resource that can be allocated to virtual machines. For example, a virtual machine 112 includes one or more logical processors, each of which represents all or a portion of the physical processor resources 110 that can be dynamically allocated to the virtual machine.

[0031] Additionally, in one embodiment, each CPU 110 is a hardware thread that executes within a processing core (also referred to as a core) 132. A core includes one or more threads, and in this example, core 132 includes four hardware threads. In other examples, the computing environment may include one or more cores, and each core may include one or more hardware threads.

[0032] Further, processor memory 104 is coupled to I / O subsystem 111. Input / output subsystem 111 directs the flow of information between input / output control unit 108, device 106, and main memory 104. It is coupled to the central processing complex, as it can be part of the central processing complex or separate from it.

[0033] In a specific example, the model of the virtual machine is the V = V model, where the virtual or absolute memory of the virtual machine is supported by the host virtual memory rather than the physical or absolute memory. Each virtual machine has a contiguous virtual memory space. Physical resources are managed by hypervisor 114, and shared physical resources are dispatched by the host to guest operating systems as needed to meet their processing requirements. The V = V virtual machine (i.e., the pageable guest) model assumes that the interaction between the guest operating system and the physical shared machine resources is controlled by the host, as a large number of guests typically prevent the host from simply partitioning hardware resources and allocating them to the configured guests.

[0034] As described above, memory 104 is coupled to I / O subsystem 111. I / O subsystem 111 can be part of the central processing complex or separate from it. It can direct the flow of information between main memory 104, input / output control unit 108, and input / output (I / O) device 106, which is coupled to the central processing complex.

[0035] Many types of I / O devices can be used. One specific type is data storage device 140. Data storage device 140 can store one or more programs 142, one or more computer-readable program instructions 144, and / or data, etc. The computer-readable program instructions can be configured to perform the functions of embodiments of aspects of the present invention.

[0036] The computer-readable program instructions configured to perform the functions of embodiments of aspects of the present invention can also or alternatively be included in memory 104. Many variations are possible.

[0037] As disclosed herein, the memory of a guest operating system and the applications running within a secure virtual machine are protected from an untrusted hypervisor, as well as from other virtual machines and any programs running on the same host system as the virtual machine. The protection is enforced by a trusted entity, which includes hardware and / or firmware elements of the secure host system. The trusted entity is referred to herein as a secure interface control or a hypervisor manager. In one or more implementations, the secure interface control (or hypervisor manager) runs in trusted firmware. The trusted firmware resides in a hardware system area (HSA) that is highly protected and can only be accessed by the lowest level of firmware. In one or more embodiments, the code is owned by the manufacturer of the computer system, rolled out by the manufacturer, and securely maintained by the manufacturer. The content of the code is machine-readable to execute the code, but not dumped or extracted from the machine. In one or more embodiments, the secure interface control is an extension of the hardware to implement instructions that may be too complex to be implemented purely in hardware. In contrast, a hypervisor can refer to any software that can host multiple guests (also known as virtual machines). A hypervisor is not necessarily firmware that is carefully loaded and protected from access by software running on the system. In general, in one or more embodiments, a hypervisor can be third-party software with a wide range of management interfaces, including network interfaces. A hypervisor is thus untrusted. A hypervisor is thus untrusted and may have vulnerabilities exploitable through network interfaces, or weaknesses that are susceptible to malicious or negligent management.

[0038] An operating system image intended to run as a secure guest in a computing environment is herein assumed to be protected from inspection and tampering, even before it is made available to the host system, in order to ensure confidentiality and integrity. To achieve this, the operating system image is encrypted and integrity-protected with a secret key selected by the image owner. This key is also referred to herein as the image encryption key. It is assumed that all components of the operating system image are encrypted, as well as all static data used by the operating system after the system has been booted.

[0039] Encryption of data not required to boot the operating system can be done independently of the encryption of the operating system image itself. Decryption of the additional data can be done by the operating system running as a secure guest. For example, an encrypted Linux operating system image can include a kernel, an initial ramdisk, and a kernel parameter line. The initial ramdisk can include keys for decrypting data residing on an encrypted disk volume allocated to the virtual machine.

[0040] The host system running the virtual machine needs to be able to decrypt the secure operating system image in order to boot the secure operating system image. To ensure confidentiality, this capability is herein reserved for the trusted hardware and firmware of the host system ("secure interface control" or "hypervisor"). For this purpose, a private-public key pair is associated with the host system. The private key is known only to the trusted hardware and firmware of the host system (i.e., the secure interface control or hypervisor) and is not accessible by any software running on the host. The public key is used by the owner of the encrypted operating system image to generate key agreement data to securely communicate the image encryption key used to encrypt the secure operating system image to the secure interface control and store the key agreement data in a metadata structure (referred to herein as the secure execution (SE) header). For example, RSA key wrapping or Diffie-Hellman / KEM-type key exchange methods can be used. The size of the SE header is independent of the size of the operating system image.

[0041] Further, as disclosed herein, the host system also verifies the integrity of the operating system image in order to prevent the execution of an image that has been tampered with. For this purpose, an integrity hash value is calculated for the content of the memory pages, and an integrity hash value is calculated for a list of the memory page addresses of the operating system image. In one or more embodiments, to facilitate the calculation of the two hash values, the pages and their addresses are provided in the order of the page addresses (e.g., from lowest to highest). These integrity hash values to be compared can be stored in and provided to the secure interface control or hypervisor via the metadata structure (SE header).

[0042] The process of incrementally decrypting and facilitating the integrity check of the secure operating system image is referred to herein as unpacking. One or more aspects disclosed herein cover the process of decrypting an operating system image within a secure host system in a manner that verifies the integrity of the operating system image while protecting confidentiality. In one or more embodiments, this can be facilitated by implementing the order of the memory pages during the unpacking process. Another advantage of the inventive aspects described herein is the ability to handle operating system images stored discontinuously.

[0043] Additionally, in one or more aspects, the disclosed method of decrypting a secure operating system image and verifying the integrity of the secure operating system image makes it more difficult to perform a statistical analysis of the secure operating system image and an attack on the image based on the statistical analysis.

[0044] As described above, in one or more embodiments, a specially prepared secure operating system image is executed in a manner that does not allow observation of memory contents in a secure state. For inherent security, it is assumed that the operating system image is encrypted with a key (referred to herein as the secret key or image encryption key) selected by the user or owner of the secure operating system image. After encryption is complete, the encryption key (i.e., the image encryption key) is wrapped with a second key of the host computing system, i.e., with the public key in a public-private key pair or with a symmetric key derived from the public-private key pair. In one or more embodiments, page-by-page encryption may be performed by a symmetric key algorithm that uses, for example, an initialization vector referred to herein as a tweak value, where the tweak value is a unique value for each page of the image.

[0045] Figure 2 An embodiment of an unpacking process is depicted in accordance with one or more aspects. In one or more embodiments, a hypervisor is provided with functionality accessible via hypervisor calls including a start unpack operation call, an execute page-by-page unpack operation call, and a complete unpack operation call by a hypervisor manager or a security interface control. Before the hypervisor manager can be called, the encrypted secure operating system image is loaded into a still insecure virtual machine (VM) memory to allow the hypervisor manager to perform the load. Further, the hypervisor must know the addresses of all pages that make up the operating system image and also the encrypted tweak values used for each page. For aspects of the present invention, it is not important how this information is made available to the hypervisor. For simplicity, an unencrypted boot component may be loaded into the virtual machine memory along with the encrypted image. The hypervisor may be called with the following parameters: the SE header, a list of memory page addresses, and a list of tweak values (e.g., one tweak per page address).

[0046] Instead of providing a comprehensive list of pages to the hypervisor, a list of page ranges can also be specified to save memory. Similarly, instead of providing a list of fine-tuning values, a range of fine-tuning values where subsequent fine-tuning values differ by a fixed positive value can be specified. Alternatively, the fine-tuning value can be derived from the page address. None of the above options affect the interaction between the hypervisor and the hypermanager. The hypervisor starts the unpacking operation with a call to the hypermanager, which is, for example, "start unpack" (200) with the SE header as an argument. The SE header contains the image encryption key of the owner wrapped by the public host key, as well as the image integrity hash value of the image page content and the page address. The hypermanager extracts the image encryption key and the integrity value from the SE header (202) and determines whether the SE header data is valid (204). If "no", the unpacking operation fails and enters the disabled waiting state (206). Entering the disabled waiting state makes the guest operating system unable to run, i.e., the guest cannot leave the disabled waiting state. For example, an error can be returned to the hypervisor. In one or more embodiments, the guest system can be reset, in which case it will start again with the encrypted image loaded and start the unpacking process described above. Alternatively, the guest system can be shut down, which effectively deletes the virtual machine, i.e., releases the host resources used by the virtual machine.

[0047] The hypervisor loops (208) over all the page addresses of a specified memory region in ascending order of page addresses (in one or more embodiments), and calls the hypervisor's "unpack page" operation (210) with the page address and the encrypted tweak value for that page. The hypervisor then performs the following operations. The hypervisor sets the memory page to be secure and decrypts the memory page content using the image encryption key from the SE header and the tweak value used to encrypt the page. To prevent the tweak value from being used more than once, each new tweak value should be represented by a number greater than the previously used tweak value, and each page address should be greater than the previously used page address (212). If "no", the unpacking fails and it enters a disabled waiting state (206). Otherwise, the hypervisor marks the page as secure, decrypts the page using the image encryption key and the tweak value, and determines the cumulative content hash of the page content and the cumulative address hash of the page address (214). (For example, the calculation of the cumulative hash can be: cum_hash (cumulative_hash): = cum_hash + partial_hash (page i) on all pages, where 1 <= i <= n, and + is a complex operation.) In one embodiment, the hypervisor determines a running hash value based on the content of the memory page and the aggregated value of all previously decrypted pages, and determines another hash value based on the page address of the memory page and the aggregated value of the page addresses of all previously decrypted pages. By concatenating multiple page addresses into one memory page and then calculating the hash value on that memory page, an enhancement to the per-page-address hash calculation such as the one mentioned above can be achieved.

[0048] After all the operating system image pages have been processed (208), the hypervisor calls the hypervisor with a "finalize unpack" operation (216), where the hypervisor compares the content and address hash values calculated for the content and page address with the corresponding integrity hash values contained in the SE header (218). If they do not match, the unpacking operation fails and an error indication is returned to the hypervisor (206). Otherwise, the unpacking operation has succeeded and the hypervisor can start the secure guest execution with the program status word (PSW) in the SE header, which starts the operating system image running in secure mode.

[0049] Note that with the processing described herein, the memory pages do not have to be contiguous since the image can have "holes", but the decryption process should (in one or more embodiments) be in ascending order to enable the validity and integrity checks of the tweak values described herein. Pages that belong to the guest but are not unpacked during guest initialization will be secure and zeroed on the first access by the secure guest.

[0050] As a further example, Figure 3A depicts an embodiment of the memory contents after the secure operating system image has been loaded. As described above, in one or more embodiments, the secure operating system image is assumed to be encrypted by the user or owner of the secure operating system image with an image encryption key. The image encryption key is a secret key selected by the user or owner. After encryption, the encryption key is wrapped with or using the public key from a public-private key pair of the host computing system or a symmetric key derived from the public-private key pair, and stored in a metadata structure (i.e., a secure execution (SE) header) 301, which is provided within the client address space 300 as part of the metadata 303 from the client disk 310. The client disk 310 and the client address space 300 are (in one or more embodiments) provided by the hypervisor to the virtual machine to run the secure operating system image in memory. A boot component 302 may be provided together with the SE header 301 for initiating the execution of the secure operating system image. In one or more implementations, the metadata 303 is unencrypted but protected from tampering. The secure operating system image 305 includes address pages 304, which, as described above, have been individually encrypted with the owner's image encryption key to ensure protection of the operating system image. The secure operating system image can be loaded into memory (as Figure 3A shown).

[0051] Figure 3B Further depicts metadata for unpacking the secure operating system image in one or more embodiments. As shown, the SE header 301 within the client address space 300 may include the image encryption key 306 (wrapped with the public key), as well as an integrity hash 307 of the image contents and an integrity hash 308 of the image address. In one or more embodiments, the boot program component 302 may include bootstrap code 309 and per-page information 311. The bootstrap code 309 may be or include a code segment executable by the hypervisor. The per-page information 311 includes a page address and a tweak value. As described above, in one or more embodiments, the hypervisor may send the page address to the super manager, and the page addresses are sorted, such as in ascending or descending order, as an effective method for being able to evaluate that the page address and the tweak value are different from the previous page address and tweak value of the secure operating system image. By way of example only, in one or more embodiments herein the page addresses are described as being arranged in ascending order, as in the following Figure 4A-4Cas in the example of. As described herein, metadata including pages and adjustment lists can be generated by an entity (such as a software tool), and the entity and the hypervisor will have a consensus on the order of the addresses and fine-tuning values within the list. More specifically, in one or more implementations, the important order is the order in which pages are encrypted and hashed, and the order in which the hypervisor submits the pages to the super manager, and these orders match. As described above, the order can be ascending or descending, but the super manager needs to know which direction of the order to use when generating the image. Therefore, this direction is typically specified by the security interface control (or super manager) architecture.

[0052] Figure 4A-4C FIG. shows an embodiment of an unpacking process according to one or more aspects of the present invention, which shows the data structures and / or operations of the hypervisor and the super manager according to the incremental decryption and integrity verification process.

[0053] In Figure 4A FIG., the relevant data structures of the guest address space 300, the hypervisor 400, and the super manager 410 are depicted. As shown, a call is made to the hypervisor 400 to run the secure operating system image. The hypervisor 400 receives the SE header 301 and temporarily stores the header for forwarding to the super manager 410. The super manager 410 is called by the hypervisor to start the unpacking process. The super manager extracts the image encryption key 306, the integrity content hash 307, and the integrity address hash 308 from the SE header and places them in its protected memory (e.g., register). As shown, in one or more embodiments, the super manager 410 also maintains registers with the current fine-tuning value 411, the current address 412 of the page to be decrypted, the current content hash 413, and the current address hash 414, as well as the cumulative content hash 415, the cumulative address hash 416, the last fine-tuning value 417, and the last page address 418.

[0054] As an example, the cumulative content hash 415 includes the hash value on the content of the memory pages that have been decrypted by the super manager so far, the cumulative address hash 416 contains the hash value on the addresses of the memory pages that have been decrypted so far, and the last fine-tuning value 417 and the last address 418 will contain the fine-tuning value and the address value last seen by the super manager. In one or more embodiments disclosed herein, this allows the super manager to ensure that page addresses and fine-tuning values are not reused. The fine-tuning value, the current address, the current content hash, and the current address hash are working registers that refer to the page currently being processed by the super manager 410.

[0055] The hypervisor 400 regains control and constructs a data structure 401 which, in one or more embodiments, includes a page address and a trim value pair 402 for each page address of the secure operating system image. An index 403 is provided by the hypervisor 400 for iterating over the memory pages of the image.

[0056] Figure 4B Describes the unpacking operation Figure 4A 4 shows a client address space, virtual machine monitor and hypervisor structure and process, wherein a page address-trim value pair 402 has been provided to the hypervisor 410 by the virtual machine monitor 400. This current pair has been placed into the current address and current trim registers, and a comparison is shown to ensure that the current address is greater than the last address and the current trim value is greater than the last trim value. Further, as part of the decryption of the content of a particular page in the client address space, the current content hash and the current address hash may be added to the cumulative content hash and cumulative address hash maintained by the hypervisor 410. As shown in FIG. Figure 4B As shown, some pages have been decrypted 304'. After decryption, in one or more embodiments, these pages are protected by the hypervisor 410 millicode, so once decrypted, the hypervisor 400 cannot access the protected pages. The hypervisor 410 can use, for example, a storage key facility to ensure that the hypervisor cannot access unencrypted pages of the secure operating system image.

[0057] Figure 4C Depicts the secure operating system image after all memory pages have been decrypted by the hypervisor (and protected by the hypervisor). Figure 4A and 4B Data structures and processes of the secure operating system image. The virtual machine monitor 400 uses the cumulative content hash value 415 and the cumulative address hash value 416 to make a final unpack call to the hypervisor to verify the integrity of the secure operating system image. As shown in the figure, the hypervisor is called to compare the integrity content hash received with the SE header with the ascertained cumulative content hash, and to compare the integrity address hash of the SE header with the obtained cumulative address hash. Assuming that each comparison is true, that is, the cumulative content hash value is equal to the integrity content hash value, and the cumulative address hash is equal to the integrity address hash, the integrity of the secure operating system image is confirmed, and the hypervisor can use, for example, the program status word (PSW) in the SE header to start the execution of the decrypted secure operating system image.

[0058] See also Figure 5A and 5B Further details related to one or more aspects of the present invention are described for one embodiment that facilitates secure processing within a computing environment.

[0059] Referring to Figure 5A , in one embodiment, a secure operating system image is incrementally decrypted (500), including for one of a plurality of pages of the secure operating system image: receiving a page address of the page and a tweak value used during encryption of the page (502); determining that the tweak value has not been previously used during decryption of another one of the plurality of pages of the secure operating system image (504); and using an image encryption key used during encryption of the page and the tweak value to decrypt the memory page content at the page address to facilitate obtaining the decrypted secure operating system image (506). Further, the integrity of the secure operating system image is verified (508), and based on verifying the integrity of the secure operating system image, execution of the decrypted secure operating system image is started (510).

[0060] In one or more embodiments, the incremental decryption and integrity verification are performed by a secure interface control of a computer system, the secure interface control being a trusted entity of the computer system, and the page address and the tweak value are received by the secure interface control from a hypervisor (512). Further, in one embodiment, the order of the page addresses among the plurality of page addresses is fixed (e.g., from low to high), and incrementally decrypting the secure operating system image includes determining that the page address is different from any previous page address of a previously decrypted page among the plurality of pages of the secure operating system image (514).

[0061] In one or more implementations, incrementally decrypting the secure operating system image further includes determining that the tweak value is different from a previous tweak value used during decryption of a previously decrypted page among the plurality of pages of the secure operating system image (516).

[0062] As another example, verifying integrity includes partially employing a cumulative content hash obtained using the memory page content of the plurality of pages and a cumulative address hash obtained using the page addresses of the plurality of pages (518). For example, as Figure 5B shown, verifying the integrity of the secure operating system image may include comparing the cumulative content hash with an integrity content hash received by the secure interface control from the hypervisor, and comparing the cumulative address hash with an integrity address hash received by the secure interface control from the hypervisor (520).

[0063] In one or more embodiments, the process includes extracting an image encryption key, as well as integrity content and address hashes (522), from metadata received from a hypervisor by a secure interface control. In a specific example, the secure interface control includes hardware and / or firmware elements of a computer system, and a secure operating system image operates as a secure guest operating system within a computing environment (524). As an example, a private key - public key pair can be associated with the computer system, where the private key is known only to the secure interface control and is inaccessible to software running on the computer system, and where the public key is wrapped by the owner of the secure operating system image for generating an image encryption key for encrypting the secure operating system image and for storing the wrapped image encryption key in a metadata structure transmitted to the secure interface control (526). Further, the secure interface control can receive the metadata structure along with a call from the hypervisor, the metadata structure further including integrity hash values used in verifying the integrity of the secure operating system image (528).

[0064] Other variations and embodiments are possible.

[0065] Aspects of the present invention can be used by many types of computing environments. See Figure 6A Another embodiment that describes a computing environment incorporating and using one or more aspects of the present invention. In this example, computing environment 10 includes, for example, a native central processing unit (CPU) 12, a memory 14, and one or more input / output devices and / or interfaces 16 that are coupled to each other via, for example, one or more buses 18 and / or other connections. As an example, computing environment 10 can include a processor provided by International Business Machines Corporation of Armonk, New York; an HP Superdome with an Intel Itanium II processor, provided by Hewlett Packard Co., Palo Alto, California; and / or other machines based on architectures provided by International Business Machines Corporation, Hewlett Packard, Intel Corporation, Oracle, or other companies. IBM, z / Architecture, IBM Z, z / OS, PR / SM, and PowerPC are trademarks or registered trademarks of International Business Machines Corporation in at least one jurisdiction. Intel and Itanium are trademarks or registered trademarks of Intel Corporation or its subsidiaries in the United States and other countries.

[0066] The native central processing unit 12 includes one or more native registers 20, such as one or more general - purpose registers and / or one or more special - purpose registers used during processing within the environment. These registers include information representing the state of the environment at any particular point in time.

[0067] In addition, the central processing unit 12 of the present machine executes instructions and code stored in the memory 14. In a specific example, the central processing unit executes emulator code 22 stored in the memory 14. This code enables a computing environment configured in one architecture to simulate another architecture. For example, the emulator code 22 allows a machine based on an architecture other than the z / Architecture hardware architecture (such as a PowerPC processor, an HP Superdome server, or others) to simulate the z / Architecture hardware architecture and execute software and instructions developed based on the z / Architecture hardware architecture.

[0068] Refer to Figure 6B for further details regarding the emulator code 22. The client instructions 30 stored in the memory 14 include software instructions (e.g., related to machine instructions) developed to execute in an architecture different from the architecture of the native CPU 12. For example, the client instructions 30 may be designed to execute on a processor based on the z / Architecture hardware architecture but instead are emulated on the native CPU 12, which may be, for example, an Intel Itanium II processor. In one example, the emulator code 22 includes an instruction fetch routine 32 to obtain one or more client instructions 30 from the memory 14 and optionally provide local buffering for the obtained instructions. It further includes an instruction translation routine 34 to determine the type of the obtained client instruction and translate the client instruction into one or more corresponding native instructions 36. This translation includes, for example, identifying the function to be performed by the client instruction and selecting native instructions to perform the function.

[0069] Further, the emulator code 22 includes an emulation control routine 40 to cause the native instructions to be executed. The emulation control routine 40 may cause the native CPU 12 to execute a routine of native instructions that emulates one or more previously obtained client instructions, and at the end of this execution, return control to the instruction fetch routine to simulate the obtaining of the next client instruction or set of client instructions. The execution of the native instructions 36 may include loading data from the memory 14 into registers; storing data from the registers back to the memory; or performing some type of arithmetic or logical operation, as determined by the translation routine.

[0070] Each routine, for example, is implemented in software that is stored in memory and executed by a native central processing unit 12. In other examples, one or more of the routines or operations are implemented in firmware, hardware, software, or some combination thereof. Registers 20 of the native CPU can be used or the registers of the emulated processor can be emulated by using locations in memory 14. In an embodiment, the client instructions 30, the native instructions 36, and the emulator code 22 can reside in the same memory or can be distributed among different memory devices.

[0071] The computing environments described above are only examples of computing environments that can be used. Other environments can be used, including but not limited to non-partitioned environments, partitioned environments, and / or emulated environments; embodiments are not limited to any one environment.

[0072] Each computing environment can be configured to include one or more aspects of the present invention. For example, according to one or more aspects of the present invention, each is configured to provide overflow handling.

[0073] One or more aspects relate to cloud computing.

[0074] It should be understood that although this disclosure includes a detailed description of cloud computing, the implementation of the teachings recited herein is not limited to a cloud computing environment. Instead, embodiments of the present invention can be implemented in conjunction with any other type of computing environment now known or later developed.

[0075] Cloud computing is a service delivery model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with the service provider. The cloud model can include at least five characteristics, at least three service models, and at least four deployment models.

[0076] The characteristics are as follows:

[0077] On-demand self-service: Cloud consumers can unilaterally and automatically provision computing capabilities, such as server time and network storage, as needed, without human interaction with the service provider.

[0078] Broad network access: Capabilities are provided over a network and accessed through standard mechanisms that facilitate use by heterogeneous thin client or thick client platforms (e.g., mobile phones, laptop computers, and PDAs).

[0079] Resource pooling: The provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, and different physical and virtual resources are dynamically allocated and reallocated as needed. There is a meaning of location independence because consumers generally have no control or knowledge of the exact location of the provided resources, but may be able to specify a location at a higher level of abstraction (e.g., country, state, or data center).

[0080] Rapid elasticity: Functions can be configured quickly and elastically, automatically scaling out rapidly in some cases and quickly releasing to scale in rapidly. To consumers, the functions available for configuration generally appear to be infinite and can be purchased in any quantity at any time.

[0081] Measured service: The cloud system automatically controls and optimizes resource use by leveraging a metering function at some level of abstraction appropriate to the service type (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both the provider and the consumer of the used service.

[0082] The service models are as follows:

[0083] Software as a Service (SaaS): The function provided to consumers is to use the provider's applications running on the cloud infrastructure. These applications can be accessed from different client devices through a thin client interface such as a web browser (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application functions, with the possible exception of limited user-specific application configuration settings.

[0084] Platform as a Service (PaaS): The function provided to consumers is to deploy applications created or acquired by consumers on the cloud infrastructure, where the applications are created using programming languages and tools supported by the provider. Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, or storage, but have control over the deployed applications and possibly the application hosting environment configuration.

[0085] Infrastructure as a Service (IaaS): The function provided to consumers is to provide processing, storage, networking, and other basic computing resources that consumers can deploy and run any software that may include operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but have control over the operating systems, storage, deployed applications, and possibly limited control over selected networking components (e.g., host firewalls).

[0086] The deployment models are as follows:

[0087] Private Cloud: The cloud infrastructure is for the exclusive use of an organization's operations. It can be managed by the organization or a third party and can exist either on - premise or off - premise.

[0088] Community Cloud: The cloud infrastructure is shared by multiple organizations and supports a specific community with common concerns (e.g., tasks, security requirements, policies, and compliance considerations). It can be managed by the organization or a third party and can exist either on - premise or off - premise.

[0089] Public Cloud: The cloud infrastructure is available to the general public or a large industry group and is owned by an organization that sells cloud services.

[0090] Hybrid Cloud: The cloud infrastructure is composed of two or more clouds (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technologies that enable data and application portability (e.g., cloud bursting for load balancing between clouds).

[0091] The cloud computing environment is service - oriented, emphasizing statelessness, low coupling, modularity, and semantic interoperability. The core of cloud computing is an infrastructure that includes a network of interconnected nodes.

[0092] Now refer to Figure 7 , which depicts an illustrative cloud computing environment 50. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 52, and local computing devices used by cloud consumers, such as a personal digital assistant (PDA) or cellular phone 54A, desktop computer 54B, laptop computer 54C, and / or in - vehicle computer system 54N, can communicate with the cloud computing nodes 52. The nodes 52 can communicate with each other. They can be physically or virtually grouped (not shown) in one or more networks, such as in the private cloud, community cloud, public cloud, or hybrid cloud or a combination thereof as described above. This allows the cloud computing environment 50 to provide infrastructure, platform, and / or software as a service, and cloud consumers do not need to maintain resources on their local computing devices. It should be understood that Figure 7 the types of computing devices 54A - N shown in

[0093] Now refer to Figure 8 , which shows a set of functional abstraction layers provided by the cloud computing environment 50 ( Figure 7 ). It should be understood in advance that Figure 8 the components, layers, and functions shown in

[0094] The hardware and software layer 60 includes hardware and software components. Examples of the hardware components include: a host 61; a server 62 based on a RISC (Reduced Instruction Set Computer) architecture; a server 63; a blade server 64; a storage 65; and network and networking components 66. In some embodiments, the software components include network application server software 67 and database software 68.

[0095] The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities can be provided: a virtual server 71; a virtual storage 72; a virtual network 73, including a virtual private network; virtual applications and operating systems 74; and a virtual client 75.

[0096] In one example, the management layer 80 can provide the functions described below. Resource provisioning 81 provides for the dynamic acquisition of computing resources and other resources for performing tasks within the cloud computing environment. Metering and pricing 82 provides cost tracking when resources are utilized within the cloud computing environment and bills or invoices for the consumption of these resources. In one example, these resources can include application software licenses. Security provides authentication for cloud consumers and tasks, as well as protection for data and other resources. The user portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 provides cloud computing resource allocation and management such that the required service levels are met. Service level agreement (SLA) planning and fulfillment 85 provides for the pre-arrangement and procurement of cloud computing resources for future requirements of cloud computing resources as expected under the SLA.

[0097] The workload layer 90 provides examples of functions that can utilize the cloud computing environment. Examples of workloads and functions that can be provided from this layer include: maps and navigation 91; software development and lifecycle management 92; virtual classroom education delivery 93; data analysis processing 94; transaction processing 95; and security interface control (supervisor) processing 96.

[0098] The present invention can be a system, method, and / or computer program product at any possible level of integrated technical detail. The computer program product can include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to execute aspects of the present invention.

[0099] A computer-readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer-readable storage medium can be, for example but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer-readable storage medium includes the following: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device (such as a punched card or raised structures in grooves having instructions recorded thereon), and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be construed as a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.

[0100] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device, or downloaded to an external computer or an external storage device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network). The network can include a copper transmission cable, an optical transmission fiber, a wireless transmission, a router, a firewall, a switch, a gateway computer, and / or an edge server. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the corresponding computing / processing device.

[0101] The computer-readable program instructions for performing the operations of the present technical solution may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, configuration data of an integrated circuit, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network (including a local area network (LAN) or a wide area network (WAN)), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, an electronic circuit (including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA)) may execute the computer-readable program instructions by using the state information of the computer-readable program instructions to personalize the electronic circuit so as to perform various aspects of the present invention.

[0102] Aspects of the present technical solution are described herein with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the technical solution. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.

[0103] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine that, when executed by the processor of the computer or other programmable data processing device, creates a device for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, a programmable data processing device, and / or other devices that operate in a specific manner, such that the computer-readable storage medium having the instructions stored therein includes an article of manufacture that includes instructions for implementing various aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.

[0104] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices that enable a series of operational steps to be performed on a computer, other programmable apparatus, or other device to produce a computer-implemented process such that the instructions executed on the computer, other programmable apparatus, or other device implement the functions and actions specified in one or more blocks of the flowchart and / or block diagram.

[0105] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present technical solution. To this end, each block in the flowchart or block diagram may represent a module, segment, or portion of an instruction, which includes one or more executable instructions for implementing the specified logical function. In some alternative embodiments, the functions marked in the block may not occur in the order marked in the figure. For example, depending on the functions involved, two consecutive blocks shown may actually be executed substantially simultaneously, or these blocks may sometimes be executed in the reverse order. It will also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a system based on dedicated hardware that performs the specified functions or actions or executes a combination of dedicated hardware and computer instructions.

[0106] In addition to the above, one or more aspects such as providing, offering, deploying, managing, servicing, etc. may be provided by a service provider that provides customer environment management. For example, the service provider may create, maintain, support computer code and / or execute one or more aspects of the computer infrastructure for one or more customers. In return, the service provider may receive payment from the customer according to a subscription and / or fee agreement, for example. Additionally, or alternatively, the service provider may receive payment from the sale of advertising content to one or more third parties.

[0107] In one aspect, an application may be deployed to execute one or more embodiments. As an example, the deployment of an application includes providing a computer infrastructure operable to execute one or more embodiments.

[0108] As another aspect, a computing infrastructure may be deployed, including integrating computer-readable code into a computing system, wherein the code combined with the computing system is capable of executing one or more embodiments.

[0109] As yet another aspect, a process for integrating a computing infrastructure may be provided, which includes integrating computer-readable code into a computer system. The computer system includes a computer-readable medium, wherein the computer medium includes one or more embodiments. The code combined with the computer system is capable of executing one or more embodiments.

[0110] Although the various embodiments are described above, these are merely examples. For example, computing environments of other architectures can be used to incorporate and use one or more embodiments. Additionally, different instructions or operations can be used. Further, different types of indicators can be specified. Many variations are possible.

[0111] In addition, other types of computing environments can also benefit from and use them. For example, a data processing system suitable for storing and / or executing program code is available, which includes at least two processors directly or indirectly coupled to a memory element via a system bus. The memory elements include, for example, local memory, mass storage, and cache memory used during actual execution of the program code, which provides temporary storage for at least some of the program code to reduce the number of times code must be retrieved from mass storage during execution.

[0112] Input / output or I / O devices (including but not limited to keyboards, displays, pointing devices, DASD, tapes, CDs, DVDs, thumb drives, and other storage media, etc.) can be coupled to the system directly or via a plug-in I / O controller. A network adapter can also be coupled to the system to enable the data processing system to be coupled to other data processing systems or remote printers or storage devices via an intervening private or public network. Modems, cable modems, and Ethernet cards are just a few of the available network adapters. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used herein, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that when the terms "comprises" and / or "comprising" are used in this specification, they specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0113] The corresponding structures, materials, acts, and equivalents of all apparatus or steps plus function elements, if any, in the following claims are intended to include any structure, material, or act for performing the function in conjunction with other claim elements of the specific claim. The description of one or more embodiments has been presented for purposes of illustration and description, but is not intended to be exhaustive or limited to the disclosed forms. Many modifications and variations will be apparent to those of ordinary skill in the art. The selection and description of the embodiments were chosen to best explain the various aspects and practical applications such that those of ordinary skill in the art can understand the various embodiments with different modifications suitable for the particular uses contemplated.

Claims

1. A computer system for facilitating secure processing within a computing environment, the computer system comprising: A memory; A processor coupled to the memory, wherein the computer system is configured to execute a method, the method comprising: Incrementally decrypting a secure operating system image, including one of a plurality of pages of the secure operating system image: Receiving a page address of the page and a tweak value used during encryption of the page; Determining that the tweak value has not been previously used during decryption of another one of the plurality of pages of the secure operating system image; and Using an image encryption key used during encryption of the page and the tweak value to decrypt the memory page content at the page address to facilitate obtaining a decrypted secure operating system image; Receiving an integrity content hash of the secure operating system image content and an integrity address hash of the secure operating system image address; Verifying the integrity of the secure operating system image, wherein verifying the integrity of the secure operating system image includes: comparing a cumulative content hash obtained using the memory page content of the plurality of pages with the received integrity content hash, and comparing a cumulative address hash obtained using the page addresses of the plurality of pages with the received integrity address hash; and Based on verifying the integrity of the secure operating system image, starting to execute the decrypted secure operating system image.

2. The computer system according to claim 1, wherein Incremental decryption and integrity verification are performed by a secure interface control of the computer system, the secure interface control being a trusted entity of the computer system, and the page address and the tweak value are received by the secure interface control from a hypervisor.

3. The computer system according to claim 2, wherein, The page addresses of the plurality of pages have a fixed order, and incrementally decrypting the secure operating system image includes determining that the page address is different from any previous page address of a previously decrypted page of the plurality of pages of the secure operating system image.

4. The computer system according to claim 3, wherein, Incrementally decrypting the secure operating system image further includes determining that the tweak value is different from a previous tweak value used during decryption of a previously decrypted page of the plurality of pages of the secure operating system image.

5. The computer system according to claim 2, further comprising: The image encryption key and the integrity content hash and integrity address hash are extracted by the secure interface control from metadata received from the hypervisor.

6. The computer system according to claim 2, wherein The secure interface control includes one or more elements of the computer system, the one or more elements being selected from the group consisting of hardware elements and firmware elements, and the secure operating system image runs as a secure guest operating system within the computing environment.

7. The computer system according to claim 2, wherein, Associating a private key - public key pair with the computer system, the private key being known only to the secure interface control and inaccessible to software running on the computer system, and wherein the public key is used by the owner of the secure operating system image to generate key agreement data for securely transmitting an image encryption key for encrypting the secure operating system image with the secure interface control, and storing the key agreement data in a metadata structure.

8. The computer system according to claim 7, further comprising: The secure interface control receives the metadata structure along with a call from the hypervisor, the metadata structure further including an integrity hash value used during verification of the integrity of the secure operating system image.

9. A computer program product, comprising: A computer-readable storage medium, readable by a processing circuit and storing instructions for performing a method, the method comprising: Incrementally decrypting a secure operating system image, including a page among a plurality of pages of the secure operating system image: Receiving a page address of the page and a tweak value used during encryption of the page; Determining that the tweak value has not been used previously during decryption of another page among the plurality of pages of the secure operating system image; and Using an image encryption key used during encryption of the page and the tweak value to decrypt memory page content at the page address to facilitate obtaining a decrypted secure operating system image; Receiving an integrity content hash of the secure operating system image content and an integrity address hash of the secure operating system image address; Verifying the integrity of the secure operating system image Receiving an integrity content hash of the secure operating system image content and an integrity address hash of the secure operating system image address; and Based on verifying the integrity of the secure operating system image, starting to execute the decrypted secure operating system image.

10. The computer program product according to claim 9, wherein, The page addresses of the plurality of pages have a fixed order, and incrementally decrypting the secure operating system image includes determining that the page address is different from any previous page address of a previously decrypted page among the plurality of pages of the secure operating system image.

11. The computer program product according to claim 10, wherein, Incrementally decrypting the secure operating system further includes: determining that the tweak value is different from a previous tweak value used during decryption of a previously decrypted page among the plurality of pages of the secure operating system image.

12. A computer-implemented method, comprising: Incrementally decrypting a secure operating system image, including a page among a plurality of pages of the secure operating system image: Receiving a page address of the page and a tweak value used during encryption of the page; Determining that the tweak value has not been used previously during decryption of another page among the plurality of pages of the secure operating system image; and Using an image encryption key used during encryption of the page and the tweak value to decrypt memory page content at the page address to facilitate obtaining a decrypted secure operating system image; Receiving an integrity content hash of the secure operating system image content and an integrity address hash of the secure operating system image address; Verifying the integrity of the secure operating system image, wherein verifying the integrity of the secure operating system image includes: comparing a cumulative content hash obtained using the memory page content of the plurality of pages with the received integrity content hash, and comparing a cumulative address hash obtained using the page addresses of the plurality of pages with the received integrity address hash; and Based on verifying the integrity of the secure operating system image, starting to execute the decrypted secure operating system image.

13. The computer-implemented method according to claim 12, wherein, Incremental decryption and integrity verification are performed by a security interface control of a computer system, the security interface control being a trusted entity of the computer system, and the page address and the tweak value are received by the security interface control from a hypervisor.

14. The computer-implemented method according to claim 13, wherein the page addresses of the plurality of pages have a fixed order, and the incremental decryption of the secure operating system image includes determining that the page address is different from any previous page address of a previously decrypted page among the plurality of pages of the secure operating system image; and the incremental decryption of the secure operating system image further includes determining that the fine-tuning value is different from a previous fine-tuning value used during the decryption of a previously decrypted page among the plurality of pages of the secure operating system image.

Citation Information

Patent Citations

  • Secure public cloud with protected guest-verified host control

    CN108509250A

  • Secure virtual machine bootstrap in untrusted cloud infrastructures

    US20110302400A1