Hardware enforced security for service grids

By introducing hardware-enforced security mechanisms into the service mesh and leveraging the synchronization mechanisms between global and local servers, the problem of plaintext exposure of private keys in cloud-native environments is solved, thus achieving security and privacy protection for the service mesh.

CN121241540APending Publication Date: 2025-12-30INTEL CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380097032.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-09-28
Filing Date
2023-10-23
Publication Date
2025-12-30

AI Technical Summary

Technical Problem

In existing service mesh systems operating in distributed third-party hosted environments, private keys are easily exposed in plaintext, and the lack of effective hardware-enforced security mechanisms results in insufficient security.

Method used

By combining confidential computing technology and introducing hardware-enforced security mechanisms into the service mesh, programmable circuits and hardware logic circuits are used to protect private keys, ensuring that they are not exposed in plaintext in the cloud-native environment. A synchronization mechanism between global servers and local servers is adopted to achieve secure transmission and storage of private keys.

Benefits of technology

It effectively protects the private keys in the gateway and proxy components of the service mesh, preventing them from being exposed in plaintext in a distributed third-party hosting environment, thereby improving the security and privacy protection capabilities of the service mesh.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121241540A_ABST
    Figure CN121241540A_ABST
Patent Text Reader

Abstract

Systems, apparatus, articles of manufacture, and methods for providing hardware enforcement security for a service grid are disclosed. An example first server for a service grid, disclosed herein, to provide hardware-enforced security for the service grid, includes programmable circuitry, the programmable circuitry is to implement at least one of instantiating the machine-readable instructions or executing the machine-readable instructions to detect a second server of the service grid, store a public key of the second server in the first enclave, and add the second server to the service grid after attestation of the second enclave is obtained.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related applications

[0002] This patent application claims the benefit of U.S. Patent Application No. 18 / 477,370, filed September 28, 2023, which is a continuation-in-part of International Application No. PCT / CN2023 / 098861, filed June 7, 2023. Both U.S. Patent Application No. 18 / 477,370 and International Application No. PCT / CN2023 / 098861 are incorporated herein by reference in their entirety. Priority to both U.S. Patent Application No. 18 / 477,370 and International Application No. PCT / CN2023 / 098861 is claimed. Technical Field

[0003] This disclosure generally relates to networks, and more specifically, to hardware-enforced security for service meshes. Background Technology

[0004] In recent years, cloud-native programming has rapidly emerged in the service deployment paradigm. Cloud-native programming is a software approach to building, deploying, and managing modern applications in a cloud computing environment. Modern applications are typically designed as a distributed collection of microservices, each group of microservices performing some discrete business function. A service mesh is a software infrastructure layer added to an application to facilitate service-to-service communication between services or microservices. A service mesh consists of a data plane and a control plane. The data plane supports communication between services. The service mesh can leverage proxies to route network traffic for the application. For example, a proxy can be deployed with each initiating service. The proxy is abstracted from the application and manages network communication for the application within the service mesh. The control plane takes the configuration required by the user and dynamically programs the proxy server to update the proxy server as rules or the environment change. The service mesh also includes gateways that receive incoming or outgoing HTTP / TCP connections at the service mesh edge. Gateways have entry points that provide incoming traffic management for applications running within the service mesh. Gateways also have exit points that provide outgoing traffic management for the service mesh. Attached Figure Description

[0005] Figure 1A and Figure 1B A block diagram is shown illustrating an exemplary environment in which an exemplary server operates to provide security for a service mesh gateway in a multi-tenant edge deployment.

[0006] Figure 2 yes Figure 1A A block diagram illustrating an exemplary implementation of an exemplary first server.

[0007] Figure 3 yes Figure 1BA block diagram illustrating an exemplary implementation of an exemplary second server.

[0008] Figure 4 This indicates that it can be executed, instantiated, and / or implemented by an exemplary programmable circuit. Figure 2 The flowchart illustrates exemplary machine-readable instructions and / or exemplary operations of an exemplary first server.

[0009] Figure 5 This indicates that it can be executed, instantiated, and / or implemented by an exemplary programmable circuit. Figure 3 A flowchart illustrating exemplary machine-readable instructions and / or exemplary operations of an exemplary second server is shown.

[0010] Figure 6 This indicates that it can be executed, instantiated, and / or implemented by an exemplary programmable circuit. Figure 2 The flowchart shown illustrates exemplary machine-readable instructions and / or exemplary operations for synchronizing a private key from the first server to a second server using an exemplary first server.

[0011] Figure 7 This indicates that it can be executed, instantiated, and / or implemented by an exemplary programmable circuit. Figure 3 The flowchart illustrates an exemplary second server for synchronizing a private key from a first server to the second server, and includes exemplary machine-readable instructions and / or exemplary operations.

[0012] Figure 8 This indicates that it can be executed, instantiated, and / or implemented by an exemplary programmable circuit. Figure 3 The flowchart shown illustrates exemplary machine-readable instructions and / or exemplary operations of an exemplary second server delivering a private key from the second server to a gateway agent.

[0013] Figure 9 This indicates that it can be executed, instantiated, and / or implemented by an exemplary programmable circuit. Figure 3 The flowchart shown illustrates an exemplary second server for generating a private key locally, including exemplary machine-readable instructions and / or exemplary operations.

[0014] Figure 10 It is used to implement Figure 1A and Figure 2 The example shown is an interactive diagram of an exemplary workflow in which an administrator uploads a key to the first server.

[0015] Figure 11 It is to achieve Figure 1A and Figure 2 The exemplary first server shown and Figure 1B and Figure 3The diagram illustrates an exemplary workflow for synchronizing a key from a first server to a second server.

[0016] Figure 12 It is to realize Figure 1 and Figure 3 The diagram illustrates an exemplary workflow of delivering a key from the second server to a gateway agent.

[0017] Figure 13 This illustrates an embodiment for use with a cloud hardware security module adapter, according to some implementations. Figure 1A and Figure 2 The diagram shows an exemplary first server.

[0018] Figure 14 This illustrates the use of security gateways and... Figure 3 The exemplary second server multi-tenant 5G control plane deployment shown Figure 2 The diagram shows an exemplary first server.

[0019] Figure 15 This is a block diagram of an exemplary processing platform including programmable circuitry configured to execute, instantiate, and / or implement exemplary machine-readable instructions and / or perform... Figure 4 and Figure 6 The exemplary operation shown is used to implement Figure 2 The first server shown.

[0020] Figure 16 This is a block diagram of an exemplary processing platform including programmable circuitry configured to execute, instantiate, and / or implement. Figure 5 , Figure 7-9 The exemplary machine-readable instructions and / or execution shown Figure 5 , Figure 7-9 The exemplary operation shown is used to implement Figure 3 The second server shown.

[0021] Figure 17 yes Figure 15 The block diagram shows an example implementation of a programmable circuit.

[0022] Figure 18 yes Figure 15 A block diagram of another exemplary embodiment of the programmable circuit shown.

[0023] Figure 19 It is used to store software, instructions, and / or firmware (e.g., corresponding to...). Figures 4-9The diagram illustrates an example software / firmware / instruction distribution platform (e.g., one or more servers) that distributes exemplary machine-readable instructions to client devices associated with end users and / or consumers (e.g., for licensing, selling, and / or using), retailers (e.g., for selling, reselling, licensing, and / or sublicensing), and / or original equipment manufacturers (OEMs) (e.g., for inclusion in products to be distributed to, for example, retailers and / or other end users, such as direct purchase customers).

[0024] Generally, the same reference numerals will be used throughout the accompanying drawings and written description to refer to the same or similar parts. The drawings are not necessarily drawn to scale. Instead, the thickness of layers or regions may be enlarged in the drawings. Although the drawings show layers and regions with simple lines and boundaries, some or all of these lines and / or boundaries may be idealized. In reality, boundaries and / or lines may be unobservable, mixed, and / or irregular.

[0025] As used herein, unless otherwise stated, references to connection (e.g., attachment, coupling, joining, and engagement) may include intermediate members between elements referenced by the connection reference and / or relative movement between those elements. Therefore, a reference to connection does not necessarily imply that two elements are directly connected and / or in a fixed relationship with each other. As used herein, stating that any component is in “contact” with another component is defined as meaning that there is no intermediate member between the two components.

[0026] Unless otherwise expressly stated, descriptive terms such as “first,” “second,” “third,” etc., are used herein without any intention of inserting or otherwise indicating priority, physical order, arrangement in a list, and / or sorting, but solely as labels and / or arbitrary names to distinguish elements for ease of understanding of the disclosed instances. In some instances, the descriptive term “first” may be used to refer to an element in a particular embodiment, while the same element may be referred to in the claims by different descriptive terms (e.g., “second” or “third”). In such cases, it should be understood that such descriptive terms are used only to clearly identify those elements within the context of the discussion (e.g., within the claims), where elements may otherwise share the same name, for example.

[0027] As used herein, the phrase “communicate with” (including its variations) covers direct and / or indirect communication through one or more intermediate components, and does not require direct physical (e.g., wired) communication and / or continuous communication, but additionally includes selective communication at periodic intervals, scheduled intervals, non-periodic intervals and / or one-off events.

[0028] As used herein, “programmable circuit” is defined as including (i) one or more special-purpose circuits (e.g., application-specific integrated circuits (ASICs)) configured to perform specific operations and including one or more semiconductor-based logic devices (e.g., electrical hardware implemented by one or more transistors), and / or (ii) one or more general-purpose semiconductor-based circuits programmable with instructions to perform specific functions and / or operations and including one or more semiconductor-based logic devices (e.g., electrical hardware implemented by one or more transistors). Examples of programmable circuits include programmable microprocessors, such as a central processing unit (CPU) capable of executing first instructions to perform one or more operations and / or functions; a field-programmable gate array (FPGA) programmable with second instructions to configure and / or structure an FPGA to instantiate one or more operations and / or functions corresponding to the first instructions; a graphics processing unit (GPU) capable of executing first instructions to perform one or more operations and / or functions; a digital signal processor (DSP), XPU capable of executing first instructions to perform one or more operations and / or functions; a network processing unit (NPU) capable of executing first instructions to perform one or more operations and / or functions; one or more microcontrollers capable of executing first instructions to perform one or more operations and / or functions; and integrated circuits such as application-specific integrated circuits (ASICs). For example, an XPU can be implemented by a heterogeneous computing system that includes a variety of types of programmable circuits (e.g., one or more FPGAs, one or more CPUs, one or more GPUs, one or more NPUs, one or more DSPs, etc. and / or any combination thereof) and orchestration techniques (e.g., application programming interfaces (APIs)) that can assign computing tasks to any of the various types of programmable circuits that are suitable and available to perform the computing tasks.

[0029] As used herein, an integrated circuit is defined as one or more semiconductor packages containing one or more circuit elements such as transistors, capacitors, inductors, resistors, current paths, diodes, etc. For example, an integrated circuit can be implemented as one or more of ASICs, FPGAs, chips, microchips, programmable circuits, semiconductor substrates coupling multiple circuit elements, system-on-a-chip (SoC), etc. Detailed Implementation

[0030] Service mesh approaches can be applied to microservice-based systems to manage network communication between services. Some service mesh implementations utilize gateways to manage incoming and outgoing traffic to the service mesh. A service mesh can include an ingress point (e.g., an inlet) and / or an egress point (e.g., an egress). Ingress and egress gateways provide services to multiple tenants accessing services offered by the system. These ingress and egress points can be scalable to meet the needs of incoming business. In some instances, a proxy (e.g., an ENVOY proxy) can be used to implement the gateway. A proxy can serve as a communication bus for large microservice service mesh architectures and can provide fine-grained control over traffic entering and leaving the service mesh.

[0031] Tenants of the service mesh access its services through cloud-native application programming interfaces (APIs). Ingress and egress gateways are sensitive control points protecting the service mesh's entry points. Typically, users perform Transport Layer Security (TLS) termination on inbound traffic and TLS initiation on outbound traffic within the gateway. For example, the gateway can be secured for TLS handshakes using a private key and certificate bound to it.

[0032] The methods and apparatus disclosed herein improve the security architecture of service meshes by combining confidential computing with cloud-native service meshes. This combination creates technical information architecture (IA)-friendly software designs that, in some instances, enable the open-source use of confidential computing. Confidential computing is a cloud computing technology that isolates sensitive data during processing within a protected central processing unit (CPU) enclave or memory. This hardware-enforced security mechanism provides protection for sensitive data such as private keys. The methods and apparatus disclosed herein provide this hardware-enforced security mechanism for protecting gateway and / or proxy components of the service mesh. The hardware-enforced security mechanism ensures that private keys are not exposed in plaintext in distributed third-party hosted environments such as the Communication Service Provider (CoSP) edge, Secure Edge Service Access (SASE), enterprise edge, etc.

[0033] Figure 1A and Figure 1B This is a block diagram of an exemplary environment 100 in which an exemplary first server or global server 102 and a second server or local server 104 operate to protect keys in an ingress gateway circuit 106 and an egress gateway circuit 108. The exemplary environment 100 includes an exemplary control plane circuit 110 for managing and configuring proxy circuits 132-138 to route traffic, and an exemplary data plane circuit 112, which includes a set of intelligent proxies 132-138 (e.g., Envoy) deployed as sidecars and their interactions. The exemplary environment 100 also includes an exemplary control plane interface 114 shared between the control plane circuit 110 and the data plane circuit 112 for communication between them.

[0034] An exemplary control plane circuit 110 includes a global server 102 for protecting and / or ensuring the security of user private keys in a global server secure storage 116 (e.g., a secure enclave, a trusted platform module (TPM), etc.). The user private key is received from an administrator 170. The following describes the process in conjunction with... Figure 2 , Figure 4 and Figure 6 The exemplary global server 102 is described in more detail. The exemplary control plane circuitry 110 also includes a daemon 120 (e.g., A daemon (ISTIOD) is a computer program that runs as a background process to unify service mesh functions such as service discovery, configuration, and certificate generation. Daemon 120 includes a Certificate Authority 122 for managing keys and certificates, an authentication policy 124 for verifying user identity, and an authorization policy 126 for determining what information a client can access. Control plane circuitry 110 configures service mesh authentication and authorization settings, correctly routes traffic from proxies to services, and specifies settings on proxies, etc.

[0035] Exemplary data plane circuitry 112 includes a set of intelligent agents 132, 134, 136, and 138 deployed as sidecars. These exemplary agents centralize and control all network communication between microservices. Exemplary data plane circuitry 112 includes an exemplary ingress gateway circuitry 106 for routing incoming traffic to the service mesh, and an exemplary egress gateway circuitry 108 for routing outgoing traffic from the service mesh. Ingress gateway circuitry 106 includes a proxy body 140 that acts as an intermediary between daemon 120 and agent 132 (e.g., (Proxy). Exemplary proxy 140 helps each sidecar connect to the service mesh by securely passing configuration and secrets to proxy 132. Although proxy 140 is considered part of the control plane circuitry 110, proxy 140 operates on a per-pod basis.

[0036] A Pod is a group of one or more containers that share storage and networking, and a specification of how those containers run. A Pod is a service mesh (e.g., Konnect, HASHICORP Container-centric management software (e.g., AppMesh, etc.) Deployment. Container-centric management software deploys and operates containerized applications in the control plane circuit 110 of the service mesh.

[0037] The exemplary proxy 140 includes a local server 104 to protect the public-private key pair stored in the local server's secure storage 142. The following, in conjunction with... Figure 3 , 5The exemplary local server 104 is described in more detail in sections 7-9. The exemplary proxy 132 includes a proxy secure storage 150 for storing public-private key pairs, and a private key provider plug-in 152 can use the private key in the proxy secure storage 150 to perform encryption and decryption operations in the data plane circuitry 112.

[0038] Figure 2 yes Figure 1A The diagram shows an exemplary implementation of the first server 102, which is used for detection and registration. Figure 1B The second server 104 shown enables the first server 102 to securely synchronize the key pair to the second server 104 using a hardware-enforced security mechanism. An exemplary first server 102 is a credential server (e.g., a Secret Discovery Service (SDS) server, a global SDS server). For example, the credential server could implement... The gRPC (Gen Remote Procedure Call) service allows client and server applications to communicate transparently and develop connected systems. In some instances, the first server 102 can be another type of server. Figure 2 The exemplary first server 102 shown can be instantiated (e.g., instantiated, generated, materialized, implemented, etc.) by a programmable circuit, such as a central processing unit (CPU) that executes first instructions. Additionally or alternatively, Figure 2 The exemplary first server 102 shown can be instantiated (e.g., instantiated, generated, materialized, implemented, etc.) by (i) an application-specific integrated circuit (ASIC) and / or (ii) a field-programmable gate array (FPGA), which is constructed and / or configured to perform the operation corresponding to the first instruction in response to the execution of the second instruction. It should be understood that Figure 2 Some or all of the circuits shown can therefore be instantiated at the same or different times. Figure 2 Some or all of the circuits shown can be instantiated, for example, in one or more threads that execute concurrently and / or serially on the hardware. Furthermore, in some instances, Figure 2 Some or all of the circuits shown can be implemented by microprocessor circuits that execute instructions and / or FPGA circuits that perform operations to implement one or more virtual machines and / or containers.

[0039] Figure 2The exemplary first server 102 shown includes an exemplary local server monitoring circuit 202, an exemplary registration circuit 204, an exemplary annotated secret monitoring circuit 206, an exemplary credential generation circuit 208, an exemplary public / private key generation circuit 210, an exemplary proof customization resource (CR) controller circuit 212, an exemplary key decryption circuit 214, an exemplary key encryption circuit 216, an exemplary communication interface circuit 218, and an exemplary enclave 116. The exemplary enclave 116 stores data from administrator 170 (…). Figure 1A ) private key.

[0040] Figure 2 The exemplary first server or global server 102 shown is equipped with an exemplary local server monitoring circuit 202 to monitor the data plane circuit 112. Figure 1B The local server or the second server in ) 104 ( Figure 1B Global server 102 monitors broadcast messages and receives broadcast messages from local server 104 when local server 104 starts up. When global server 102 receives a broadcast message from local server 104, global server 102 determines that local server 104 exists.

[0041] In the illustrated example, registration circuit 204 registers the detected local server 104 with global server 102. When global server 102 receives a private key from administrator 170, registering local server 104 allows global server 102 to synchronize the private key to local server 104. Administrator 170 obtains the private key from users who want to access microservices in the service mesh system.

[0042] Figure 2 The exemplary first server 102 shown includes an exemplary annotated secret monitoring circuit 206 for monitoring annotated secrets. Annotated secrets are objects containing sensitive data (such as keys, passwords, or tokens) annotated with special flags. In the illustrated example, the annotated secret is a key carrying a private key ID, certificate chain, and / or CA certificate. Secret. Administrator 170 ( Figure 1A The secret is annotated with special identifiers such as "Intel-SGX". The annotated secret monitoring circuit 206 monitors the annotated secret.

[0043] If an annotated secret is detected, the exemplary credential generation circuit 208 generates a credential for remote authentication. Performing remote authentication ensures that two enclaves can securely collaborate, such as performing data exchange, communicating to conduct specific services, etc. When a secure enclave 116 ( Figure 1AWhen global server 102 receives a secret from administrator 170, global server 102 can prove to administrator 170 that global server 102 is running on a trusted platform capable of securely handling secrets. The process of proving a secure execution environment is sometimes referred to as proof. A credential is a platform-unique asymmetric proof key representing a digitally signed proof generated through the hardware and software configuration of a specific enclave. The credential serves as proof of the enclave's trustworthiness.

[0044] The exemplary public-private key generation circuit 210 generates a public-private key pair. The remote party uses the public key to verify credentials. The private key is used to sign the secure enclave 116.

[0045] An exemplary proof customization resource (CR) controller 212 creates proof customization resources. For example, a custom resource can be an extension of the K8 API. Proof customization resources are used in remote proofs on global server 102 to store and retrieve structured data related to remote proofs.

[0046] Figure 2 The exemplary first server 102 shown includes an exemplary key decryption circuit 214 for decrypting a user's private key from an administrator 170. While the decryption circuit 214 in the illustrated example applies a decryption algorithm, it may additionally or alternatively decrypt the user's private key and / or apply any other type of algorithm to access it. The decrypted user's private key is stored in a global server security enclave 116.

[0047] The exemplary key encryption circuit 216 encrypts the user's private key. The encrypted user's private key is synchronized to the local server 104. Although the encryption circuit 216 of the illustrated example applies an encryption algorithm, the encryption circuit 216 may additionally or alternatively encapsulate the user's private key and / or apply any other type of algorithm to encapsulate the user's private key.

[0048] The exemplary communication interface circuit 218 performs communication between the global server 102 and the local server 104. The global server 102 creates a custom resource associated with the synchronization request. The exemplary communication interface circuit 218 sends a synchronization request CR to the local server 104 before synchronizing the user's private key to the local server 104.

[0049] In some instances, the first server 102 includes means for monitoring a local server. For example, the means for monitoring may be implemented by a local server monitoring circuit 202. In some instances, the local server monitoring circuit 202 may be, for example... Figure 15 The exemplary programmable circuit 1512 shown is an instantiation of a programmable circuit. For example, the local server monitoring circuit 202 can be executed by, for example, at least by... Figure 4 Boxes 402 and 404 in the code implement those machine-executable instructions. Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the local server monitoring circuitry 202 may be instantiated by hardware logic circuitry, which may be configured and / or structured to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuitry 1800 is implemented. Additionally or alternatively, the local server monitoring circuitry 202 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the local server monitoring circuitry 202 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0050] In some instances, the first server 102 includes means for registering the server. For example, the means for registration may be implemented by registration circuitry 204. In some instances, registration circuitry 204 may be implemented by, for example... Figure 15 The exemplary programmable circuit 1512 shown can be instantiated as a programmable circuit. For example, the registration circuit 204 can be implemented by, for example, at least by... Figure 4 Box 406 in the middle implements those machine-executable instructions. Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the registration circuit 204 may be instantiated by hardware logic circuitry configured and / or constructed to perform operations corresponding to machine-readable instructions. Figure 18 The ASIC, XPU, or FPGA circuit 1800 shown is implemented. Additionally or alternatively, the registration circuit 204 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the registration circuit 204 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0051] In some instances, the first server 102 includes means for monitoring. For example, the means for monitoring may be implemented by annotated secret monitoring circuitry 206. In some instances, annotated secret monitoring circuitry 206 may be, for example... Figure 15The exemplary programmable circuit 1512 shown can be instantiated using programmable circuits such as this one. For example, the annotated secret monitoring circuit 206 can be executed by, for example, at least by... Figure 4 Box 408 in the middle implements those machine-executable instructions. Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the annotated secret monitoring circuit 206 can be instantiated by hardware logic circuitry configured and / or constructed to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is used for implementation. Additionally or alternatively, the annotated secret monitoring circuit 206 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the annotated secret monitoring circuit 206 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0052] In some instances, the first server 102 includes means for generating vouchers. For example, the means for generating vouchers may be implemented by voucher generation circuitry 208. In some instances, voucher generation circuitry 208 may be, for example... Figure 15 The exemplary programmable circuit 1512 shown is an instantiation of a programmable circuit. For example, the credential generation circuit 208 can be instantiated by, for example, at least by... Figure 4 Box 414 in the middle implements those machine-executable instructions. Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the credential generation circuit 208 may be instantiated by hardware logic circuitry configured and / or structured to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the credential generation circuit 208 may be instantiated by any other combination of hardware, software, and / or firmware. For example, the credential generation circuit 208 may be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0053] In some instances, the first server 102 includes means for generating key pairs. For example, the means for generating key pairs may be implemented by a public-private key generation circuit 210. In some instances, the public-private key generation circuit 210 may be, for example... Figure 15 The exemplary programmable circuit 1512 shown is an instantiation of a programmable circuit. For example, the public-private key generation circuit 210 can be instantiated by, for example, at least by, Figure 4 Box 414 in the middle implements those machine-executable instructions. Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the public-private key generation circuit 210 may be instantiated by hardware logic circuitry configured and / or constructed to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the public-private key generation circuit 210 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the public-private key generation circuit 210 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0054] In some instances, the first server 102 includes a unit for generating proof CRs. For example, the means for generating proof CRs may be implemented by proof customization resource (CR) controller circuitry 212. In some instances, the proof CR controller circuitry 212 may be, for example... Figure 15 The exemplary programmable circuit 1512 shown can be instantiated using programmable circuits such as this one. For example, it can be demonstrated that the CR controller circuit 212 can be executed by, for example, at least by... Figure 4 Box 412 in the middle implements those machine-executable instructions. Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, it is demonstrated that the CR controller circuit 212 can be instantiated by hardware logic circuitry configured and / or constructed to perform operations corresponding to machine-readable instructions. Figure 18The ASIC, XPU, or FPGA circuit 1800 shown is used for implementation. Additionally or alternatively, it is demonstrated that the CR controller circuit 212 can be instantiated by any other combination of hardware, software, and / or firmware. For example, it is demonstrated that the CR controller circuit 212 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0055] In some instances, the first server 102 includes means for decryption. For example, the means for decryption may be implemented by a key decryption circuit 214. In some instances, the key decryption circuit 214 may be, for example... Figure 15 The exemplary programmable circuit 1512 shown is an example of a programmable circuit instantiated from such a circuit. For example, the key decryption circuit 214 can be executed by, for example, at least by... Figure 4 Box 416 in the middle implements those machine-executable instructions. Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the key decryption circuit 214 may be instantiated by hardware logic circuitry, which may be configured and / or constructed to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the key decryption circuit 214 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the key decryption circuit 214 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0056] In some instances, the first server 102 includes means for encryption. For example, the means for encryption may be implemented by a key encryption circuit 216. In some instances, the key encryption circuit 216 may be, for example... Figure 15 The exemplary programmable circuit 1512 shown is an instantiation of a programmable circuit. For example, the key encryption circuit 216 can be instantiated by, for example, at least by... Figure 6 The machine-executable instructions implemented in box 608 are... Figure 17The exemplary microprocessor 1700 shown is instantiated. In some instances, the key encryption circuitry 216 may be instantiated by hardware logic circuitry configured and / or constructed to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the key encryption circuit 216 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the key encryption circuit 216 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0057] In some instances, the first server 102 includes means for sending synchronization requests. For example, the means for sending synchronization requests may be implemented by communication interface circuitry 218. In some instances, communication interface circuitry 218 may be, for example... Figure 15 The exemplary programmable circuit 1512 shown can be instantiated as a programmable circuit. For example, the communication interface circuit 218 can be implemented by, for example, at least Figure 6 The machine-executable instructions implemented in boxes 604 and 612 are... Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the communication interface circuitry 218 may be instantiated by hardware logic circuitry configured and / or structured to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the communication interface circuit 218 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the communication interface circuit 218 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0058] Although Figure 2 The implementation is shown in the figure. Figure 1A The first server 102 shown is an exemplary configuration, but... Figure 2One or more of the elements, processes, and / or devices shown may be combined, divided, rearranged, omitted, eliminated, and / or implemented in any other way. Furthermore, Figure 2 The exemplary local server monitoring circuit 202, exemplary registration circuit 204, exemplary annotated secret monitoring circuit 206, exemplary credential generation circuit 208, exemplary public key / private key generation circuit 210, exemplary proof custom resource (CR) controller circuit 212, exemplary key decryption circuit 214, exemplary key encryption circuit 216, exemplary communication interface circuit 218, and / or more generally, the exemplary first server 102 may be implemented by separate hardware or by hardware combining software and / or firmware. Therefore, for example, the exemplary local server monitoring circuit 202, the exemplary registration circuit 204, the exemplary annotated secret monitoring circuit 206, the exemplary credential generation circuit 208, the exemplary public key / private key generation circuit 210, the exemplary proof customization resource (CR) controller circuit 212, the exemplary key decryption circuit 214, the exemplary key encryption circuit 216, the exemplary communication interface circuit 218, and / or more generally, any one of the exemplary first server 102 can be implemented by programmable circuitry combined with machine-readable instructions (e.g., firmware or software), processor circuitry, analog circuitry, digital circuitry, logic circuitry, programmable processors, graphics processing units (GPUs), digital signal processors (DSPs), ASICs, programmable logic devices (PLDs), and / or field-programmable logic devices (FPLDs). Furthermore, Figure 2 The exemplary first server 102 shown may include, in addition to Figure 2 The elements, processes and / or equipment shown are outside of or replace those shown. Figure 2 The elements, processes, and / or devices shown may include more than one of any or all of the elements, processes, and devices shown.

[0059] Figure 3 It is used to synchronize from Figure 1A The first server 102 shows the user's private key and delivers the user's private key to the gateway agent 132. Figure 1B )of Figure 1B A block diagram illustrating an example implementation of a second server or local server 104. Figure 3 The exemplary second server 104 shown can be instantiated (e.g., instantiated, generated, materialized, implemented, etc.) by programmable circuitry, such as a central processing unit (CPU) that executes the first instructions. Additionally or alternatively, Figure 3The exemplary second server 104 shown can be instantiated (e.g., instantiated, generated, materialized, implemented, etc.) by (i) an application-specific integrated circuit (ASIC) and / or (ii) a field-programmable gate array (FPGA), which is constructed and / or configured to perform the operation corresponding to the first instruction in response to the execution of the second instruction. It should be understood that, therefore, Figure 3 Some or all of the circuits shown can be instantiated at the same or different times. Figure 3 Some or all of the circuits shown can be instantiated, for example, in one or more threads that execute in parallel and / or serially on hardware. Furthermore, in some instances, Figure 3 Some or all of the circuits shown can be implemented by microprocessor circuits that execute instructions and / or FPGA circuits that perform operations to implement one or more virtual machines and / or containers.

[0060] Figure 3 The exemplary second server 104 shown includes an exemplary synchronization request monitoring circuit 302, an exemplary credential generation circuit 304, an exemplary public / private key generation circuit 306, an exemplary certificate signing request (CSR) circuit 307, an exemplary proof customization resource (CR) controller circuit 308, an exemplary communication interface circuit 310, an exemplary key decryption circuit 312, an example enclave 142, an exemplary key encryption circuit 316, and an exemplary token file generation circuit 318. The example enclave 142 is used to store data from the first server 102 (…). Figure 1A ) private key.

[0061] Figure 3 The exemplary second server or local server 104 shown is equipped with an exemplary synchronization request monitoring circuit 302 for monitoring synchronization requests (syncReq) from the first server or global server 102. When a new user private key is uploaded to the global server 102, the new user private key triggers the global server 102 to send a synchronization request to each local server 104 registered with the global server 102. The global server 102 creates a synchronization request custom resource (CR) and sends the synchronization request CR to the local server 104. The exemplary synchronization request monitoring circuit 302 monitors the corresponding synchronization request CR. If a synchronization request CR is detected, the local server 104 creates another CR associated with the certificate.

[0062] The exemplary credential generation circuit 304 generates credentials for remote authentication. Performing remote authentication is to ensure that two enclaves can securely collaborate, for example, to perform data exchange, communicate for specific services, etc. When a secure enclave 116 ( Figure 1AWhen global server 102 wants to synchronize a user's private key to local server 104, local server 104 must prove to global server 102 that local server 104 is running on a trusted platform that can securely handle private keys or secrets. To ensure the enclave 116 is secure and trustworthy, the enclave provides evidence called credentials. A credential is a unique asymmetric proof key representing a digital signature generated through the hardware and software configuration of a specific enclave. The process of verifying credentials is called remote proof. Therefore, the credential generation circuit 304 of local server 104 generates credentials to prove the trustworthiness of the enclave.

[0063] The exemplary Certificate Signature Request (CSR) circuit 307 generates a CSR. The CSR is a request from the applicant to the Certificate Authority (CA) 122 of the Public Key Infrastructure. Figure 1A A message is sent to request a digital identity certificate. In the example shown, local server 104 sends a CSR to the CA to create a certificate for local server 104 to encrypt traffic to local server 104. CSR circuit 307 encodes credentials into the CSR. The CA only signs the CSR if the credentials are verified. The signed certificate is then sent to local server 104.

[0064] An exemplary public-private key generation circuit 306 generates a public-private key pair used in the remote authentication process. The remote party uses the public key to verify credentials. In the illustrated example, the remote party is the authentication controller 162 that verifies credentials from the local server 104. Figure 1A The private key is used for secure enclave 142 on the local server. Figure 1B Sign it.

[0065] An exemplary proof custom resource (CR) controller circuit 308 creates a proof CR to be sent to proof controller 162 for credential verification. The proof CR is used in remote proofs on local server 104 to store and retrieve structured data related to the remote proof process.

[0066] Figure 3 The exemplary second server or local server 104 shown includes a communication interface circuit 310 to enable the local server 104 to communicate with the first server or global server 102 and gateway proxy 132. Figure 1B Communication. Exemplary communication interface circuitry 310 receives an updated certificate CR from certificate controller 162 and a packet of user private keys from global server 102. Communication interface circuitry 310 is also configured to send a packet of user private keys from local server 104 to gateway agent 132.

[0067] Figure 3The exemplary local server 104 shown is equipped with a key decryption circuit 312 for decrypting encrypted user private keys received from the global server 102. While the decryption circuit 312 in the illustrated example applies a decryption algorithm, it can additionally or alternatively decrypt the user private key and / or apply any other type of algorithm to access it. The decrypted user private key is stored in a secure enclave 142.

[0068] Figure 3 The exemplary second server 104 shown includes an exemplary key encryption circuit 316 for encrypting the user's private key before synchronizing it to the gateway agent 132. While the encryption circuit 316 in the illustrated example applies an encryption algorithm, the encryption circuit 316 may additionally or alternatively encapsulate the user's private key and / or apply any other type of algorithm to encapsulate the user's private key.

[0069] An exemplary token file generation circuit 318 is used to securely transfer a user's private key from a local server 104 to a gateway agent 132. In the illustrated example, the token file generation circuit 318 is a Cryptographic API Toolkit (CTK). The token file generation circuit 318 generates a token file shared between the local server 104 and the gateway agent 132. The local server 104 utilizes the CTK with a secure enclave 142 to enhance the security of data and key protection applications by exposing an interface within the secure enclave 142 to securely run key generation and encryption operations. When the agent 132 is initiated, the agent 132 bootstraps the agent secure enclave 150 using the same token file utilized by the local server secure enclave 142. When the agent 132 requires a new secret, the agent 132 sends a standard SDS request to the local server 104. The local server 104 sends an SDS response to the agent 132. The SDS response includes the final certificate and configuration regarding the secure enclave private key provider plugin. When agent 132 receives the SDS response, it creates a secure enclave private key provider plugin object 152. Secure enclave private key provider plugin 152 then locates secure enclave 150, created by the secure enclave bootstrap extension upon its initial startup. Using the shared CTK token file, local server 104 is able to send the corresponding user private key configuration information and a signed certificate 320 to gateway agent 132. Gateway agent 132 stores the final certificate 320 and private key in secure enclave 150. Secure enclave private key provider plugin 152 uses the private key in secure enclave 150 to perform signature() / decryption() operations in the data plane.

[0070] In some instances, the second server 104 includes means for monitoring. For example, the means for monitoring may be implemented by a synchronization request monitoring circuit 302. In some instances, the synchronization request monitoring circuit 302 may be, for example... Figure 16The exemplary programmable circuit 1612 shown is an example of a programmable circuit instantiation. For example, the synchronization request monitoring circuit 302 can be instantiated by, for example, at least by... Figure 5 Box 502 in the middle implements those machine-executable instructions. Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the synchronization request monitoring circuit 302 may be instantiated by hardware logic circuitry configured and / or structured to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the synchronization request monitoring circuit 302 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the synchronization request monitoring circuit 302 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0071] In some instances, the second server 104 includes means for generating vouchers. For example, the means for generating vouchers may be implemented by voucher generation circuitry 304. In some instances, voucher generation circuitry 304 may be, for example... Figure 16 The exemplary programmable circuit 1612 shown is an instantiation of a programmable circuit. For example, the credential generation circuit 304 can be instantiated by, for example, at least by... Figure 7 Box 704 and Figure 9 The machine-executable instructions implemented in box 906 are... Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the credential generation circuit 304 may be instantiated by hardware logic circuitry configured and / or structured to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the credential generation circuit 304 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the credential generation circuit 304 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0072] In some instances, the second server 104 includes means for generating key pairs. For example, the means for generating key pairs may be implemented by a public-private key generation circuit 306. In some instances, the public-private key generation circuit 306 may be implemented by, for example... Figure 16 The exemplary programmable circuit 1612 shown is an instantiation of a programmable circuit. For example, the public-private key generation circuit 306 can be instantiated by, for example, at least by, Figure 7 Box 704 and Figure 9 The machine-executable instructions implemented in box 902 are... Figure 17 The exemplary microprocessor 1700 shown is used as an example for instantiation. In some instances, the public-private key generation circuit 306 can be instantiated by hardware logic circuitry, which can be configured and / or constructed to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the public-private key generation circuit 306 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the public-private key generation circuit 306 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0073] In some instances, the second server 104 includes means for creating a proof CR. For example, the means for creating a proof CR may be implemented by proof customization resource (CR) controller circuitry 308. In some instances, the proof CR controller circuitry 308 may be implemented by, for example... Figure 16 The exemplary programmable circuit 1612 shown is an example of a programmable circuit instantiation. For example, it is demonstrated that the CR controller circuit 308 can perform, for example, at least by Figure 7 Box 706 and Figure 8 The machine-executable instructions implemented in box 808 are... Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, it is demonstrated that the CR controller circuit 308 can be instantiated by hardware logic circuitry configured and / or constructed to perform operations corresponding to machine-readable instructions. Figure 18The ASIC, XPU, or FPGA circuit 1800 shown is used for implementation. Additionally or alternatively, it is demonstrated that the CR controller circuit 308 can be instantiated by any other combination of hardware, software, and / or firmware. For example, it is demonstrated that the CR controller circuit 308 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0074] In some instances, the second server 104 includes means for communication. For example, the means for communication may be implemented by a communication interface circuit 310. In some instances, the communication interface circuit 310 may be, for example... Figure 16 The exemplary programmable circuit 1612 shown can be instantiated using programmable circuits such as those described above. For example, the communication interface circuit 310 can be implemented by, for example, at least by... Figure 5 Boxes 504 and 506 in the middle Figure 7 Boxes 702, 708, and 716 in the middle Figure 8 Boxes 802, 804, 806, 812, 816, 818 and Figure 9 The machine-executable instructions implemented in boxes 912 and 914 are... Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the communication interface circuitry 310 may be instantiated by hardware logic circuitry configured and / or structured to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the communication interface circuit 310 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the communication interface circuit 310 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0075] In some instances, the second server 104 includes means for decryption. For example, the means for decryption may be implemented by a key decryption circuit 312. In some instances, the key decryption circuit 312 may be, for example... Figure 16The exemplary programmable circuit 1612 shown is an example of a programmable circuit instantiation. For example, the key decryption circuit 312 can be instantiated by, for example, at least by... Figure 7 Box 710 and Figure 8 The machine-executable instructions implemented in box 810 are... Figure 17 The exemplary microprocessor 1700 shown is used as an example for instantiation. In some instances, the key decryption circuit 312 may be instantiated by hardware logic circuitry, which may be configured and / or constructed to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the key decryption circuit 312 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the key decryption circuit 312 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0076] In some instances, the second server 104 includes means for encryption. For example, the means for encryption may be implemented by a key encryption circuit 316. In some instances, the key encryption circuit 316 may be, for example... Figure 16 The exemplary programmable circuit 1612 shown is an instantiation of a programmable circuit. For example, the key encryption circuit 316 can be instantiated by, for example, at least by... Figure 8 The machine-executable instructions implemented in box 816 are... Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the key encryption circuitry 316 may be instantiated by hardware logic circuitry configured and / or constructed to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the key encryption circuit 316 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the key encryption circuit 316 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0077] In some instances, the second server 104 includes means for generating a token file. For example, the means for generating the token file may be implemented by a token file generation circuit 318. In some instances, the token file generation circuit 318 may be implemented by, for example... Figure 16 The exemplary programmable circuit 1612 shown is an instantiation of a programmable circuit. For example, the token file generation circuit 318 can be instantiated by, for example, at least by, a programmable circuit generated by... Figure 9 Box 904 in the middle implements those machine-executable instructions. Figure 17 The exemplary microprocessor 1700 shown is instantiated. In some instances, the token file generation circuit 318 may be instantiated by hardware logic circuitry configured and / or structured to perform operations corresponding to machine-readable instructions. Figure 18 The illustrated ASIC, XPU, or FPGA circuit 1800 is implemented. Additionally or alternatively, the token file generation circuit 318 can be instantiated by any other combination of hardware, software, and / or firmware. For example, the token file generation circuit 318 can be implemented by at least one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, XPU, comparator, operational amplifier, logic circuitry, etc.) configured and / or constructed to perform some or all of the operations corresponding to machine-readable instructions without executing software or firmware, but other configurations are equally suitable.

[0078] Although Figure 3 The example shown in Figure 1 illustrates a way to implement the second server 104 shown in Figure 1, but Figure 3 One or more of the elements, processes, and / or devices shown may be combined, divided, rearranged, omitted, eliminated, and / or implemented in any other way. Furthermore, the exemplary synchronization request monitoring circuit 302, exemplary credential generation circuit 304, exemplary public / private key generation circuit 306, exemplary certificate signing request (CSR) circuit 307, exemplary proof customization resource (CR) controller circuit 308, exemplary communication interface circuit 310, exemplary key decryption circuit 312, exemplary key encryption circuit 316, exemplary token file generation circuit 318, and / or more generally, Figure 3The exemplary second server 104 shown can be implemented solely by hardware or by hardware in combination with software and / or firmware. Therefore, for example, the exemplary synchronization request monitoring circuit 302, the exemplary credential generation circuit 304, the exemplary public / private key generation circuit 306, the exemplary certificate signing request (CSR) circuit 307, the exemplary proof customization resource (CR) controller circuit 308, the exemplary communication interface circuit 310, the exemplary key decryption circuit 312, the exemplary key encryption circuit 316, the exemplary token file generation circuit 318, and / or more generally, any one of the exemplary second server 104 can be implemented by, for example, a programmable circuit, processor circuit, analog circuit, digital circuit, logic circuit, programmable processor, programmable microcontroller, graphics processing unit (GPU), digital signal processor (DSP), ASIC, programmable logic device (PLD), and / or field-programmable logic device (FPLD) combined with machine-readable instructions (e.g., firmware or software), such as an FPGA. Furthermore, Figure 3 The exemplary second server 104 shown may include, in addition to Figure 3 The elements, processes and / or equipment shown are outside of or replace those shown. Figure 3 The elements, processes, and / or devices shown may include more than one of any or all of the elements, processes, and devices shown.

[0079] Figure 4 and Figure 6 The diagram illustrates an implementation and / or instantiation that can be executed by a programmable circuit. Figure 2 The exemplary machine-readable instructions and / or representations of the first server 102 shown can be executed by programmable circuitry to implement and / or instantiate it. Figure 2 The flowchart illustrates an exemplary operation of the first server. Machine-readable instructions can be used by programmable circuits (e.g., in conjunction with the following). Figure 15 The programmable circuitry 1512 shown in the exemplary processor platform 1500 discussed herein executes one or more executable programs or a portion thereof, and / or may be to be combined with the following Figure 17 And / or 18. The exemplary programmable circuits (e.g., FPGAs) discussed in the examples perform one or more functions or a portion of functions. In some instances, machine-readable instructions cause operations, tasks, etc., to be performed and / or executed in an automated manner in the real world. As used herein, “automation” means without human intervention.

[0080] Figure 5 , 7 -9 illustrates that it can be implemented and / or instantiated by programmable circuitry. Figure 3 The exemplary machine-readable instructions and / or representations of the second server 104 shown can be executed by programmable circuitry to implement and / or instantiate it. Figure 3 The flowchart illustrates an exemplary operation of the second server 104. Machine-readable instructions may be one or more executable programs or parts thereof for execution by programmable circuitry, as illustrated below. Figure 16 The programmable circuitry 1612 shown in the exemplary processor platform 1600 discussed herein, and / or may be to be combined with the following Figure 17 And / or 18. Exemplary programmable circuits (e.g., FPGAs) discussed in the examples perform one or more functions or a portion thereof. In some instances, machine-readable instructions cause operations, tasks, etc., to be performed and / or executed in an automated manner in the real world. As used herein, “automation” means without human intervention.

[0081] The program may be embodied in instructions (e.g., software and / or firmware) stored on one or more non-transitory computer-readable and / or machine-readable storage media, such as cache memory, magnetic storage devices or disks (e.g., floppy disks, hard disk drives (HDDs), etc.), optical storage devices or disks (e.g., Blu-ray discs, CDs, DVDs, etc.), redundant arrays of independent disks (RAID), registers, ROM, solid-state drives (SSDs), SSD memory, non-volatile memory (e.g., electrically erasable programmable read-only memory (EEPROM), flash memory, etc.), volatile memory (e.g., random access memory (RAM) of any type), and / or any other storage device or disk. The instructions on the non-transitory computer-readable and / or machine-readable media may be programmed and / or executed by programmable circuitry located in one or more hardware devices, but the entire program and / or portions thereof may alternatively be executed and / or instantiated and / or embodied in dedicated hardware by one or more hardware devices other than programmable circuitry. Machine-readable instructions can be distributed across multiple hardware devices and / or executed by two or more hardware devices (e.g., server and client hardware devices). For example, client hardware devices can be implemented by endpoint client hardware devices (e.g., hardware devices associated with human and / or machine users) or intermediate client hardware device gateways (e.g., radio access networks (RAN)) that facilitate communication between the server and endpoint client hardware devices. Similarly, non-transitory computer-readable storage media can include one or more media. Furthermore, although references... Figures 4-9The flowcharts shown depict exemplary programs; however, many other methods for implementing the exemplary first server 102 and second server 104 can be used alternatively. For example, the execution order of the boxes in the flowchart can be changed, and / or some of the boxes described can be changed, eliminated, or combined. Additionally or alternatively, any or all boxes in the flowchart can be implemented by one or more hardware circuits (e.g., processor circuitry, discrete and / or integrated analog and / or digital circuitry, FPGA, ASIC, comparator, operational amplifier, logic circuitry, etc.) configured to perform the corresponding operations without executing software or firmware. Programmable circuitry can be distributed across different network locations and / or local to one or more hardware devices (e.g., single-core processors (e.g., single-core CPUs), multi-core processors (e.g., multi-core CPUs, XPUs, etc.)). For example, programmable circuitry can be a CPU and / or FPGA located in the same package (e.g., the same integrated circuit (IC) package or two or more separate housings), one or more processors in a single machine, multiple processors distributed across multiple servers in a server rack, multiple processors distributed across one or more server racks, and / or any combination thereof.

[0082] The machine-readable instructions described herein can be stored in one or more of the following formats: compressed format, encrypted format, segmented format, compiled format, executable format, packaged format, etc. As described herein, machine-readable instructions can be stored as data (e.g., computer-readable data, machine-readable data, one or more bits (e.g., one or more computer-readable bits, one or more machine-readable bits, etc.), bit streams (e.g., computer-readable bit streams, machine-readable bit streams, etc.)) or data structures (e.g., as parts of instructions, code, code representations, etc.), which can be used to create, manufacture, and / or produce machine-executable instructions. For example, machine-readable instructions can be segmented and stored on one or more storage devices, disks, and / or computing devices (e.g., servers) located in the same or different locations (e.g., in the cloud, on edge devices, etc.) within a network or network set. Machine-readable instructions may require installation, modification, adaptation, updating, combination, supplementation, configuration, decryption, decompression, unpacking, distribution, reallocation, compilation, etc., to enable the machine-readable instructions to be directly read, interpreted, and / or executed by computing devices and / or other machines. For example, machine-readable instructions may be stored in multiple parts that are individually compressed, encrypted, and / or stored on separate computing devices, wherein these parts, when decrypted, decompressed, and / or combined, form a set of computer-executable instructions and / or machine-executable instructions that, together, can form one or more functions and / or operations of a program, such as those described herein.

[0083] In another instance, machine-readable instructions can be stored in a state that can be read by programmable circuitry, but libraries (e.g., dynamic link libraries (DLLs)), software development kits (SDKs), application programming interfaces (APIs), etc., need to be added to execute the machine-readable instructions on a specific computing device or other device. In yet another instance, the machine-readable instructions may need to be configured (e.g., stored settings, data input, recorded network addresses, etc.) before they can be executed in whole or in part. Therefore, as used herein, machine-readable, computer-readable, and / or machine-readable media can include instructions and / or programs, regardless of their specific format or state.

[0084] The machine-readable instructions described in this article can be represented by any past, present, or future instruction language, scripting language, programming language, etc. For example, machine-readable instructions can be represented using any of the following languages: C, C++, Java, C#, Perl, Python, JavaScript, Hypertext Markup Language (HTML), Structured Query Language (SQL), Swift, etc.

[0085] As mentioned above, Figures 4-9Exemplary operations can be implemented using executable instructions (e.g., computer-readable instructions and / or machine-readable instructions) stored on one or more non-transitory computer-readable and / or machine-readable media. As used herein, the terms non-transitory computer-readable media, non-transitory computer-readable storage media, non-transitory machine-readable media, and / or non-transitory machine-readable storage media are explicitly defined to include any type of computer-readable storage device and / or storage disk, excluding propagation signals and transmission media. Examples of such non-transitory computer-readable media, non-transitory computer-readable storage media, non-transitory machine-readable media, and / or non-transitory machine-readable storage media include optical storage devices, magnetic storage devices, HDDs, flash memory, read-only memory (ROM), CDs, DVDs, caches, any type of RAM, registers, and / or any other storage device or storage disk in which information is stored for any duration (e.g., for extended periods, permanently, for short-lived instances, for temporary buffering, and / or for caching information). As used herein, the terms "non-transitory computer-readable storage device" and "non-transitory machine-readable storage device" are defined as any physical (mechanical, magnetic, and / or electrical) hardware that retains information for a period of time, but excludes signal propagation and transmission media. Examples of non-transitory computer-readable storage devices and / or non-transitory machine-readable storage devices include any type of random access memory, any type of read-only memory, solid-state memory, flash memory, optical discs, magnetic disks, disk drives, and / or redundant arrays of independent disks (RAID) systems. As used herein, the term "device" means a physical structure, such as mechanical and / or electrical equipment, hardware, and / or circuitry, that can or may not be configured and / or manufactured to execute computer-readable instructions, machine-readable instructions, etc.

[0086] "Comprising" and "including" (and all their forms and tenses) are used herein as open-ended terms. Therefore, whenever a claim uses any form of "comprising" or "including" (e.g., including, having, etc.) as a preamble or within the recounting of any kind of claim, it should be understood that additional elements, terms, etc., may be present without falling outside the scope of the corresponding claim or recounting. As used herein, when the phrase "at least" is used as a transitional term, for example, in the preamble of a claim, it is open-ended in the same way that the terms "comprising" and "including" are open-ended. When used in the form of, for example, A, B, and / or C, the term "and / or" refers to any combination or subset of A, B, C, such as (1) A alone, (2) B alone, (3) C alone, (4) A and B, (5) A and C, (6) B and C, or (7) A and B and C. As used herein in the context of describing structures, components, articles, objects, and / or things, the phrase “at least one of A and B” is intended to refer to an implementation that includes (1) at least one A, (2) at least one B, or (3) at least one A and at least one B. Similarly, as used herein in the context of describing structures, components, articles, objects, and / or things, the phrase “at least one of A or B” is intended to refer to an implementation that includes (1) at least one A, (2) at least one B, or (3) at least one A and at least one B. As used herein in the context of describing the execution or performance of processes, instructions, actions, and / or activities, the phrase “at least one of A and B” is intended to refer to an implementation that includes (1) at least one A, (2) at least one B, or (3) at least one A and at least one B. Similarly, as used herein in the context of describing the execution or performance of a process, instruction, action and / or activity, the phrase “at least one of A or B” is intended to refer to an implementation that includes (1) at least one A, (2) at least one B or (3) any one of at least one A and at least one B.

[0087] As used herein, singular references (e.g., "a," "an," "first," "second," etc.) do not exclude plurals. As used herein, the term "a" or "an" refers to one or more of those objects. The terms "a" (or "an"), "one or more," and "at least one" are used interchangeably herein. Furthermore, although listed separately, multiple means, elements, or actions may be implemented by, for example, the same entity or object. Additionally, although individual features may be included in different instances or claims, these features may be combined, and inclusion in different instances or claims does not imply that the combination of features is impractical and / or advantageous.

[0088] Figure 4This is a flowchart illustrating exemplary machine-readable instructions and / or exemplary operations 400, which can be executed, instantiated, and / or implemented by programmable circuitry to transmit data from a first server or global server 102. Figure 1A The private key is synchronized to the second server or the local server. Figure 1B ). Figure 4 The exemplary machine-readable instructions and / or exemplary operations 400 shown begin at box 402, where the local server monitoring circuit 202 ( Figure 2 The exemplary local server monitoring circuit 202 monitors local server 104. If the exemplary local server monitoring circuit 202 does not detect the second server 104 (box 404: No), control proceeds to box 402, where the exemplary local server monitoring circuit 202 continues to monitor the second server 104. If the exemplary local server monitoring circuit 202 detects the second server 104 (box 404: Yes), control proceeds to box 406, where the exemplary registration circuit 204 (box 406: Yes) monitors local server 104. Figure 2 The second server 104 detected in the registration environment 100. Example annotated secret monitoring circuit 206 ( Figure 2 Monitoring from administrator 170 ( Figure 1A The annotation secret of ) (box 408). If the exemplary annotation secret monitoring circuit 206 does not detect the annotation secret (box 410: No), control proceeds to box 408, where the exemplary annotation secret monitoring circuit 206 continues to monitor the annotation secret. If the exemplary annotation secret monitoring circuit 206 detects the annotation secret (box 410: Yes), control proceeds to box 412, where the exemplary verification custom resource (CR) controller circuit 212 ( Figure 2 Generate a certificate customization resource (CR) (box 412). At box 414, the exemplary certificate generation circuit 208 ( Figure 2 Generate credentials for remote authentication. At box 416, key decryption circuit 214 decrypts or unseales the user's private key from administrator 170. At box 418, the private key is saved to the first server secure enclave 116. Figure 1A As shown below Figure 6 As described, at box 420, the first server 102 synchronizes the private key to the second server 104. Figure 4 The exemplary instructions and / or operations shown have ended.

[0089] Figure 5 This is a flowchart illustrating exemplary machine-readable instructions and / or exemplary operations 500, which can be executed, instantiated, and / or implemented by programmable circuitry to transmit data from a first server or global server 102. Figure 1A The private key is synchronized to the second server or the local server. Figure 1B ). Figure 5 The exemplary machine-readable instructions and / or exemplary operations 500 shown begin at block 502, where a synchronous request monitoring circuit 302 is initiated. Figure 3 Monitoring from the first server or global server 102 ( Figure 1A Synchronization requests. See below for examples. Figure 9 As described, if the exemplary synchronization request monitoring circuit 302 does not receive a synchronization request from the first server 102 (box 502: No), control returns to the beginning, where the exemplary synchronization request monitoring circuit 302 continues to monitor synchronization requests, or control proceeds to box 508, where the exemplary second server 104 generates a private key locally. This is in conjunction with the following... Figure 7 As described, if the exemplary synchronization request monitoring circuit 302 detects a synchronization request (box 502: Yes), control proceeds to box 504, where the exemplary second server 104 synchronizes its private key with the private key from the first server 102. This is further illustrated below. Figure 8 As described, at box 506, the second server 104 delivers the private key to the gateway agent 132 in the exemplary environment 100. Figure 5 The example instructions and / or operations shown have ended.

[0090] Figure 6 This is a flowchart illustrating exemplary machine-readable instructions and / or exemplary operations that can be executed, instantiated, and / or implemented by exemplary programmable circuitry. Figure 1A and Figure 2 The first server 102 shown synchronizes the private key from the first server 102 to the second server 104. Figure 1B ). Figure 6 The instructions and / or operations represented in the flowchart can be used to implement Figure 4 Box 420 in the diagram is used to implement the synchronization process at the first server 102. Figure 6 The exemplary machine-readable instructions and / or exemplary operations shown begin at box 602, where the first server 102 is in exemplary environment 100 ( Figure 1A and 1B Create a Synchronization Request Custom Resource (CR) in box 604. The communication interface circuit 218 ( Figure 2The exemplary first server 102 sends a synchronization request CR to the second server 104 and waits for a proof CR with proof results. If the exemplary first server 102 does not receive a proof CR update (box 606: No), control proceeds to box 602, where the exemplary first server recreates the synchronization request CR. If the exemplary first server 102 receives a proof CR update (box 606: Yes), control proceeds to box 608, where the exemplary key encryption circuit 216 ( Figure 2 The user's private key is encapsulated or encrypted. At box 610, the exemplary first server 102 updates the certificate CR with the encapsulated or encrypted key. At box 612, the exemplary communication interface circuitry 218 sends the certificate CR with the encapsulated key to the second server 104. At box 614, the first server 102 sends a "delete synchronization request CR" to the second server 104. Figure 6 The exemplary instructions and / or operations shown have ended.

[0091] Figure 7 This is a flowchart illustrating exemplary machine-readable instructions and / or exemplary operations that can be executed, instantiated, and / or implemented by exemplary programmable circuitry. Figure 1B and Figure 3 The second server 104 shown is used to transmit data from the first server 102 ( Figure 1A The private key is synchronized to the second server 104. Figure 7 The instructions and / or operations represented in the flowchart can be used to implement Figure 5 Box 504 in the diagram is used to implement the synchronization process at the second server 104. Figure 7 The exemplary machine-readable instructions and / or exemplary operations shown begin at block 702, where the exemplary synchronization request monitoring circuit 302 ( Figure 3 Monitoring from the first server or global server 102 ( Figure 1A The exemplary synchronization request monitoring circuit 302 does not receive a synchronization request from the first server 102 (box 702: No), then control returns to the beginning, where the exemplary synchronization request monitoring circuit 302 continues to monitor synchronization requests. If the exemplary synchronization request monitoring circuit 302 detects a synchronization request (box 702: Yes), then control proceeds to box 704, where the exemplary credential generation circuit 304 ( Figure 3 Generate credentials, and an exemplary public-private key pair generation circuit 306 ( Figure 3 Generate a public-private key pair for remote authentication. At box 706, authenticate the CR controller circuit 308. Figure 3 Create proof CR. At box 708, exemplary communication interface circuit 310 ( Figure 3) Receives an updated proof CR with an encapsulated or encrypted user private key. At block 710, exemplary key decryption circuit 312 ( Figure 3 Decrypt or unblock the user's private key. At box 712, the second server 104 stores the user's private key and certificate in a secure enclave or secure storage 142 on the second server. Figure 1B In block 714, exemplary second server 104 deletes the proof CR. In block 716, communication interface circuitry 310 receives a "delete synchronization request CR" from first server 102. Figure 7 The exemplary instructions and / or operations shown have ended and control has returned to... Figure 5 Box 506 in the middle.

[0092] Figure 8 This indicates that it can be executed, instantiated, and / or implemented by an exemplary programmable circuit. Figure 1B and Figure 3 The second server 104 shown synchronizes the private key from the second server 104 to the gateway agent 132 in the exemplary environment 100. Figure 1B A flowchart of exemplary machine-readable instructions and / or exemplary operations. Figure 8 The instructions and / or operations represented in the flowchart can be used to implement Figure 5 Box 506 in the code is used to deliver the private key from the second server 104 to the gateway agent. Figure 8 The exemplary machine-readable instructions and / or exemplary operations shown begin at block 802, where the exemplary communication interface circuit 310 ( Figure 3 ) Receives a Secret Discovery Service (SDS) request from gateway agent 132. At box 804, a custom resource controller circuit 308 is demonstrated ( Figure 3 The exemplary proof custom resource controller circuit 308 sends a proof request to the gateway agent 132. At box 806, the exemplary proof custom resource controller circuit 308 receives a proof response from the gateway agent 132. At box 808, the exemplary proof custom resource controller circuit 308 creates a proof CR for remote proof. At box 810, the exemplary proof custom resource controller circuit 308 receives an updated proof CR. At box 812, the exemplary key encryption circuit 316 (… Figure 3 The relevant user private key to be sent to gateway agent 132 is encrypted or encapsulated. At box 814, the exemplary proof custom resource controller circuit 308 deletes the proof CR. At box 816, the communication interface circuit 310 sends the encapsulated user private key and agent configuration to gateway agent 132. At box 818, the exemplary communication interface circuit 310 sends an SDS response (private key provider) to gateway agent 132. Figure 8 The exemplary instructions and / or operations shown have ended.

[0093] Figure 9 This is a flowchart illustrating exemplary machine-readable instructions and / or exemplary operations that can be executed, instantiated, and / or implemented by exemplary programmable circuitry. Figure 1B and Figure 3 The second server 104 shown generates a private key locally at the second server 104. Figure 9 The instructions and / or operations represented in the flowchart can be used to implement Figure 5 Box 508 in the diagram is used to implement the key generation process at the second server 104. Figure 9 The exemplary machine-readable instructions and / or exemplary operations shown begin at block 902, where the exemplary public-private key pair generation circuit 306 ( Figure 3 The exemplary token file generation circuit 318 generates a public-private key pair used in the remote authentication process. At box 904, the exemplary token file generation circuit 318 generates a Cryptographic API Toolkit (CTK) token file. At box 906, the exemplary credential generation circuit 304 generates credentials for remote authentication. At box 908, the exemplary CSR circuit 307 sends a request to a trusted certificate service or Certificate Authority (CA) 122 (…). Figure 1A Generate a Certificate Service Request (CSR). Exemplary CSR circuit 307 adds credentials as an extension to the CSR (box 910) for remote authentication. At box 912, communication interface circuit 310 receives the signed certificate after successful remote authentication. At box 914, communication interface circuit 310 sends the proxy configuration and certificate to gateway agent 132. Figure 9 The exemplary instructions and / or operations shown have ended and control has returned to... Figure 5 Box 506 in the middle.

[0094] Figure 10 It is used to implement Figure 1A and Figure 2 The exemplary first server 102 shown is used by administrator 170 ( Figure 1A An example workflow 1000 illustrates the interaction of uploading a key to a first server 102. Figure 10 The diagram shows an administrator 170, a Key Management Reference Application (KMRA) 160, a proof controller 162, a first server or global server 102, and a second server or local server 104. Figure 1BThe process is as follows: In the illustrated exemplary workflow 1000, at event 1002, administrator 170 deploys a global server or first server 102 and a local server or second server 104 in exemplary environment 100. At event 1004, exemplary global server 102 registers local server 104. At event 1010, exemplary administrator 170 creates a secret with annotations (e.g., key identifier (ID) or certificate) and sends the secret to global server 102. At event 1012, global server 102 generates credentials for remote authentication and a public-private key pair. At event 1014, global server 102 creates an authentication custom resource (CR) and sends the authentication CR to exemplary authentication controller 162. At event 1016, exemplary authentication controller 162 verifies the credentials, thereby remotely authenticating global server 102. At event 1018, administrator 170 updates the authentication CR with the encapsulated key. At event 1020, global server 102 unsealed the user's private key to its secure enclave 116. Figure 1A In event 1022, global server 102 deletes the proof CR from exemplary proof controller 162.

[0095] Figure 11 It is to achieve Figure 1A and Figure 2 The exemplary first server or global server 102 shown and Figure 1B and Figure 3 The diagram illustrates an exemplary workflow 1100 for synchronizing a key from a first server 102 to a second server 104, using an exemplary second server or local server 104. Example Figure 11 The example consists of a Key Management Reference Application (KMRA) 160, an exemplary proof controller 162, and a first server or global server 102. Figure 1A ) and the second server or local server 104 ( Figure 1BThe process is as follows: In the exemplary workflow 1100 shown, at event 1102, global server 102 creates a synchronization request CR and sends the CR to local server 104. At event 1104, local server 104 generates credentials for remote authentication and a public-private key pair. At event 1106, local server 104 creates an authentication CR and sends the CR to remote authentication controller 162 for remote authentication. At event 1108, exemplary authentication controller 162 verifies the credentials and sends them to exemplary KMRA 160. At event 1110, exemplary authentication controller 162 updates the CR with the authentication result and sends the result back to global server 102. At event 1112, global server 102 encapsulates or encrypts the user's private key. At event 1114, global server 102 updates the CR with the encapsulated key and sends the encapsulated key to local server 104. At event 1116, local server 104 decapsulates the user's private key. At event 1118, local server 104 deletes the proof CR request sent to the proof controller. At event 1120, global server 102 sends a delete synchronization request CR to local server 104.

[0096] Figure 12 It is to realize Figure 1 and Figure 3 The exemplary second server or local server 104 shown is used to deliver keys from local server 104 to gateway agent 132. Figure 1B An example workflow 1200 interaction diagram. Figure 12The process is illustrated by an exemplary administrator 170, an exemplary Key Management Reference Application (KMRA) 160, an exemplary authentication controller 162, a second server or local server 104, an exemplary gateway agent 132, and an exemplary daemon 120. In the illustrated exemplary workflow 1200, at event 1202, the administrator 170 creates a gateway-customized resource and sends it to the daemon 120. At event 1204, the daemon 120 generates the certificate “tls_certificate_sds_secret_config”. At event 1212, the exemplary gateway agent 132 sends a Secret Discovery Service (SDS) request to the local server 104. At event 1214, the local server 104 responds by sending an authentication request to the gateway agent 132. At event 1216, the gateway agent 132 generates credentials and a public-private key pair for remote authentication. At event 1218, the gateway agent 132 sends the authentication response back to the local server 104. At event 1220, local server 104 creates a proof CR for proof controller 162. At event 1222, proof controller 162 verifies the credentials from gateway agent 132 and sends the verified credentials to KMRA 160. At event 1224, proof controller 162 updates the proof CR with the proof result and sends the proof result to local server 104. At event 1226, local server 104 encapsulates the associated user private key. At event 1228, local server 104 deletes the proof CR sent to proof controller 162. At event 1230, local server 104 sends the encapsulated key to gateway agent 132. At event 1232, gateway agent 132 uncaptures the user private key. At event 1234, local server 104 sends an SDS response to the private key provider extension in gateway agent 132.

[0097] Figure 13 It is shown Figure 1A and Figure 2 The illustrated block diagram shows an exemplary first server integrating security policies and key delivery with a cloud service provider (CSP) using a cloud hardware security module (HSM) adapter. In some instances, cloud HSM adapter 1308 monitors proof CR 1306 to obtain the corresponding key identifier (ID) information and cloud HSM information. Exemplary cloud HSM adapter 1308 establishes secure calls to the backend cloud HSM according to the corresponding cloud HSM API. Exemplary cloud HSM adapter 1308 obtains the encapsulated private key from cloud HSMs 1310, 1312, 1314, and 1316 by updating proof CR 1306. Global server 102 uncaptures the private key into global server security enclave 116 by monitoring updates from proof CR 1306.

[0098] Figure 14 This illustrates the use of a security gateway with, according to some embodiments. Figure 1B and Figure 3 The exemplary second server multi-tenant 5G control plane deployment shown Figure 1A and Figure 2 The diagram shows an exemplary first server. (This is in the context of illustrating a 5G use case.) Figure 14 In the exemplary use case illustrated, multiple 5G control plane functions 1402, 1404, 1406, 1408, 1410, and 1412 utilize a horizontal service mesh 1420 in a highly distributed multi-tenant deployment. All access to the exemplary service mesh 1420 occurs through multiple instances of a gateway 1422 (e.g., an ingress point), which serves multiple tenants requiring access to services provided by the 5G system. For example, users may require 5G access for purposes such as subscriber registration, billing, etc. These ingress points are able to meet the demands of incoming traffic. Tenants securely access the service mesh via cloud-native APIs, therefore, the gateway 1422 is a sensitive control point protecting access to the service mesh. The gateway 1422 protects tenant security credentials by using hardware-enforced security mechanisms. These hardware-enforced security mechanisms enhance the security of the service mesh.

[0099] Figure 15 It is constructed to execute and / or instantiate Figure 4 and Figure 6 The exemplary machine-readable instructions and / or exemplary operations shown are for implementing Figure 1 and Figure 2 The diagram shows an exemplary programmable circuit platform 1500 of the first server 102. The programmable circuit platform 1500 may be, for example, a server, a personal computer, a workstation, a self-learning machine (e.g., a neural network), an internet device, or any other type of computing device and / or electronic device.

[0100] The programmable circuit platform 1500 of the illustrated example includes a programmable circuit 1512. The programmable circuit 1512 of the illustrated example is hardware. For example, the programmable circuit 1512 can be implemented by one or more integrated circuits, logic circuits, FPGAs, microprocessors, CPUs, GPUs, DSPs, and / or microcontrollers from any desired family or manufacturer. The programmable circuit 1512 can be implemented by one or more semiconductor-based (e.g., silicon-based) devices. In this example, the programmable circuit 1512 implements an exemplary local server monitoring circuit 202, an exemplary registration circuit 204, an exemplary annotated secret monitoring circuit 206, an exemplary credential generation circuit 208, an exemplary public / private key generation circuit 210, an exemplary proof-custom resource (CR) controller circuit 212, an exemplary key decryption circuit 214, and an exemplary key encryption circuit 216.

[0101] The programmable circuit 1512 of the illustrated example includes local memory 1513 (e.g., cache, registers, etc.). The programmable circuit 1512 of the illustrated example communicates with main memories 1514 and 1516 via bus 1518. Main memories 1514 and 1516 include volatile memory 1514 and non-volatile memory 1516. Volatile memory 1514 can be synchronous dynamic random access memory (SDRAM), dynamic random access memory (DRAM), etc. The non-volatile memory 1516 may be implemented using flash memory and / or any other desired type of memory device. Access to the main memory 1514, 1516 in the illustrated example is controlled by a memory controller 1517. In some instances, the memory controller 1517 may be implemented using one or more integrated circuits, logic circuits, microcontrollers, or any other type of circuit from any desired family or manufacturer to manage the flow of data to and from the main memory 1514, 1516.

[0102] The programmable circuit platform 1500 of the illustrated example also includes interface circuitry 1520. Interface circuitry 1520 can be configured according to any type of interface standard, such as an Ethernet interface, a Universal Serial Bus (USB) interface, etc. Hardware implementation of an interface, a Near Field Communication (NFC) interface, a Peripheral Component Interconnect (PCI) interface, and / or a Peripheral Component Interconnect Fast (PCIe) interface. In this example, interface circuit 1520 is implemented. Figure 2 The communication interface circuit 218 shown is shown.

[0103] In the illustrated example, one or more input devices 1522 are connected to interface circuitry 1520. Input devices 1522 allow users (e.g., human users, machine users, etc.) to input data and / or commands into programmable circuitry 1512. Input devices 1522 can be implemented using, for example, audio sensors, microphones, (still or video) cameras, keyboards, buttons, mice, touchscreens, touchpads, trackballs, isotope devices, and / or voice recognition systems.

[0104] One or more output devices 1524 are also connected to the interface circuitry 1520 of the illustrated example. The output devices 1524 may be implemented, for example, by display devices (e.g., light-emitting diode (LED), organic light-emitting diode (OLED), liquid crystal display (LCD), cathode ray tube (CRT) display, in-place switching (IPS) display, touchscreen, etc.), haptic output devices, printers, and / or speakers. Therefore, the interface circuitry 1520 of the illustrated example typically includes a graphics driver card, a graphics driver chip, and / or graphics processor circuitry such as a GPU.

[0105] The interface circuit 1520 of the illustrated example also includes communication devices, such as a transmitter, receiver, transceiver, modem, residential gateway, wireless access point, and / or network interface, to facilitate the exchange of data with external machines (e.g., any type of computing device) via network 1526. Communication can be performed via, for example, Ethernet connections, digital subscriber line (DSL) connections, telephone line connections, coaxial cable systems, satellite systems, beyond-line-of-sight wireless systems, line-of-sight wireless systems, cellular telephone systems, optical connections, etc.

[0106] The programmable circuit platform 1500 of the illustrated example also includes one or more mass storage disks or storage devices 1528 for storing firmware, software, and / or data. Examples of such mass storage disks or storage devices 1528 include magnetic storage devices (e.g., floppy disks, drives, HDDs, etc.), optical storage devices (e.g., Blu-ray discs, CDs, DVDs, etc.), RAID systems, and / or solid-state storage disks or storage devices such as flash memory devices and / or SSDs.

[0107] It can be by Figure 4 and Figure 6 The machine-readable instructions 1532 shown can be stored in mass storage device 1528, volatile memory 1514, non-volatile memory 1516 and / or can be on at least one non-transitory computer-readable storage medium such as a removable CD or DVD.

[0108] Figure 16 It is constructed to execute and / or instantiate Figure 5 and Figure 7-9 The exemplary machine-readable instructions and / or exemplary operations shown are for implementing Figure 1 and Figure 3 The diagram shows an exemplary programmable circuit platform 1600 of the second server 104. The programmable circuit platform 1600 may be, for example, a server, a personal computer, a workstation, a self-learning machine (e.g., a neural network), an internet device, or any other type of computing device and / or electronic device.

[0109] The programmable circuit platform 1600 of the illustrated example includes a programmable circuit 1612. The programmable circuit 1612 of the illustrated example is hardware. For example, the programmable circuit 1612 can be implemented by one or more integrated circuits, logic circuits, FPGAs, microprocessors, CPUs, GPUs, DSPs, and / or microcontrollers from any desired family or manufacturer. The programmable circuit 1612 can be implemented by one or more semiconductor-based (e.g., silicon-based) devices. In this example, the programmable circuit 1612 implements an exemplary synchronization request monitoring circuit 302, an exemplary credential generation circuit 304, an exemplary public / private key generation circuit 306, an exemplary proof-custom resource (CR) controller circuit 308, an exemplary key decryption circuit 312, an exemplary key encryption circuit 316, and an exemplary token file generation circuit 318.

[0110] The programmable circuit 1612 of the illustrated example includes local memory 1613 (e.g., cache, registers, etc.). The programmable circuit 1612 of the illustrated example communicates with main memories 1614 and 1616 via bus 1618. Main memories 1614 and 1616 include volatile memory 1614 and non-volatile memory 1616. Volatile memory 1614 can be synchronous dynamic random access memory (SDRAM) or dynamic random access memory (DRAM). Dynamic Random Access Memory and / or any other type of RAM device. The non-volatile memory 1616 may be implemented using flash memory and / or any other desired type of memory device. Access to the main memory 1614, 1616 in the illustrated example is controlled by a memory controller 1617. In some instances, the memory controller 1617 may be implemented using one or more integrated circuits, logic circuits, microcontrollers, or any other type of circuitry from any desired family or manufacturer to manage the flow of data to and from the main memory 1614, 1616.

[0111] The programmable circuit platform 1600 of the illustrated example also includes interface circuitry 1620. Interface circuitry 1620 can conform to any type of interface standard, such as an Ethernet interface, a Universal Serial Bus (USB) interface, etc. Hardware implementation of an interface, a Near Field Communication (NFC) interface, a Peripheral Component Interconnect (PCI) interface, and / or a Peripheral Component Interconnect Fast (PCIe) interface. In this example, interface circuit 1620 is implemented. Figure 3 The communication interface circuit 310.

[0112] In the illustrated example, one or more input devices 1622 are connected to interface circuitry 1620. Input devices 1622 allow users (e.g., human users, machine users, etc.) to input data and / or commands into programmable circuitry 1612. Input devices 1622 can be implemented using, for example, audio sensors, microphones, (still or video) cameras, keyboards, buttons, mice, touchscreens, touchpads, trackballs, isotope devices, and / or voice recognition systems.

[0113] One or more output devices 1624 are also connected to the interface circuitry 1620 of the illustrated example. The output devices 1624 may be implemented, for example, by display devices (e.g., light-emitting diode (LED), organic light-emitting diode (OLED), liquid crystal display (LCD), cathode ray tube (CRT) display, in-place switching (IPS) display, touchscreen, etc.), haptic output devices, printers, and / or speakers. Therefore, the interface circuitry 1620 of the illustrated example typically includes a graphics driver card, a graphics driver chip, and / or graphics processor circuitry such as a GPU.

[0114] The interface circuit 1620 of the illustrated example also includes communication devices, such as a transmitter, receiver, transceiver, modem, residential gateway, wireless access point, and / or network interface, to facilitate the exchange of data with external machines (e.g., any type of computing device) via network 1626. Communication can be conducted via, for example, Ethernet connections, digital subscriber line (DSL) connections, telephone line connections, coaxial cable systems, satellite systems, beyond-line-of-sight wireless systems, line-of-sight wireless systems, cellular telephone systems, optical connections, etc.

[0115] The programmable circuit platform 1600 of the illustrated example also includes one or more mass storage disks or storage devices 1628 for storing firmware, software, and / or data. Examples of such mass storage disks or storage devices 1628 include magnetic storage devices (e.g., floppy disks, drives, HDDs, etc.), optical storage devices (e.g., Blu-ray discs, CDs, DVDs, etc.), RAID systems, and / or solid-state storage disks or storage devices such as flash memory devices and / or SSDs.

[0116] It can be by Figure 5 and Figures 7 to 9 The machine-readable instructions 1632 shown can be stored in mass storage device 1628, in volatile memory 1614, in non-volatile memory 1616, and / or on at least one non-transitory computer-readable storage medium, such as a removable CD or DVD.

[0117] Figure 17 yes Figure 15 A block diagram illustrating an exemplary implementation of the programmable circuit 1512. In this example, Figure 15 The programmable circuit 1512 shown is implemented by microprocessor 1700. For example, microprocessor 1700 may be a general-purpose microprocessor (e.g., a general-purpose microprocessor circuit). Microprocessor 1700 executes... Figure 4 and Figure 6 The flowchart shown contains some or all of the machine-readable instructions to effectively... Figure 2 The circuit shown is instantiated as a logic circuit to perform operations corresponding to those machine-readable instructions. Microprocessor 1700 executes... Figure 5 and 7 -9 The flowchart shows some or all of the machine-readable instructions to effectively translate... Figure 3 The circuit shown is instantiated as a logic circuit to perform operations corresponding to those machine-readable instructions. In some such instances, Figure 2 and Figure 3 The circuitry shown is instantiated by hardware circuitry of microprocessor 1700 combined with machine-readable instructions. For example, microprocessor 1700 can be implemented by multi-core hardware circuitry such as a CPU, DSP, GPU, XPU, etc. Although microprocessor 1700 may include any number of exemplary cores 1702 (e.g., one core), this example of microprocessor 1700 is a multi-core semiconductor device including N cores. The cores 1702 of microprocessor 1700 can operate independently or can cooperate to execute machine-readable instructions. For example, machine code corresponding to firmware, embedded software programs, or software programs can be executed by one of the cores 1702, or can be executed simultaneously or at different times by multiple cores 1702. In some instances, the machine code corresponding to firmware, embedded software programs, or software programs is divided into threads and executed in parallel by two or more cores 1702. The software program may correspond to... Figures 4-9 The flowchart represents part or all of the machine-readable instructions and / or operations.

[0118] Core 1702 can communicate via a first exemplary bus 1704. In some instances, the first bus 1704 can be implemented as a communication bus to enable communication associated with one of the cores in core 1702. For example, the first bus 1704 can be implemented as at least one of an Inter-Integrated Circuit (I2C) bus, a Serial Peripheral Interface (SPI) bus, a PCI bus, or a PCIe bus. Additionally or alternatively, the first bus 1704 can be implemented as any other type of computing or electrical bus. Core 1702 can obtain data, instructions, and / or signals from one or more external devices via example interface circuitry 1706. Core 1702 can output data, instructions, and / or signals to one or more external devices via interface circuitry 1706. Although the core 1702 of this example includes an exemplary local memory 1720 (e.g., a Level 1 (L1) cache that can be divided into an L1 data cache and an L1 instruction cache), the microprocessor 1700 also includes an exemplary shared memory 1710 (e.g., a Level 2 (L2) cache) that can be shared by the core for high-speed access to data and / or instructions. Data and / or instructions can be transferred (e.g., shared) by writing to and / or reading from the shared memory 1710. The local memory 1720 and shared memory 1710 of each of the cores 1702 can include cache memory and main memory (e.g., Figure 15 The main memory 1514, 1516 and shown Figure 16 This is part of a multi-level storage device hierarchy for main memories (1614, 1616). Typically, higher-level memories in the hierarchy exhibit lower access times and have smaller storage capacities compared to lower-level memories. Variations within the cache hierarchy are managed by cache coherence policies (e.g., reconciliation).

[0119] Each core 1702 may be referred to as a CPU, DSP, GPU, or any other type of hardware circuit. Each core 1702 includes a control unit circuit 1714, an arithmetic logic (AL) circuit (sometimes called an ALU) 1716, multiple registers 1718, local memory 1720, and a second exemplary bus 1722. Other structures may also be present. For example, each core 1702 may include vector unit circuitry, single instruction multiple data (SIMD) unit circuitry, load / store unit (LSU) circuitry, branch / jump unit circuitry, floating-point unit (FPU) circuitry, etc. The control unit circuitry 1714 includes semiconductor-based circuitry configured to control (e.g., coordinate) the movement of data within the corresponding core 1702. The AL circuitry 1716 includes semiconductor-based circuitry configured to perform one or more mathematical and / or logical operations on the data within the corresponding core 1702. In some instances, the AL circuitry 1716 performs integer-based operations. In other instances, the AL circuitry 1716 also performs floating-point operations. In other instances, the AL circuit 1716 may include a first AL circuit that performs integer-based operations and a second AL circuit that performs floating-point operations. In some instances, the AL circuit 1716 may be referred to as an arithmetic logic unit (ALU).

[0120] Register 1718 is a semiconductor-based structure used to store data and / or instructions, such as the results of one or more operations performed by the AL circuit 1716 of the corresponding core 1702. For example, register 1718 may include vector registers, SIMD registers, general-purpose registers, flag registers, segment registers, machine-specific registers, instruction pointer registers, control registers, debug registers, memory management registers, machine check registers, etc. Register 1718 may be arranged in a manner such as... Figure 17 The memory bank shown. Alternatively, register 1718 can be organized in any other arrangement, format, or structure, for example, by distributing it throughout core 1702 to reduce access time. The second bus 1722 can be implemented by at least one of an I2C bus, an SPI bus, a PCI bus, or a PCIe bus.

[0121] Each core 1702 and / or more generally, the microprocessor 1700 may include additional and / or alternative structures to the structures shown and described above. For example, one or more clock circuits, one or more power supplies, one or more power gates, one or more cache home agents (CHAs), one or more convergence / common grid nodes (CMS), one or more shifters (e.g., barrel shifters), and / or other circuitry may be present. The microprocessor 1700 is a semiconductor device fabricated to include a plurality of transistors interconnected to implement the above-described structures in one or more integrated circuits (ICs) contained in one or more packages.

[0122] The microprocessor 1700 may include one or more accelerators (e.g., acceleration circuitry, hardware accelerators, etc.) and / or cooperate with one or more accelerators. In some instances, accelerators are implemented by logic circuitry to perform certain tasks faster and / or more efficiently than a general-purpose processor can. Examples of accelerators include ASICs and FPGAs, such as those discussed herein. GPUs, DSPs, and / or other programmable devices may also be accelerators. Accelerators may be on the microprocessor 1700, in the same chip package as the microprocessor 1700, and / or in one or more packages separate from the microprocessor 1700.

[0123] Figure 18 yes Figure 15 The programmable circuit 1512 shown and Figure 16 A block diagram of another exemplary embodiment of the programmable circuit 1612. In this example, programmable circuits 1512 and 1612 are implemented by FPGA circuit 1800. For example, FPGA circuit 1800 can be implemented by an FPGA. For example, FPGA circuit 1800 can be used to implement functions that can be otherwise... Figure 17 The exemplary microprocessor 1700 shown executes operations by corresponding machine-readable instructions. However, once configured, the FPGA circuitry 1800 instantiates operations and / or functions corresponding to machine-readable instructions in the hardware, and is therefore generally able to execute operations / functions faster than those that can be executed by a general-purpose microprocessor executing the corresponding software.

[0124] More specifically, as described above Figure 17 The microprocessor 1700 shown (which can be programmed to execute by) Figures 4-9 In contrast, a flowchart represents some or all of the machine-readable instructions of a general-purpose device, but whose interconnections and logic circuitry are fixed once manufactured. Figure 18 The FPGA circuit 1800 in the example shown includes components that can be configured, structured, programmed, and / or interconnected in different ways after manufacturing to, for example, connect with, a, or other components manufactured by [unclear]. Figures 4-9 The flowchart represents the interconnects and logic circuits that instantiate some or all of the machine-readable instructions corresponding to the operations / functions. Specifically, the FPGA circuit 1800 can be considered as an array of logic gates, interconnects, and switches. Switches can be programmed to change the way logic gates are linked to each other via interconnects, thereby effectively forming one or more dedicated logic circuits (unless and until the FPGA circuit 1800 is reprogrammed). The configured logic circuits enable logic gates to cooperate in different ways to perform different operations on data received from the input circuits. Those operations can correspond to... Figures 4-9The flowchart represents some or all of the instructions (e.g., software and / or firmware). Therefore, the FPGA circuit 1800 can be configured and / or constructed to effectively connect with... Figures 4-9 The machine-readable instructions in the flowchart instantiate some or all of the operations / functions corresponding to those software instructions into dedicated logic circuits, executing the operations / functions corresponding to those software instructions in a dedicated manner similar to that of an ASIC. Therefore, the FPGA circuit 1800 can execute operations / functions corresponding to those software instructions faster than a general-purpose microprocessor. Figures 4-9 Some or all of the machine-readable instructions shown correspond to the operations / functions.

[0125] exist Figure 18 In the example shown, the FPGA circuit 1800 is configured and / or structured in response to being programmed (and / or reprogrammed once or multiple times) based on a binary file. In some instances, the binary file can be compiled and / or generated based on instructions in a hardware description language (HDL) (e.g., Lucid, VHSIC Hardware Description Language (VHDL), or Verilog). For example, a user (e.g., a human user, a machine user, etc.) can write code or programs corresponding to one or more operations / functions in the HDL; the code / program can be translated into a low-level language as needed; and the code / program (e.g., code / program in a low-level language) can be converted into a binary file (e.g., through a compiler, software application, etc.). In some instances, Figure 18 The FPGA circuit 1800 shown can access and / or load binary files to enable... Figure 18 The FPGA circuit 1800 shown is configured and / or constructed to perform one or more operations / functions. For example, a binary file may consist of a bit stream (e.g., one or more computer-readable bits, one or more machine-readable bits, etc.), data (e.g., computer-readable data, machine-readable data, etc.), and / or may be generated by... Figure 18 The FPGA circuit shown 1800 accesses to cause Figure 18 The FPGA circuit 1800 shown or a portion thereof is configured and / or implemented using structured machine-readable instructions.

[0126] In some instances, binary files are compiled, generated, transformed, and / or otherwise output from a unified software platform used to program the FPGA. For example, the unified software platform can translate first instructions (e.g., code or program) corresponding to one or more operations / functions in a high-level language (e.g., C, C++, Python, etc.) into second instructions corresponding to one or more operations / functions in an HDL. In some such instances, binary files are compiled, generated, and / or otherwise output from the unified software platform based on the second instructions. In some instances, Figure 18The FPGA circuit 1800 shown can access and / or load binary files to enable... Figure 18 The FPGA circuit 1800 is configured and / or constructed to perform one or more operations / functions. For example, a binary file may consist of a bit stream (e.g., one or more computer-readable bits, one or more machine-readable bits, etc.), data (e.g., computer-readable data, machine-readable data, etc.), and / or may be generated by... Figure 18 The FPGA circuit shown 1800 accesses to cause Figure 18 The FPGA circuit 1800 shown or a portion thereof is configured and / or implemented using structured machine-readable instructions.

[0127] Figure 18 The FPGA circuit 1800 includes exemplary input / output (I / O) circuitry 1802 for obtaining data from and / or outputting data to the exemplary configuration circuit 1804 and / or external hardware 1806. For example, the configuration circuit 1804 may be implemented by interface circuitry that can obtain a binary file, which may be implemented by bitstreams, data, and / or machine-readable instructions to configure the FPGA circuit 1800 or a portion thereof. In some such instances, the configuration circuit 1804 may obtain the binary file from a user, a machine (e.g., hardware circuitry (e.g., programmable or dedicated circuitry) that can implement artificial intelligence / machine learning (AI / ML) models to generate binary files, and / or any combination thereof). In some instances, the external hardware 1806 may be implemented by external hardware circuitry. For example, the external hardware 1806 may be implemented by… Figure 17 The microprocessor 1700 shown is implemented.

[0128] The FPGA circuit 1800 also includes an array of exemplary logic gates 1808, a plurality of exemplary configurable interconnects 1810, and exemplary memory circuitry 1812. The logic gates 1808 and the configurable interconnects 1810 are configurable to interact with... Figures 4-9 Instantiate one or more operations / functions corresponding to at least some of the machine-readable instructions and / or other expected operations. Figure 18 The logic gate circuits 1808 shown are fabricated as blocks or groups. Each block includes semiconductor-based electrical structures that can be configured into logic circuits. In some instances, the electrical structures include logic gates (e.g., AND gates, OR gates, NOR gates, etc.) that provide basic building blocks for the logic circuits. Electrically controllable switches (e.g., transistors) are present within each logic gate circuit 1808 to enable the configuration of the electrical structures and / or logic gates to form circuits that perform desired operations / functions. The logic gate circuits 1808 may include other electrical structures such as lookup tables, registers (e.g., flip-flops or latches), multiplexers, etc.

[0129] The configurable interconnect 1810 of the example shown is a conductive path, trace, via, etc., which may include electrically controllable switches (e.g., transistors) whose states can be changed by programming (e.g., using an HDL instruction language) to activate or deactivate one or more connections between one or more logic gates 1808, thereby programming the desired logic circuit.

[0130] The storage circuit 1812 in the illustrated example is configured to store the results of one or more operations performed by the corresponding logic gates. The storage circuit 1812 can be implemented using registers, etc. In the illustrated example, the storage circuit 1812 is distributed among the logic gates 1808 to facilitate access and improve execution speed.

[0131] Figure 18 The exemplary FPGA circuit 1800 shown also includes exemplary dedicated operating circuitry 1814. In this example, dedicated operating circuitry 1814 includes special-purpose circuitry 1816, which can be invoked to perform common functions to avoid the need for field programming of those functions. Examples of such special-purpose circuitry 1816 include memory (e.g., DRAM) controller circuitry, PCIe controller circuitry, clock circuitry, transceiver circuitry, memory and multiplier-accumulator circuitry. Other types of dedicated circuitry may be present. In some instances, FPGA circuitry 1800 may also include exemplary general-purpose programmable circuitry 1818, such as exemplary CPU 1820 and / or exemplary DSP 1822. Additionally or alternatively, other general-purpose programmable circuitry 1818, such as GPUs, XPUs, etc., that can be programmed to perform other operations may be present.

[0132] although Figure 17 and Figure 18 It shows Figure 15 The programmable circuit 1512 shown and Figure 16 The two exemplary implementations of the programmable circuit 1612 shown are examples; however, many other methods are conceivable. For instance, the FPGA circuit may include an onboard CPU, such as... Figure 17 One or more of the exemplary CPUs 1820 shown. Therefore, Figure 15 The programmable circuit 1512 shown and Figure 16 The programmable circuit 1612 shown can be further combined with at least Figure 17 The exemplary microprocessor 1700 shown and Figure 18 The exemplary FPGA circuit 1800 shown is used for implementation. In some such hybrid instances, Figure 17 One or more cores 1702 shown can perform the functions of Figures 4-9 The flowchart shown represents the first part of a machine-readable instruction to perform a first operation / function. Figure 18The FPGA circuit 1800 shown can be configured and / or constructed to perform operations related to... Figures 4-9 The flowchart shown represents the second operation / function corresponding to the second part of the machine-readable instruction, and / or the ASIC can be configured and / or constructed to perform the operation / function described by the second part of the machine-readable instruction. Figures 4-9 The flowchart shown represents the third operation / function corresponding to the third part of the machine-readable instruction.

[0133] It should be understood that Figure 2 and Figure 3 Some or all of the circuitry can therefore be instantiated at the same or different times. For example, Figure 17 The same and / or different parts of the microprocessor 1700 can be programmed to execute parts of machine-readable instructions at the same and / or different times. In some instances, Figure 18 The same and / or different parts of the FPGA circuit 1800 can be configured and / or constructed to perform operations / functions corresponding to parts of machine-readable instructions at the same and / or different times.

[0134] In some instances, Figure 2 and Figure 3 Some or all of the circuits shown can be instantiated, for example, in one or more threads that execute concurrently and / or serially. For example, Figure 17 The microprocessor 1700 shown can execute machine-readable instructions in one or more threads that execute concurrently and / or serially. In some instances, Figure 18 The FPGA circuit 1800 can be configured and / or constructed to perform operations / functions in parallel and / or serially. Furthermore, in some instances, Figure 2 and Figure 3 Some or all of the circuits shown can be in Figure 17 One or more virtual machines and / or containers are implemented and executed on the microprocessor 1700 shown.

[0135] In some instances, Figure 15 The programmable circuit 1512 shown and Figure 16 The programmable circuit 1612 shown can be in one or more packages. For example, Figure 17 The microprocessor 1700 and / or shown Figure 18 The FPGA circuit 1800 shown can be housed in one or more packages. In some instances, the XPU can be comprised of components that can be housed in one or more packages. Figure 15 The programmable circuit 1512 shown and Figure 16 The programmable circuit 1512 shown is an implementation. For example, the XPU may include a CPU in a package (e.g., Figure 17 The microprocessor 1700 shown Figure 18The CPU 1820 shown), and the DSP in another package (e.g., Figure 18 The DSP 1822 shown), a GPU in another package, and an FPGA in yet another package (e.g., Figure 18 The FPGA circuit shown is 1800.

[0136] Figure 19 A block diagram illustrating an exemplary software distribution platform 1905 is provided, which is used to distribute, for example... Figure 15 The exemplary machine-readable instructions 1532 and Figure 16 The software of the exemplary machine-readable instructions 1632 shown is distributed to other hardware devices (e.g., hardware devices owned and / or operated by a third party from the owner and / or operator of the software distribution platform). The exemplary software distribution platform 1905 can be implemented by any computer server, data facility, cloud service, etc., capable of storing and transferring software to other computing devices. The third party can be a customer of the entity that owns and / or operates the software distribution platform 1905. For example, the entity owning and / or operating the software distribution platform 1905 can be the software (e.g., software...). Figure 15 The exemplary machine-readable instructions 1532 and Figure 16 The developer, seller, and / or licensor of the exemplary machine-readable instruction 1632 shown. A third party can be a consumer, user, retailer, OEM, etc., who purchases and / or licenses the software for use and / or resells and / or sublicenses it. In the illustrated example, the software distribution platform 1905 includes one or more servers and one or more storage devices. As described above, the storage devices can store data that can be stored in conjunction with… Figure 4 and Figure 6 The exemplary machine-readable instruction shown corresponds to machine-readable instruction 1532. As described above, the storage device stores information that can be... Figure 5 and Figures 7-9 The exemplary machine-readable instruction shown corresponds to machine-readable instruction 1632. One or more servers of the exemplary software distribution platform 1905 communicate with an exemplary network 1910, which may correspond to any one or more of the Internet and / or any of the aforementioned exemplary networks. In some instances, one or more servers respond to a request to transmit software to a requesting party as part of a commercial transaction. Payment for the delivery, sale, and / or licensing of the software may be processed by one or more servers of the software distribution platform and / or by a third-party payment entity. The servers enable purchasers and / or licensors to download machine-readable instructions 1532 and 1632 from the software distribution platform 1905. For example, it may be possible to communicate with... Figure 4 and Figure 6The software corresponding to the exemplary machine-readable instructions shown can be downloaded to the exemplary programmable circuit platform 1500, which is used to execute the machine-readable instructions 1532 to implement the first server 102. For example, it can be used with... Figure 5 and Figure 7-9 The software corresponding to the exemplary machine-readable instructions shown can be downloaded to the exemplary programmable circuit platform 1600, which executes the machine-readable instructions 1632 to implement the second server 104. In some instances, one or more servers of the software distribution platform 1905 periodically provide, transmit, and / or force software updates (e.g., Figure 15 The exemplary machine-readable instructions 1532 and Figure 16 The exemplary machine-readable instruction 1632 shown ensures that improvements, patches, updates, etc., are distributed and applied to the software at the end-user device. Although referred to as software above, distributed “software” can also be firmware.

[0137] Based on the foregoing, it should be understood that this document discloses exemplary systems, apparatuses, artifacts, and methods for providing hardware-enforced security for service mesh key management. The disclosed systems, apparatuses, artifacts, and methods improve the efficiency of using computing devices by providing hardware-enforced security for service mesh key management. Therefore, the disclosed systems, apparatuses, artifacts, and methods address one or more improvements to the operation of machines such as computers or other electronic and / or mechanical equipment.

[0138] This document discloses exemplary methods, apparatuses, systems, and artifacts for providing hardware-enforced security for service mesh key management. Further examples and combinations thereof include the following: Example 1 includes a first server for a service mesh, the first server including interface circuitry, machine-readable instructions, and programmable circuitry configured to implement instantiation of the machine-readable instructions or execution of at least one of the machine-readable instructions to detect a second server of the service mesh, store the public key of the second server in a first enclave, and add the second server to the service mesh after obtaining proof of the second enclave.

[0139] Example 2 includes the first server for the service mesh of Example 1, wherein the first server is located on the control plane of the service mesh.

[0140] Example 3 includes the first server for the service mesh of Example 2, wherein the service mesh is used to control the delivery of service requests through the control plane, which creates service instances and exchanges policy and telemetry information with agents on the data plane.

[0141] Example 4 includes the first server for serving the mesh of Example 1, wherein the programmable circuitry is configured to enable the first server to request proof of a first enclave.

[0142] Example 5 includes the first server for serving the mesh of Example 1, wherein the programmable circuitry is used to generate cryptographic measurements for the first enclave.

[0143] Example 6 includes the first server for serving the mesh of Example 5, wherein the programmable circuitry is configured to transmit the cryptographic measurement value to a verification controller to verify the cryptographic measurement value of the first enclave.

[0144] Example 7 includes the first server for serving a mesh of Example 1, wherein the programmable circuitry is used to transmit a key pair from the first server to a key manager to verify the identity of the first server.

[0145] Example 8 includes the first server for a service mesh of Example 1, wherein the programmable circuitry is used to encrypt a private key using the public key of the second server, and the second server is used to deliver the encrypted private key from the first server to a proxy on the gateway of the service mesh.

[0146] Example 9 includes a non-transitory machine-readable storage medium comprising instructions for causing programmable circuitry to at least detect servers of a service mesh, store the public key of the servers in a first enclave, and add the servers to the service mesh after obtaining proof of a second enclave.

[0147] Example 10 includes the non-transitory machine-readable storage medium of Example 9, wherein a first server is provided on the control plane of the service mesh.

[0148] Example 11 includes the non-transitory machine-readable medium of Example 9, wherein a second server is provided on the data plane of the service mesh.

[0149] Example 12 includes the non-transitory machine-readable storage medium of Example 10, wherein the instructions are used to cause the programmable circuitry to cause the first server to request proof of the first enclave.

[0150] Example 13 includes the non-transitory machine-readable storage medium of Example 10, the instructions being used to cause the programmable circuit to generate cryptographic measurements of the first enclave.

[0151] Example 14 includes the non-transitory machine-readable storage medium of Example 13, wherein the instructions are configured to cause the programmable circuitry to transmit the cryptographic measurement value to the authentication controller to verify the cryptographic measurement value of the first enclave.

[0152] Example 15 includes the non-transitory machine-readable storage medium of Example 9, wherein the instructions are used to cause the programmable circuit to encrypt a private key using a public key of a second server, and the first server is used to deliver the encrypted private key to a proxy on the gateway of the service mesh via the second server.

[0153] Example 16 includes a method comprising: detecting a server of a service mesh using programmable circuitry, storing the public key of the server in a first enclave, and adding the server to the service mesh after obtaining proof of a second enclave.

[0154] Example 17 includes the method of Example 16, wherein a first server is set up on the control plane of the service mesh.

[0155] Example 18 includes the method of Example 17, wherein the service mesh is used to control the delivery of service requests through the control plane, which creates service instances and exchanges policies and telemetry information with agents on the data plane.

[0156] Example 19 includes the method of Example 16, wherein a second server is set up on the data plane of the service mesh.

[0157] Example 20 includes the method of Example 16, and also includes generating the cryptographic measurement value for the first enclave.

[0158] Example 21 includes the method of Example 20, and further includes transmitting the cryptographic measurement value to a verification controller to verify the cryptographic measurement value of the first enclave.

[0159] Example 22 includes the method of Example 16, wherein a second server is used to deliver an encrypted private key to a proxy on the gateway of the service mesh.

[0160] It should be noted that this patent claims priority to U.S. Patent Application No. 18 / 477,370, filed September 28, 2023, which is incorporated herein by reference in its entirety, and is a continuation-in-part of International Application No. PCT / CN2023 / 098861, filed June 7, 2023.

[0161] The appended claims are incorporated herein by reference in the detailed description. While exemplary systems, devices, articles of manufacture, and methods have been disclosed herein, the scope of this patent is not limited thereto. Rather, this patent covers all systems, devices, articles of manufacture, and methods that reasonably fall within the scope of the claims of this patent.

Claims

1. A first server for a service mesh, comprising: an interface circuit; machine-readable instructions; and a programmable circuit to perform at least one of instantiating or executing the machine-readable instructions to: detect a second server of the service mesh; store a public key of the second server in a first enclave; and add the second server to the service mesh after obtaining an attestation to a second enclave.

2. The first server for a service mesh of claim 1, wherein the first server is disposed on a control plane of the service mesh.

3. The first server for a service mesh of claim 2, wherein the service mesh is to control delivery of service requests through the control plane, the control plane creating service instances and exchanging policy and telemetry information with proxies on a data plane.

4. The first server for a service mesh of claim 1, wherein the programmable circuit is to cause the first server to request an attestation to the first enclave.

5. The first server for a service mesh of claim 1, wherein the programmable circuit is to generate a cryptographic measurement of the first enclave.

6. The first server for a service mesh of claim 5, wherein the programmable circuit is to cause the cryptographic measurement to be transmitted to an attestation controller to verify the cryptographic measurement of the first enclave.

7. The first server for a service mesh of claim 1, wherein the programmable circuit is to cause a key pair to be transmitted from the first server to a key manager to verify an identity of the first server.

8. The first server for a service mesh of claim 1, wherein the programmable circuit is to encrypt a private key with the public key of the second server, and the second server is to deliver the encrypted private key from the first server to a proxy on a gateway of the service mesh.

9. A non-transitory machine-readable storage medium comprising instructions that cause a programmable circuit to at least: detect a server of a service mesh; store a public key of the server in a first enclave; and add the server to the service mesh after obtaining an attestation to a second enclave.

10. The non-transitory machine-readable storage medium of claim 9, wherein a first server is disposed on a control plane of the service mesh.

11. The non-transitory machine-readable medium of claim 9, wherein a second server is disposed on a data plane of the service mesh.

12. The non-transitory machine-readable storage medium of claim 10, wherein the instructions are to cause the programmable circuit to cause the first server to request an attestation to the first enclave.

13. The non-transitory machine-readable storage medium of claim 10, the instructions are to cause the programmable circuit to generate a cryptographic measurement of the first enclave. ​ ​ 14. The non-transitory machine readable storage medium of claim 13, wherein the instructions are to cause the programmable circuit to transmit the cryptographic measurement to an attestation controller to verify the cryptographic measurement of the first enclave.

15. The non-transitory machine readable storage medium of claim 9, wherein the instructions are to cause the programmable circuit to encrypt a private key with a public key of a second server, and the first server to deliver the encrypted private key to a proxy on a gateway of the service mesh via the second server.

16. A method comprising: detecting, with programmable circuitry, a server of a service mesh; storing a public key of the server in a first enclave; and after obtaining attestation to a second enclave, adding the server to the service mesh.

17. The method of claim 16, wherein the first server is set up on a control plane of the service mesh.

18. The method of claim 17, wherein the service mesh is to control delivery of service requests through the control plane, the control plane creating service instances and exchanging policy and telemetry information with proxies on a data plane.

19. The method of claim 16, wherein the second server is set up on a data plane of the service mesh.

20. The method of claim 16, further comprising generating a cryptographic measurement of the first enclave.

21. The method of claim 20, further comprising causing the cryptographic measurement to be transmitted to an attestation controller to verify the cryptographic measurement of the first enclave.

22. The method of claim 16, wherein the encrypted private key is delivered to a proxy on a gateway of the service mesh using a second server.