Secure multi-part metadata customization for guests

The trusted execution environment uses multipart metadata to verify and decrypt separate integrity measures for secure guests, addressing trust issues in hypervisors by ensuring secure guest integrity and confidentiality, facilitating secure data access without owner interaction.

JP7892049B2Active Publication Date: 2026-07-17INTERNATIONAL BUSINESS MACHINE CORPORATION

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
INTERNATIONAL BUSINESS MACHINE CORPORATION
Filing Date
2022-08-03
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Conventional hypervisors lack the ability to fully trust secure guests, leading to potential integrity and confidentiality issues in virtualized environments, as they can inspect and modify secure guest memory, compromising the protection of sensitive data.

Method used

Implementing a trusted execution environment that uses multipart metadata to separately manage vendor-specific and customer-specific sensitive data, ensuring integrity and confidentiality by performing independent integrity checks on each metadata part before starting the secure guest.

Benefits of technology

Ensures secure guest integrity and confidentiality by allowing independent verification and decryption of metadata parts, enabling secure guest access to sensitive data without requiring guest owner interaction or image modification, thus maintaining protection and simplifying processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007892049000001
    Figure 0007892049000001
  • Figure 0007892049000002
    Figure 0007892049000002
  • Figure 0007892049000003
    Figure 0007892049000003
Patent Text Reader

Abstract

The trusted execution environment obtains a secure guest image and metadata used to initiate the secure guest. The metadata includes a plurality of portions and a plurality of integrity measures. A first portion of the metadata includes one or more integrity measures of the plurality of integrity measures, and a second portion of the metadata includes customized sensitive data of the secure guest and one or more other integrity measures of the plurality of integrity measures. The trusted execution environment is used to validate at least one selected portion of the metadata using at least one integrity measure of the plurality of integrity measures of the metadata. Based on successful validation of the at least one selected portion of the metadata, the trusted execution environment initiates the secure guest using the secure guest image and at least a portion of the metadata.
Need to check novelty before this filing date? Find Prior Art