Secure multi-part metadata customization for guests
The trusted execution environment uses multipart metadata to verify and decrypt separate integrity measures for secure guests, addressing trust issues in hypervisors by ensuring secure guest integrity and confidentiality, facilitating secure data access without owner interaction.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- INTERNATIONAL BUSINESS MACHINE CORPORATION
- Filing Date
- 2022-08-03
- Publication Date
- 2026-07-17
AI Technical Summary
Conventional hypervisors lack the ability to fully trust secure guests, leading to potential integrity and confidentiality issues in virtualized environments, as they can inspect and modify secure guest memory, compromising the protection of sensitive data.
Implementing a trusted execution environment that uses multipart metadata to separately manage vendor-specific and customer-specific sensitive data, ensuring integrity and confidentiality by performing independent integrity checks on each metadata part before starting the secure guest.
Ensures secure guest integrity and confidentiality by allowing independent verification and decryption of metadata parts, enabling secure guest access to sensitive data without requiring guest owner interaction or image modification, thus maintaining protection and simplifying processing.
Smart Images

Figure 0007892049000001 
Figure 0007892049000002 
Figure 0007892049000003