Method and system for creating confidential cloud computing platform in disaggregated architecture
The method and system address the challenge of protecting distributed components in disaggregated cloud architectures by implementing an attestation and key management system to create confidential VMs, ensuring secure and efficient resource utilization and data confidentiality in disaggregated cloud computing platforms.
Patent Information
- Application Number
- PCT/EP2024/058562
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-28
- Publication Date
- 2025-10-02
AI Technical Summary
Conventional cloud computing platforms struggle to protect distributed components across disaggregated resource architectures due to the limitations of device-specific Trusted Execution Environments (TEEs), which are not well-suited for the distributed and heterogeneous nature of disaggregated architectures, leading to challenges in scalability, uniform attestation, and secure resource management.
A method and system for creating a confidential cloud computing platform with confidential virtual machines (VMs) in a disaggregated architecture, utilizing an attestation and key management system to enforce security policies, allocate resources dynamically, and perform attestation on processor and storage hardware resources, ensuring secure and efficient resource utilization.
The solution provides a secure and efficient environment for confidential computing, ensuring data integrity and confidentiality by encapsulating user applications within confidential VMs, leveraging TEEs for enhanced security and integrity, and facilitating seamless resource allocation and management.
Smart Images

Figure EP2024058562_02102025_PF_FP_ABST
Abstract
Description
[0001] METHOD AND SYSTEM FOR CREATING CONFIDENTIAL CLOUD COMPUTING PLATFORM IN DISAGGREGATED ARCHITECTURE
[0002] TECHNICAL FIELD
[0003] The present disclosure relates generally to the field of cloud computing and more specifically, to a method and a system for creating a confidential cloud computing platform including at least one of a plurality of confidential virtual machines (VMs) in a disaggregated resource architecture.
[0004] BACKGROUND
[0005] Evolving demands for better performance in cloud data centres are driving a fundamental change in cloud infrastructure. Conventional monolithic architecture, where hardware resources, such as CPUs, accelerators, and memory are tied to a machine limits the flexibility in managing resources. In traditional cloud data centres, the deployment unit is a monolithic server, which includes all necessary hardware resources (mainly CPU, RAM, network, and disks) to run applications. The conventional monolithic architecture has two main limitations i.e., difficulty in achieving full resource utilization and coarse granularity for hardware maintenance. Disaggregated architecture emerges as a solution by overcoming the limitations to achieve full resource utilization and coarse granularity for hardware maintenance.
[0006] The disaggregated architecture addresses these limitations by allowing each resource to be managed (maintenance, allocation) independently. Memory and hardware accelerators can be dynamically assigned to processing units to boost application performance, while high-speed, low-latency electrical and optical interconnect is a prerequisite for realizing the concept of data centre disaggregation. The disaggregated Architecture aims to loosen the strong coupling between compute, storage / memory, and network elements within a single machine. Generally, the disaggregated architecture fails to adapt to conventional Trusted Execution Environment (TEE) technologies due to its distributed and heterogeneous nature. Prominent cloud service providers provide platforms for confidential cloud computing that use TEEs to protect sensitive data. However, the disaggregated architecture presents distinct difficulties that limit the efficient utilization of current TEE technology. Scalability, uniform attestation methods, and transparent support for confidential virtual machines on the disaggregated architectures have been lacking in conventional cloud computing systems.
[0007] Conventionally, cloud computing platform services include a remote attestation mechanism that enables customers to remotely verify the security and integrity of the firmware, software, and hardware configuration of a target customer service deployed on the cloud. Modem cloud workloads, such as Al applications, e.g., large language model-based services, often handle large amounts of confidential and security-sensitive private data, including medical data, voice / video recordings, and even financial information. In order to protect the large amount of data being operated on, it is important to ensure that machine learning models, calculations, and queries are not exposed to or manipulated by any unauthorized party, including software run by other tenants, OS / hypervisors, devices, and networking infrastructure. Hence, the data in transit between distributed heterogeneous compute and storage components are protected and attested to for their authenticity and integrity before any component becomes involved in any computation. The TEEs have been studied for decades to ensure code integrity and provide strong isolation from untrusted parties. TEEs offer a hardware-assisted isolated environment, called an “enclave”, to execute securitysensitive workloads, where application code and data is protected from other cloud tenants and applications, even from compromised privileged software.
[0008] Furthermore, the cloud computing platform does not offer confidential computing services on top of the disaggregated architecture. While the TEEs provide essential security features in the conventional cloud computing systems, the TEEs have not been well-applied for the disaggregated architecture as the conventional TEE technologies are device-specific, and the protection domains of conventional TEE technologies are limited to target devices. The disaggregated architecture deploys user code and data across an arbitrary set of various hardware components, making it difficult for such device-specific TEEs to protect all the distributed components of an application. Thus, there exists a technical problem of how to protect distributed components across the disaggregated resource architectures in cloud computing platforms.
[0009] Therefore, in light of the foregoing discussion, there exists a need to overcome the aforementioned drawbacks associated with the conventional methods and conventional systems of creating a confidential cloud computing platform including at least one of a plurality of confidential virtual machines (VMs) in a disaggregated resource architecture.
[0010] SUMMARY
[0011] The present disclosure provides a method and a system for creating a confidential cloud computing platform including at least one of a plurality of confidential virtual machines (VMs) in a disaggregated resource architecture. The present disclosure provides a solution to the existing problem of how to protect distributed components across the disaggregated resource architectures in cloud computing platforms. An objective of the present disclosure is to provide a solution that overcomes at least partially the problems encountered in the prior art and provides an improved method and an improved system for creating the confidential cloud computing platform including at least one of the plurality of confidential virtual machines (VMs) in the disaggregated resource architecture (e.g., a confidential disaggregated architecture).
[0012] One or more objectives of the present disclosure are achieved by the solutions provided in the enclosed independent claims. Advantageous implementations of the present disclosure are further defined in the dependent claims.
[0013] In one aspect, the present disclosure provides a method of creating a confidential cloud computing platform including at least one of a plurality of confidential virtual machines (VMs) in a disaggregated resource architecture. The method includes receiving a security policy from a user at an attestation and key management system, where the security policy includes public keys to be used for the user’s at least one confidential VM. The method further includes receiving from a user at a disaggregated resource cloud gateway a request to create at least one confidential VM according to the received security policy and receiving from the cloud gateway at a cloud scheduler system the request to create at least one confidential VM on top of the disaggregated resource architecture. Furthermore, the method includes the cloud scheduler system interacting with monitoring agents in a plurality of compute pools comprising a plurality of processor hardware resources and a plurality of storage pools comprising a plurality of storage hardware resources to obtain availability information regarding the processor hardware resources and the storage hardware resources and the cloud scheduler system allocates processor hardware resources and storage hardware resources to the at least one confidential VM based on the results, to thereby create the at least one confidential VM. Moreover, the attestation and key management system performs attestation for the allocated processor hardware resources and the allocated storage hardware resources.
[0014] Advantageously, the method is used to build confidential computing services (i.e., the confidential VMs) along with the disaggregated architecture thereby, allowing users to run existing applications while keeping the internet protocol (code, data) confidential. In addition, the method is also used to provide an end-to-end workflow of how to create and attest the confidential VMs on top of the disaggregated architecture. The security policies are used to maintain the data security and the data confidentiality of the at least one confidential virtual machine (VM). Furthermore, the attestation and key management system serves as a centralized system for managing the security policies in order to ensure the data integrity and data security by verifying the security standards through the security policies and providing an assurance against any unauthorized access. The interaction between the attestation and key management system, the cloud scheduler system, and monitoring agents ensures seamless integration of security measures with resource allocation decisions that facilitate a cohesive workflow within the confidential cloud computing platform for the creation of at least one of the plurality of confidential virtual machines (VMs). The disaggregated resource cloud gateway provides a user-friendly interface for initiating the creation of the at least one of the plurality of confidential VMs based on the security policies. The cloud scheduler system is configured to allocate resources by interacting with monitoring agents dynamically to provide an optimized resource utilization in real-time or near real-time. As a result, the method is used to provide an efficient and reliable resource utilization along with a centralized security management, a robust attestation, and a key management system to provide a confidential cloud environment along with an enhanced data security and user experience.
[0015] In an implementation form, a user application runs in the at least one confidential virtual machine (VM) in the confidential cloud computing platform according to a disaggregated resource architecture.
[0016] By virtue of running the user application in at least one confidential virtual machine (VM) in the confidential cloud computing platform, the method ensures security by encapsulating the user application within the confidential VM, leveraging the protective features of TEEs, thereby increasing the confidentiality and integrity of the user application's code and data.
[0017] In another implementation form, the confidential VM includes a disaggregated operating system.
[0018] Advantageously, the inclusion of the disaggregated operating system within the confidential virtual machine (VM) enables independent management of resources within the confidential VM. The independent management of the resources within the confidential VM facilitates efficient resource allocation, optimal utilization, and adaptability to varying workloads.
[0019] In another implementation form, at least one of the plurality of storage hardware resources and at least one of the plurality of processor hardware resources includes a Trusted Execution Environment (TEE) module.
[0020] The inclusion of the TEE elements within the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources enhances the overall security of the confidential cloud computing platform by providing a dedicated and secure enclave for critical operations. The TEE elements ensure the confidentiality and integrity of the data and computations, protecting the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources from unauthorized access or tampering, securing the entire platform against potential threats.
[0021] In a further implementation form, the TEE elements perform a measurement of a software component of the least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources which include the TEE elements and uses the measurement to create a proof for its respective hardware resource and sends the proof to the attestation and key management system.
[0022] The measurement of a software component of the least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources and the creation of proof for its respective hardware resource and sending the proof to the attestation and key management system provides enhanced security and integrity assurance of both the least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources within the confidential cloud computing platform. Upon utilization of the proof of measurement of the software component, the TEE elements ensures the verifiable trustworthiness of the associated software components, guarding against unauthorized access or tampering and providing a secure architecture.
[0023] In a further implementation, a security controller is provided as part of a TEE elements and the security controller performs a measurement of a software component of the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources which do not include a TEE elements and uses the measurement to create a proof for a respective hardware resource and sends the proof to the attestation and key management system.
[0024] The integration of the security controller extends the security measures to the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources that do not include the TEE elements. After conducting the measurement of the software component, the security controller generates a proof specific to each hardware resource. The proof is then transmitted to the attestation and key management system, contributing to the overall security of the non-TEE-equipped storage hardware resources and processor hardware resources.
[0025] In a further implementation, the attestation and key management system performs attestation for the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources.
[0026] By virtue of performing the attestation for the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources, the attestation and key management system provides robust security assurance for both the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources within the confidential cloud computing platform.
[0027] In a further implementation, the attestation and key management system provides a certificate to the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor resources, according to the performance of the attestation.
[0028] The issuance of certificates by the attestation and key management system to at least one storage hardware resource and at least one processor resource based on the performance of attestation establishes verifiable and documented proof of the integrity and security status of the storage hardware resources and the processor hardware resources.
[0029] In a further implementation, the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources communicate with each other using the certificate provided by the attestation and key management system.
[0030] By virtue of utilizing the certificates provided by the attestation and key management system as a means of authentication, the attestation and key management system ensures that the communication between the storage hardware resources and processor hardware resources is not only encrypted but also verified, preventing unauthorized access and tampering.
[0031] In another aspect, a system comprising means adapted for carrying out all the steps of the method according to any preceding method claim.
[0032] The disclosed system achieves all the advantages and technical effects of the method of creating the confidential cloud computing platform of the present disclosure.
[0033] It is to be appreciated that all the aforementioned implementation forms can be combined.
[0034] It has to be noted that all devices, elements, circuitry, units, and means described in the present application could be implemented in the software or hardware elements or any kind of combination thereof. All steps which are performed by the various entities described in the present application as well as the functionalities described to be performed by the various entities are intended to mean that the respective entity is adapted to or configured to perform the respective steps and functionalities. Even if, in the following description of specific embodiments, a specific functionality or step to be performed by external entities is not reflected in the description of a specific detailed element of that entity which performs that specific step or functionality, it should be clear for a skilled person that these methods and functionalities can be implemented in respective software or hardware elements, or any kind of combination thereof. It will be appreciated that features of the present disclosure are susceptible to being combined in various combinations without departing from the scope of the present disclosure as defined by the appended claims.
[0035] Additional aspects, advantages, features, and objects of the present disclosure would be made apparent from the drawings and the detailed description of the illustrative implementations construed in conjunction with the appended claims that follow.
[0036] BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The summary above, as well as the following detailed description of illustrative embodiments, is better understood when read in conjunction with the appended drawings. For the purpose of illustrating the present disclosure, exemplary constructions of the disclosure are shown in the drawings. However, the present disclosure is not limited to specific methods and instrumentalities disclosed herein. Moreover, those in the art will understand that the drawings are not to scale. Wherever possible, like elements have been indicated by identical numbers.
[0038] Embodiments of the present disclosure will now be described, by way of example only, with reference to the following diagrams wherein:
[0039] FIG. 1 is a diagram that depicts at least one of a plurality of confidential virtual machines in a disaggregated architecture, in accordance with an embodiment of the present disclosure;
[0040] FIG. 2 is a diagram that depicts an interaction of non-trusted execution environment elements with trusted execution environment elements, in accordance with an embodiment of the present disclosure;
[0041] FIG. 3 is a diagram that depicts a system for creating a confidential cloud computing platform including at least one of a plurality of confidential virtual machines (VMs), in accordance with an embodiment of the present disclosure;
[0042] FIG. 4 is a diagram that depicts a remote attestation of hardware and storage resources of the at least one of the plurality of confidential virtual machines (VMs), in accordance with another embodiment of the present disclosure; and
[0043] FIG. 5 is a flow chart that depicts a method of creating the confidential cloud computing platform including the at least one of the plurality of confidential virtual machines (VMs), in a disaggregated resource architecture, in accordance with an embodiment of the present disclosure.
[0044] In the accompanying drawings, an underlined number is employed to represent an item over which the underlined number is positioned or an item to which the underlined number is adjacent. A non-underlined number relates to an item identified by a line linking the non-underlined number to the item. When a number is non-underlined and accompanied by an associated arrow, the non-underlined number is used to identify a general item at which the arrow is pointing.
[0045] DETAILED DESCRIPTION OF EMBODIMENTS
[0046] The following detailed description illustrates embodiments of the present disclosure and ways in which they can be implemented. Although some modes of carrying out the present disclosure have been disclosed, those skilled in the art would recognize that other embodiments for carrying out or practicing the present disclosure are also possible. FIG. 1 is a diagram that depicts at least one of a plurality of confidential virtual machines in a disaggregated architecture, in accordance with an embodiment of the present disclosure. With reference to FIG. 1, there is shown a block diagram 100 comprising a compute pool 102 and a storage pool 104 connected with each- other through a high-speed network 108 and at least one of a plurality of confidential virtual machines (VM) 110, which is connected with another virtual machine (VM) 112. The at least one of the plurality of confidential virtual machines 110 comprises a distributed hypervisor 136.
[0047] The compute pool 102 refers to a collection of a plurality of processor hardware resources organized in a disaggregated manner, which operates as a dynamic and flexible resource allocation system within a confidential cloud computing platform. Furthermore, the compute pool 102 includes a central processing unit (CPU) pool 114, an XPU pool 116, and a field- programmable gate array (FPGA) pool 118. The CPU pool 114 refers to processor hardware resources that are used to cater to general-purpose computing requirements. The XPU pool 116 refers to accelerators (e.g., general processing unit (GPU), neural processing unit (NPU), and the like) within the compute pool 102 that go beyond traditional Central Processing Units CPUs and are used to address specific computational requirements of the users within the confidential cloud computing platform. Moreover, the FPGA pool 118 refers to the processor hardware resources that are used to execute specialized algorithms or tasks.
[0048] The storage pool 104 is a collection of a plurality of storage hardware resources, which operates as a centralized and dynamic resource management system within a confidential cloud computing platform to fulfil the data storage requirements of users. The storage pool 104 includes a memory (MEM) pool 120, a solid-state drive (SSD) pool 122, and a hard disk drive (HDD) pool 124.
[0049] The high-speed network 108 refers to a communication infrastructure that enables fast and efficient data transfer between different hardware and storage resources, such as the processor hardware resources of the compute pool 102 and the storage hardware resources of the storage pool 104. The high-speed network 108 is capable of transmitting data at rates that exceed typical network speeds, providing the necessary bandwidth to accommodate the demands of modem, data-intensive applications.
[0050] The at least one of the plurality of confidential virtual machines 110 and the other VM 112 refers to a virtual machine that is configured to provide a secure and confidential execution environment for the user application 126 and the data to a user 106. Moreover, the at least one of the plurality of confidential VM 110 includes a virtual central processing unit (vCPU) 128, a virtual general purpose unit (vGPU) 130, a vFPGA 132, and a vMEM 134. The at least one of the plurality of confidential VM 110 further includes the user application 126 which is a software or program that is executed within the at least one of the plurality of confidential VM 110 in the confidential cloud computing platform and encompasses the tasks and computations by the user 106 that are initiated in a secure and isolated environment.
[0051] In an implementation scenario, to build a confidential computing service in a disaggregated architecture, existing trusted execution environments (TEEs) cannot be applied on monolithic servers due to the distributed nature and device heterogeneity of the disaggregated resource architecture. Moreover, the existing TEEs are device-specific, and the protection domains of the existing TEEs are also limited to certain target devices. In addition, the disaggregated resource architecture deploys a user code and the data across an arbitrary set of the plurality of hardware resources (i.e., the compute pool 102 and the storage pool 104), making it difficult to protect all the distributed plurality of hardware resources of user applications. The distributed hypervisor 136 acts as an intermediary layer between the physical hardware (e.g., a first hardware 138A, a second hardware 138B, a third hardware 138C, and a fourth hardware 138D) and the virtualized components. For example, the distributed hypervisor 136 acts as the intermediary layer between the vCPU 128 and a CPU 140, the vGPU 130 and an XPU 142, the vFPGA 132, and a FPGA 144 along with the vMEM 134 and a MEM 146. Typically, the end-to-end security for user application 126 deployed across different hardware resources is difficult to ensure due to the heterogeneity of the disaggregated architecture. Moreover, the plurality of processor hardware resources (e.g., the CPU pool 114, the XPU pool 116, and the FPGA pool 118) and the plurality of storage hardware resources (e.g., the MEM pool 120, the SSD pool 122, and the EIDD pool 124.) have different root of trust and includes both, TEE and non-TEE devices that creates challenges in remote attestation and to establish a trustworthy environment to the at least one of the plurality of confidential VM 110 built in the disaggregated architecture. Therefore, the disaggregated resource architecture provides high flexibility for resource allocation, allowing resources to be allocated and reallocated as needed, leading to more efficient resource utilization with an improved resource utilization by decoupling resources from specific servers. Furthermore, the disaggregated resource architecture facilitates a quick adoption of new- generation components in data centres through function disaggregation in order to achieve 10-100 times larger CPU and memory capacity, along with 100 times larger bandwidth compared to server-centric architectures thereby, enhancing the overall capacity and the overall performance of the at least one of the plurality of confidential virtual machines 110.
[0052] FIG. 2 is a diagram that depicts an interaction of non-trusted execution environment elements with trusted execution environment elements, in accordance with an embodiment of the present disclosure. With reference to FIG. 2, there is shown an exemplary diagram 200 depicting a Trusted Execution Environment (TEE) module 202 comprising a security controller 204 and an authentication and access controller 206. The TEE elements 202 interacts with a non-TEE FPGAs 218, a Non-TEE GPUs 220, and a Non-TEE MEMs 222.
[0053] In an implementation scenario, the TEE elements 202 (e.g., an AMD SEV SNP, an ARM CCA, and the like) refers to a secure area that helps to protect a code and the data loaded inside the processor from an unauthorized access or an unauthorized modification. Moreover, the TEE elements 202 is configured to keep code and data of trusted user applications confidential, intact, and isolated on a device and can also resist tampering and leakage from software or physical attacks, even from privileged code. The security controller 204 is configured to enable security features for non-TEE elements (i.e., the non-TEE FPGAs 218, the non-TEE GPUs 220, and the non-TEE MEM 222). The security controller 204 acts as a mediator between the TEE elements 202 and the non-TEE elements in order to provide secure boot, isolation, trusted path, and remote attestation to the non-TEE elements. The security controller 204 is a controller with a hardware root of trust that can isolate (i.e. , by enforcing isolation 212) its own memory to ensure that each non-TEE element is assigned to a single tenant and is not shared with any other tenants or services in the disaggregated architecture. The security controller 204, configured inside the TEE elements 202, is configured to protect communication between the TEE elements 202 and the non-TEE elements by performing authenticated encryption and decryption 214 using a shared secret provision during user setup and enforces an access control by checking if a source and a destination belong to the same user application or not. Furthermore, the security controller 204 allows or blocks the communication between the source and the destination (i.e., between the TEE elements 202 and the non- TEE elements) accordingly. The security controller 204 is physically connected to the non-TEE elements and creates a locally unique identity for each of the non-TEE elements during a start-up. Moreover, the security controller 204 also maintains an input and output buffer for the non-TEE elements and allocates non-overlapping regions to ensure isolated access. Additionally, the security controller 204 also keeps track of the non-TEE elements that belong to the same application or the confidential virtual machine to enforce access control. In an implementation, the security controller 204 runs inside the TEE elements 202 and can be attested by users (e.g., the user 106 of FIG. 1). In an implementation, the authentication and access controller 206 is configured to manage and control the authentication and access rights of entities interacting with the TEE elements 202, such as by verifying the identity of users or components seeking access to the TEE elements 202, ensuring that only authorized entities are granted entry. Moreover, a scheduling 216 helps in adapting and managing the execution of tasks and jobs for non- TEE elements. Typically, to securely run an application in a cloud, the user uses a confidential computing service to run the application inside secure enclaves. Therefore, a remote attestation mechanism is required to allow the user to attest the execution of the application deployed in a remote environment. Conventionally, the remote attestation mechanism offers TEE elements 202 to ensure the integrity of the application at the start of an enclave. However, the application dynamically loads libraries and configurations during runtime, which can add vulnerabilities to the application that cannot be further detected by the TEE elements 202. Therefore, it is required to measure the dynamic behaviour of the application. In addition, the TEE elements 202 offers different formats regarding attestation report, which is required to be converted from all different formats into a unified attestation format. The measurement function involves the systematic assessment and recording of various aspects that define the behaviour and integrity of applications or elements within the TEE elements. The measurement 208 and attestation 210 capture a comprehensive snapshot of the runtime environment, including dynamically loaded libraries and configurations during application execution, ensuring that the measurement accurately reflects the current and dynamic state of the system. Moreover, the attestation function leverages measurement data to establish the integrity and legitimacy of the TEE elements 202 to external entities and allows users or external systems to verify the confidentiality and integrity of applications running within the TEE elements 202, safeguarding against potential attacks or unauthorized interference. The attestation 210 acts as a means for users to trust and verify the secure execution of applications within a remote environment, providing assurance that the TEE elements 202 is operating as intended and has not been compromised.
[0054] FIG. 3 is a diagram that depicts a system for creating a confidential cloud computing platform including at least one of a plurality of confidential virtual machines (VMs), in accordance with an embodiment of the present disclosure, in accordance with an embodiment of the present disclosure. FIG. 3 is described in conjunction with elements from FIG. 1 and FIG. 2. With reference to FIG. 3, there is shown an illustration of a system 300 that includes a user 302, an attestation and key management system 306, a disaggregated resource cloud gateway 310, a cloud scheduler system 314, a disaggregated operating system 320, and a combination of security systems 322 including Trusted execution environment (TEE), Hardware security module (HSM) and Trusted platform module (TPM).
[0055] The attestation and key management system 306 is configured to handle and manage the decryption and encryption keys for functions operating within enclaves. Moreover, the attestation and key management system 306 is also configured to store the keys and provide the keys to the at least one of the plurality of confidential virtual machines (VMs), such as the at least one confidential VM 110 running the user application 126 after verifying the keys.
[0056] There is provided the system 300 for creating the confidential cloud computing platform including at least one of the plurality of confidential virtual machines 110 in the disaggregated resource architecture.
[0057] The attestation and key management system 306 is configured to receive the security policy from the user 302. The security policy 304 includes public keys to be used for the user’s at least one confidential VM 110. The attestation and key management system 306 is configured to receive the security policy 304 from the user 302. The security policy 304 includes public keys to be used for the at least one of the plurality of confidential VM 110. The security policy 304 serves as a set of guidelines and configurations, outlining how the security features for the at least one of the plurality of confidential VMs 110 should be managed. The public keys are used to perform an encryption and decryption within the confidential VM, ensuring the confidentiality and integrity of the user application code and the data of the user application 126. The attestation and key management system 306 utilizes the security policy 304 to enforce security measures and manage cryptographic keys, providing a secure environment for the operation of the at least one of the plurality of confidential VMs 110.
[0058] Furthermore, the disaggregated resource cloud gateway 310 is configured to receive a request from the user 302 to create at least one confidential VM 110 according to the received security policy 304, such as at operation 308, such as at operation 312. The disaggregated resource cloud gateway 310 acts as an intermediary responsible for routing requests and managing interactions between the user 302 and the cloud computing platform infrastructure. The disaggregated resource cloud gateway 310 efficiently directs the requests to create the at least one of the plurality of confidential VM 110 according to the security policy 304. As a result, the disaggregated resource cloud gateway 310 provides an efficient routing, security policy enforcement, and specialized handling of user requests for creating confidential VMs within the disaggregated architecture. Furthermore, the cloud scheduler system 314 is configured to receive a request from the disaggregated resource cloud gateway 310 to create at least one confidential VM 110 on top of the disaggregated resource architecture. In other words, the cloud scheduler system 314 is configured to initiate the request of creating the at least one of the plurality of confidential VM 110 on the top of the disaggregated architecture. By receiving requests from the disaggregated resource cloud gateway 310, the cloud scheduler system 314 helps in orchestrating the deployment of confidential virtual machines (VMs), contributing to the overall functionality and responsiveness of the cloud computing platform.
[0059] Furthermore, the cloud scheduler system 314 interacts with monitoring agents in a plurality of compute pools 102 comprising a plurality of processor hardware resources and a plurality of storage pools 104 comprising a plurality of storage hardware resources to obtain availability information regarding the processor hardware resources and the storage hardware resources. The cloud scheduler system 314 is configured to collect the information with respect to the monitoring agents in the plurality of compute pools 102 comprising a plurality of processor hardware resources (e.g., CPUs, XPUs, GPUs, NPUs, TPUs, or FPGAs) and the plurality of storage pools 104 comprising a plurality of storage hardware resources (e.g., DRAM, SSDs, HDDs). In an implementation, at operation 316, the cloud scheduler system 314 is configured to launch a new confidential virtual machine, and at operation 318, the cloud scheduler system 310 is configured to receive a resource update from the plurality of hardware resources and the plurality of storage resources. By obtaining real-time availability information, the cloud scheduler system 314 can make informed decisions about where to allocate or reallocate the plurality of hardware resources based on the current state of the plurality of compute pool 102 and the plurality of storage pool 104 to optimize resource utilization and enhance the overall performance of the cloud computing platform.
[0060] In accordance with an embodiment, the plurality of storage hardware resources includes DRAM, SSD, or HDD hardware resources. In an implementation, the plurality of storage hardware resources includes Dynamic Random-Access Memory (DRAM). In another implementation, the plurality of storage hardware resources includes Solid State Drive (SSD). In yet another implementation, the plurality of storage hardware resources includes Hard Disk Drive (HDD). Therefore, a diverse plurality of storage hardware resources can be utilized by the system 300 for different functionalities, such as the DRAM can be used for volatile and high-speed memory, the SSD can be used for faster and non-volatile storage using flash memory, and the HDD can be used for traditional, larger-capacity, and slower mechanical disk-based storage. As a result, the plurality of storage hardware resources provides flexibility to cater to different performance and capacity requirements within the system 300.
[0061] In accordance with an embodiment, the plurality of processor hardware resources includes CPU, XPU, GPU, NPU, TPU, or FPGA hardware resources. In an implementation, the plurality of processor hardware resources includes the central processing unit (CPU) to handle general-purpose computing tasks. In another implementation, the plurality of processor hardware resources includes an Accelerated Processing Unit (XPU) to accelerate specific workloads. In yet another implementation, the plurality of processor hardware resources includes a general processing unit (GPU) to excel in graphics-related computations. In another implementation, the plurality of processor hardware resources includes a Neural Processing Unit (NPU) to perform optimized neural network tasks. In yet another implementation, the plurality of processor hardware resources includes a Tensor Processing Unit (TPU) for machine learning-related computations. In another implementation, the plurality of processor hardware resources includes a Field-Programmable Gate Array (FPGA) for flexibility for custom hardware acceleration. Similarly, other hardware resources can also be included in the plurality of processor hardware resources without affecting the scope of the present disclosure. As a result, such inclusion of the plurality of processor hardware resources offers versatility to address various computational requirements within the broader context of the system 300.
[0062] Furthermore, the cloud scheduler system 314 allocates processor hardware resources and storage hardware resources to the at least one confidential VM 110 based on the availability of information regarding the processor hardware resources and the storage hardware resources, thereby creating the at least one confidential VM 110. The cloud scheduler system 314 first receives the request and then collects essential monitoring information regarding the current availabilities of the processor hardware resources and of the storage hardware resources in the compute pool 102 and the storage pool 104. After obtaining the information, the cloud scheduler system 314 is configured to allocate processor hardware resources and storage hardware resources to the at least one confidential VM 110 based on the availability of information regarding the processor hardware resources and the storage hardware resources, thereby creating the at least one of the plurality of confidential VM 110. As a result, the cloud scheduler system 314 is configured to ensure a judicious and efficient allocation of the hardware resources and allow the at least one of the plurality of confidential VM 110 to adapt workload variations, enhancing reliability, and responsiveness in meeting user demands.
[0063] In accordance with an embodiment, the confidential VM 110 includes the disaggregated operating system 320. The disaggregated operating system 320 (or a lightweight disaggregated operating system) is configured to operate as an underlying software layer responsible for managing the isolation and encryption of user applications 126. The disaggregated operating system 320 collaborates with the security controller 204 and the hardware Trusted Execution Environment (TEE) elements (e.g., a first TEE element 334A, a second TEE element 334B, a third TEE element 334C, and a fourth TEE element 334D) attached to the plurality of compute pool 102 and the plurality of storage pool 104 to ensure the secure execution of applications within the VMs to provide a seamless and user-friendly experience.
[0064] Moreover, the attestation and key management system 306 performs attestation for the allocated processor hardware resources and the allocated storage hardware resources. In other words, the attestation and key management system 306 performs the process of verifying and confirming the integrity and trustworthiness of both the allocated processor hardware resources and the allocated storage hardware resources within the confidential cloud computing platform, such as at operation 324. The attestation and key management system 306 initiates an attestation procedure for each of these resource types and performs attestation by examining various security parameters and measurements associated with the processor and storage hardware elements which may include verifying the integrity of the boot process, ensuring the absence of unauthorized modifications, and confirming that the hardware resources are running as per the expected and unmodified code.
[0065] In accordance with an embodiment, the attestation and key management system 306 performs attestation for the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources. In an implementation, the attestation and key management system 306 performs attestation for the at least one of the plurality of storage hardware resources. In another implementation, the attestation and key management system 306 performs attestation for the at least one of the plurality of processor hardware resources. In yet another implementation, the attestation and key management system 306 performs attestation for the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources. Advantageously, the attestation process performed by attestation and key management system 306 is used for maintaining the integrity of the created at least one of the plurality of confidential virtual machines 110 and preventing potential security risks or unauthorized access to confidential VMs and associated data.
[0066] In accordance with an embodiment, the attestation and key management system 306 provides a certificate to the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor resources, according to the performance of the attestation. In an implementation, the attestation and key management system 306 provides the certificate to the at least one of the plurality of storage hardware resources, according to the performance of the attestation for the at least one of the plurality of storage hardware resources. In another implementation, the attestation and key management system 306 provides the certificate to the at least one of the plurality of processor hardware resources, according to the performance of the attestation for the at least one of the plurality of processor hardware resources. In yet another implementation, the attestation and key management system 306 provides the certificate to the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources, according to the performance of the attestation for the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources. Advantageously, the providing certificate by the attestation and key management system 306 helps in establishing verifiable and documented proof of the integrity and security status of the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor resources.
[0067] In accordance with an embodiment, the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources communicate with each other using the certificate provided by the attestation and key management system 306. Therefore, the secure and trustworthy communication facilitated by the use of certificates the at least one storage hardware resource and at least one processor hardware resource engages in communication between the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources by the attestation and key management system 306 thereby, ensuring the integrity and authenticity of the communicating entities.
[0068] In accordance with an embodiment, the at least one of the plurality of storage hardware resources and at least one of the plurality of processor hardware resources includes a Trusted Execution Environment (TEE) elements. In an implementation, the at least one of the plurality of storage hardware resources includes the TEE elements. In another implementation, the at least one of the plurality of processor hardware resources includes the TEE elements. In yet another implementation, the at least one of the plurality of storage hardware resources and at least one of the plurality of processor hardware resources includes the TEE elements. The inclusion of the TEE elements within the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources enhances the overall security of the confidential cloud computing platform by providing a dedicated and secure enclave for critical operations. The TEE elements ensure the confidentiality and integrity of the data and computations, protecting the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources from unauthorized access or tampering, securing the entire platform against potential threats.
[0069] In accordance with an embodiment, the TEE elements performs a measurement of a software component of the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources which include the TEE elements and uses the measurement to create a proof for its respective hardware resource and sends the proof to the attestation and key management system 306. In an implementation, the TEE elements performs a measurement of a software component of the at least one of the plurality of storage hardware resources which include the TEE elements. In another implementation, the TEE elements performs a measurement of a software component of the at least one of the plurality of processor hardware resources which include the TEE elements. In yet another implementation, the TEE elements performs a measurement of a software component of the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources which include the TEE elements. The measurement of a software component of the least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources and the creation of proof for its respective hardware resource and sending the proof to the attestation and key management system 306 provides enhanced security and integrity assurance of both the least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources within the confidential cloud computing platform. For example, by sending a notification to the attestation and key management system 306 for automatic and transparent remote attestation, such as at operation 328. Upon utilization of the proof of measurement of the software component, the TEE elements ensure the verifiable trustworthiness of the associated software components, guarding against unauthorized access or tampering and providing a secure architecture.
[0070] In accordance with an embodiment, at least one of the plurality of storage hardware resources and at least one of the plurality of processor hardware resources does not include a TEE elements. In an implementation, at least one of the plurality of storage hardware resources does not include a TEE elements. In another implementation, at least one of the plurality of processor hardware resources does not include a TEE elements. In yet another implementation, at least one of the plurality of storage hardware resources and at least one of the plurality of processor hardware resources does not include a TEE elements. By virtue of not including the TEE elements, the cloud computing platform introduces versatility, allowing for the inclusion of hardware resources without TEE elements while still being part of the cloud computing platform. The flexibility is advantageous when dealing with diverse applications and workloads that may not require security measures provided by the TEE elements. Thus, the cloud computing platform can cater to a variety of computing needs, optimizing resource allocation based on the specific security requirements of different tasks, thereby enhancing scalability and adaptability, making the confidential cloud computing platform suitable for a broader range of applications while maintaining a robust security framework where needed and helps in achieving a balanced and flexible approach within the confidential cloud computing platform.
[0071] In accordance with an embodiment, a security controller is provided as part of a TEE elements and the security controller performs a measurement of a software component of the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources which do not include a TEE elements, and uses the measurement to create a proof for a respective hardware resource and sends the proof to the attestation and key management system 306. In an implementation, the TEE elements perform a measurement of a software component of the at least one of the plurality of storage hardware resources which do not include the TEE elements. In another implementation, the TEE elements perform a measurement of a software component of the at least one of the plurality of processor hardware resources which do not include the TEE elements. In yet another implementation, the TEE elements perform a measurement of a software component of the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources which do not include the TEE elements. The integration of the security controller 204 extends the security measures to the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources that do not include the TEE elements. After conducting the measurement of the software component, the security controller 204 generates a proof specific to each hardware resource. The proof is then transmitted to the attestation and key management system 306, such as at operation 326, contributing to the overall security of the non-TEE-equipped storage hardware resources and processor hardware resources.
[0072] In accordance with an embodiment, a user application runs at least one confidential VM 110 in the confidential cloud computing platform according to a disaggregated resource architecture. In an implementation, the user application runs in the at least one confidential VM 110 in the confidential cloud computing platform according to a disaggregated resource architecture via secure shell (SSH), such as at operation 330. By virtue of running the user application in at least one confidential virtual machine (VM) in the confidential cloud computing platform, the cloud computing platform ensures security by encapsulating the user application within the at least one of the plurality of confidential VM 110, leveraging the protective features of TEEs, thereby increasing the confidentiality and integrity of the user application's code and data.
[0073] FIG. 4 is a diagram that depicts a remote attestation of hardware and storage resources of the at least one of the plurality of confidential virtual machines (VMs), in accordance with another embodiment of the present disclosure. FIG. 4 is described in conjunction with elements from FIGs. 1, 2, and 3. With reference to FIG. 4, there is shown a diagram 400 that includes the compute pool 102, and the storage pool 104 connected with the high-speed network 108.
[0074] In an implementation scenario, the attestation and key management system 306 handles all complexities regarding the attestation of different heterogeneous TEEs inside the disaggregated architecture instead of the user (i.e., the user 302). The attestation and key management system 306 is configured to provide a general unified attestation abstraction for multiple heterogeneous hardware resources in the disaggregated architecture by offering the certificates / tokens for each element belonging to the at least one of the plurality of confidential VM 110, and the TEE elements utilizes the certificates (or tokens) to communicate directly with each other via secure network, such as through transport layer security (TLS) connections. Moreover, the plurality of compute pool 102, the plurality of storage pool 104, and the attestation and key management system 306 in combination with security systems 322 including a combination of a trusted execution environment (TEE), a hardware security module (HSM), and a trusted platform module (TPM) are connected to the high-speed network 108. The attestation and key management system 306 is configured to examine attestation quotes and, upon successful verification, issues a token or certificate, along with essential configurations and secret provisions, such as encryption and decryption keys. Furthermore, the attestation and secret provision 402 increase the robust enhancement of security and trust within the disaggregated architecture. Additionally, the attestation and secret provision 402 ensures that only the trusted and attested plurality of hardware resources and the plurality of storage resources can participate in secure communication in order to mitigate the risk of unauthorized access and foster a highly secure and trustworthy system environment.
[0075] FIG. 5 is a flow chart that depicts a method for creating the confidential cloud computing platform including the at least one of the plurality of confidential virtual machines (VMs), in a disaggregated resource architecture, in accordance with an embodiment for the present disclosure. With reference to FIG. 5, there is shown a flowchart of method 500 of creating the confidential cloud computing platform including at least one of the plurality of confidential virtual machines 110 in the disaggregated resource architecture. The method 500 includes steps 502 to 512.
[0076] There is provided the method 500 for creating the confidential cloud computing platform including the at least one of the plurality of confidential virtual machines 110 in the disaggregated resource architecture.
[0077] At step 502, the method 500 includes receiving the security policy 304 from the user 302 at the attestation and key management system 306. Moreover, the security policy 304 includes public keys to be used for the user’s at least one confidential VM 110.
[0078] At step 504, the method 500 includes receiving from the user 302 at the disaggregated resource cloud gateway 310, the request to create the at least one confidential VM 110 according to the received security policy 304.
[0079] At step 506, the method 500 includes receiving from the disaggregated resource cloud gateway 310 at the cloud scheduler system 314 the request to create at least one confidential VM 110 on top of the disaggregated resource architecture.
[0080] At step 508, the method 500 includes interacting with monitoring agents in the plurality of compute pools 102 comprising a plurality of processor hardware resources and a plurality of storage pools 104 comprising a plurality of storage hardware resources to obtain available information regarding the processor hardware resources and the storage hardware resources by the cloud scheduler system 314.
[0081] At step 510, the method 500 includes allocating the processor hardware resources and storage hardware resources to the at least one confidential VM 110 by the cloud scheduler system 314 based on the availability of information regarding the processor hardware resources and the storage hardware resources, thereby creating the at least one confidential VM 110. Moreover, the attestation and key management system 306 performs attestation for the allocated processor hardware resources and the allocated storage hardware resources.
[0082] At step 512, the method 500 includes running the user application 126 in the at least one confidential VM 110 in the confidential cloud computing platform according to the disaggregated resource architecture.
[0083] Advantageously, the method 500 is used to build confidential computing services (i.e., the confidential VMs) along with the disaggregated architecture thereby, allowing users to run existing applications while keeping the internet protocol (code, data) confidential. In addition, the method 500 is also used to provide an end-to-end workflow of how to create and attest the confidential VMs on top of the disaggregated architecture. The security policies are used to maintain the data security and the data confidentiality of the at least one confidential virtual machine (VM). Furthermore, the attestation and key management system 306 serves as a centralized system for managing the security policies in order to ensure the data integrity and data security by verifying the security standards through the security policies and providing an assurance against any unauthorized access. The interaction between the attestation and key management system, the cloud scheduler system 314, and monitoring agents ensures seamless integration of security measures with resource allocation decisions that facilitate a cohesive workflow within the confidential cloud computing platform for the creation of at least one of the plurality of confidential virtual machines 110. The disaggregated resource cloud gateway 310 provides a user-friendly interface for initiating the creation of the at least one of the plurality of confidential VMs based on the security policies. The cloud scheduler system 314 is configured to allocate resources by interacting with monitoring agents dynamically to provide an optimized resource utilization in real-time or near real-time. As a result, the method 500 is used to provide an efficient and reliable resource utilization along with a centralized security management, a robust attestation, and key management system 306 to provide a confidential cloud environment along with an enhanced data security and user experience.
[0084] There is provided a computer program comprising instructions that, when executed by a computer system, cause the computer system to implement the method 500. In an example, the instructions are implemented on the computer-readable media, which include, but are not limited to, Electrically Erasable Programmable Read-Only Memory (EEPROM), Random Access Memory (RAM), Read-Only Memory (ROM), Hard Disk Drive (HDD), Flash memory, a Secure Digital (SD) card, Solid-State Drive (SSD), a computer-readable storage medium, and / or CPU cache memory. In an example, the instructions are generated by a computer program, which is implemented in view of the method 500 for creating a confidential cloud computing platform including at least one of the plurality of confidential virtual machines 110, in the disaggregated resource architecture.
[0085] Modifications to embodiments of the present disclosure described in the foregoing are possible without departing from the scope of the present disclosure as defined by the accompanying claims. Expressions such as “including”, “comprising”, “incorporating”, “have”, “is” used to describe, and claim the present disclosure are intended to be construed in a non-exclusive manner, namely allowing for items, components or elements not explicitly described also to be present. Reference to the singular is also to be construed to relate to the plural. The word “exemplary” is used herein to mean “serving as an example, instance, or illustration”. Any embodiment described as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments or to exclude the incorporation of features from other embodiments. The word “optionally” is used herein to mean “is provided in some embodiments and not provided in other embodiments”. It is appreciated that certain features of the present disclosure, which are, for clarity, described in the context of separate embodiments, may also be provided in combination in a single embodiment. Conversely, various features of the invention, which are, for brevity, described in the context of a single embodiment, may also be provided separately or in any suitable combination or as suitable in any other described embodiment of the disclosure.
Claims
CLAIMS1. A method (500) of creating a confidential cloud computing platform including at least one of a plurality of confidential virtual machines (VMs) (110), in a disaggregated resource architecture, comprising steps of: a) receiving a security policy (304) from a user (302) at an attestation and key management system (306), where the security policy (304) includes public keys to be used for the user’s at least one confidential VM (110); b) receiving from a user at a disaggregated resource cloud gateway (310) a request to create at least one confidential VM (110) according to the received security policy (304); c) receiving from the disaggregated resource cloud gateway (310) at a cloud scheduler system (314) the request to create at least one confidential VM (110) on top of the disaggregated resource architecture; d) the cloud scheduler system (314) interacting with monitoring agents in a plurality of compute pools (102) comprising a plurality of processor hardware resources and a plurality of storage pools (104) comprising a plurality of storage hardware resources to obtain availability information regarding the processor hardware resources and the storage hardware resources; and e) based on the results of step (d), the cloud scheduler system (314) allocates processor hardware resources and storage hardware resources to the at least one confidential VM (110), to thereby create the at least one confidential VM (110); wherein the attestation and key management system (306) performs attestation for the allocated processor hardware resources and the allocated storage hardware resources.
2. The method (500) of claim 1 wherein a user application runs (126) in the at least one confidential VM (110) in the confidential cloud computing platform according to a disaggregated resource architecture.
3. The method (500) of claim 2 wherein the confidential VM (110) includes a disaggregated operating system (128).
4. The method (500) of claim 1 wherein at least one of the plurality of storage hardware resources and at least one of the plurality of processor hardware resources includes a Trusted Execution Environment (TEE) elements (202).
5. The method (500) of claim 4 wherein the TEE elements (202) performs a measurement of a software component of the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources which include the TEE elements (202) and uses the measurement to create a proof for its respective hardware resource and sends the proof to the attestation and key management system (306).
6. The method (500) of claim 1 wherein at least one of the plurality of storage hardware resources and at least one of the plurality of processor hardware resources does not include a TEE elements (202).
7. The method (500) of claim 6 wherein a security controller (204) is provided as part of a TEE elements (202) and the security controller (204) performs a measurement of a software component of the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources which do not include a TEE elements, and uses the measurement to create a proof for a respective hardware resource and sends the proof to the attestation and key management system (306).
8. The method (500) of claim 5 or 7 wherein the attestation and key management system (306) performs attestation for the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources.
9. The method (500) of claim 8 wherein the attestation and key management system (306) provides a certificate to the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor resources, according to the performance of the attestation.
10. The method (500) of claim 9 wherein the at least one of the plurality of storage hardware resources and the at least one of the plurality of processor hardware resources communicates with each other using the certificate provided by the attestation and key management system (306).
11. The method (500) of claim 1 wherein the plurality of storage hardware resources include DRAM, SSD or HDD hardware resources.
12. The method (500) of claim 1 wherein the plurality of processor hardware resources include CPU, XPU, GPU, NPU, TPU or FPGA hardware resources.
13. A system (300) comprising means adapted for carrying out all the steps of the method according to any preceding method (500) claim.
14. A computer program comprising instructions for carrying out all the steps of the method according to any preceding method (500) claim, when said computer program is executed on a computer system.
Citation Information
Patent Citations
Technologies for accelerated orchestration and attestation with edge device trust chains
US20190230002A1
Decentralized policy for secure sharing of a trusted execution environment (TEE) among independent workloads
US20230273991A1
Resource modeling language to specify and control the placement of resources in a cloud environment
US9893959B1
Cited By
Data processing method
CN120973479A