Secure Public Cloud via Cryptographic Domain Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In public cloud services environments, consumers' data is vulnerable to access and modification by the cloud services provider due to the high-level control provided by the provider, leading to potential security breaches and exposure to unauthorized access, including government warrants.

Innovation Solution

A secure public cloud environment is created where consumers control their data processing by establishing a cryptographically secure code/data image, referred to as a consumer domain image, which is encrypted and executed only on the cloud services provider's server hardware using a consumer-provided key, keeping the Virtual Machine Monitor and other privileged components outside the Trusted Computing Base, ensuring only the consumer can access and modify their data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the cloud services provider provides high-level control over the cloud infrastructure, then the provider can manage and optimize resources effectively, but the consumer's data becomes vulnerable to access and modification by the provider

Engineering Contradiction:
Improveprovider control over cloud infrastructureVSAvoiddata vulnerability to provider access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the cloud infrastructure into separate control layers: the provider manages the physical infrastructure and virtualization layer, while the consumer maintains exclusive control over their data through customer-specific encryption keys. This segmentation allows provider control for resource management while preventing unauthorized access to consumer data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces hardware-based cryptographic modules and virtual machine monitors as intermediaries between the provider and consumer. These intermediaries enable the provider to manage resources while maintaining security boundaries that prevent direct access to consumer data, even by provider employees.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the consumer provides full control over their data processing, then data security is maximized, but the consumer loses the ability to leverage cloud provider resources

Engineering Contradiction:
Improvedata securityVSAvoidaccess to cloud resources
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements different control qualities at different levels: the provider has control over infrastructure resources, while the consumer has exclusive control over their data. This local quality differentiation allows each party to exercise control only where appropriate, maintaining both security and resource access capability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses virtualization to create virtual machine copies that can be deployed on provider infrastructure. These virtual machines execute consumer code while maintaining isolated data spaces, enabling the consumer to leverage cloud resources without sacrificing data control or security.

Inventive Principle:
Principle #26Copying

3Reliability

If the Virtual Machine Monitor and privileged components are included in the Trusted Computing Base, then the system can provide high-level security features, but the Trusted Computing Base becomes larger and more vulnerable to compromise

Engineering Contradiction:
Improvesecurity feature capabilityVSAvoidTrusted Computing Base size
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the Virtual Machine Monitor and privileged components from the consumer's Trusted Computing Base and places them in a separate provider-managed layer. This extraction reduces the consumer's TCB size and vulnerability surface while maintaining the ability to access high-level security features through the virtualization infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a new dimensional separation between consumer and provider control spaces. The consumer operates in a restricted space with minimal TCB, while the provider manages the broader infrastructure. This dimensional change allows security features to exist without increasing consumer TCB complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11783081B2Secure public cloud
Publication Date: 2023.10.10 INTEL CORP
  • US11783081B2 patent drawing
  • US11783081B2 patent drawing
  • US11783081B2 patent drawing

AI summary

In a method to utilize a secure public cloud, a computer receives a domain manager image and memory position-dependent address information in response to requesting a service from a cloud services provider. The computer also verifies the domain manager image and identifies a key domain key to be used to encrypt data stored in a key domain of a key domain-capable server. The computer also uses the key domain key and the memory-position dependent address information to encrypt a domain launch image such that the encrypted domain launch image is cryptographically bound to at least one memory location of the key domain. The computer also encrypts the key domain key and sends the encrypted domain launch image and the encrypted key domain key to the key domain-capable server, to cause a processor of the key domain-capable server to create the key domain. Other embodiments are described and claimed.