Virtualized Protected Storage via OS-Tagged Cryptographic Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems lack effective mechanisms for secure storage and access control of long-term secrets across multiple operating systems on a single device, leading to potential unauthorized access and performance bottlenecks due to hypervisor management.
Innovation Solution
The implementation of a cryptographic engine that tags binary large objects with operating system identifiers, enabling secure, virtualized protected storage by deriving encryption keys from master secret keys and key modifiers, including an operating system tag, to restrict access and allow direct interaction between guest operating systems and the cryptographic module without hypervisor oversight.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cryptographic systems store long-term secrets in a single centralized location managed by the hypervisor, then security control is centralized, but performance bottlenecks occur and unauthorized access risks increase
Solution Approach 1:
The patent segments the centralized cryptographic storage into multiple virtualized storage units, each accessible by specific operating systems through unique identifiers. This segmentation allows parallel access by multiple OSes simultaneously, eliminating the performance bottleneck of centralized hypervisor-managed storage while maintaining security through isolated access paths.
Solution Approach 2:
The patent introduces virtualized cryptographic storage as an intermediary layer between the hypervisor and operating systems. This intermediary provides direct access paths for authorized OSes to cryptographic secrets without requiring hypervisor mediation for each access operation, improving performance while the virtualization layer maintains security controls.
2Adaptability or versatility
If multiple operating systems share access to the same cryptographic secrets, then resource utilization improves, but unauthorized access risk increases
Solution Approach 1:
The patent applies local quality by assigning unique identifiers to different operating systems and using these identifiers to create distinct access paths to cryptographic storage. Each OS has customized access permissions tailored to its specific needs, allowing multiple OSes to share the cryptographic infrastructure while maintaining isolated, authorized access paths that prevent unauthorized cross-OS access.
3Reliability
If the hypervisor manages all cryptographic operations for guest operating systems, then centralized control is maintained, but performance overhead increases
Solution Approach 1:
The patent enables guest operating systems to directly access and manage their own cryptographic secrets through virtualized storage interfaces without requiring hypervisor intervention for each cryptographic operation. The hypervisor maintains initial control by establishing the virtualized storage structure and access permissions, but individual OSes then self-serve their cryptographic needs, eliminating the performance overhead of continuous hypervisor mediation.
Data Source
AI summary
Embodiments of an electronic circuit include a cryptographic engine which includes a key derivation function and encryption logic. The key derivation function combines a master secret key with a plurality of key modifiers including at least an operating system tag specific to an operating system, and derives an encryption key from the combined master secret key and plurality of key modifiers. The encryption logic is coupled to the key derivation function and encrypts data using the derived encryption key to generate a cryptographic binary large object (blob) for virtualized protected storage that is accessible only to the operating system specified by the operating system tag.


