Invention Grant
- Patent Title: Protecting cognitive code and client data in a public cloud via deployment of data and executables into a stateless secure partition
-
Application No.: US15917619Application Date: 2018-03-10
-
Publication No.: US10685106B2Publication Date: 2020-06-16
- Inventor: Richard H. Boivie , Jonathan D. Bradbury , William E. Hall , Guerney D. H. Hunt , Jentje Leenstra , Jeb R. Linton , James A. O'Connor, Jr. , Elaine R. Palmer , Dimitrios Pendarakis
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; Jack V. Musgrove
- Main IPC: G06F21/53
- IPC: G06F21/53 ; H04L29/08 ; H04L29/06 ; H04L9/30 ; G06F21/78 ; G06F21/12 ; H04L9/32

Abstract:
A secure cloud computing environment protects the confidentiality of application code from a customer while simultaneously protecting the confidentiality of a customer's data from intentional or inadvertent leaks by the application code. This result is accomplished without the need to trust the application code and without requiring human surveillance or intervention. A client secure virtual machine (SVM) is accessible by a client who supplies commands, operand data and application data. An appliance SVM has the application code loaded therein and includes an application program interface that accesses a memory area shared by both SVMs. All access to the appliance SVM is initially revoked by an ultravisor, except for the shared memory. The appliance SVM processes the commands without ever saving any persistent state of the application data. The ultravisor manages an SVM by maintaining exclusive control over a device tree used by the operating system of the SVM.
Public/Granted literature
Information query