Invention Grant
- Patent Title: Technologies for implementing mutually distrusting domains
-
Application No.: US15721124Application Date: 2017-09-29
-
Publication No.: US10686605B2Publication Date: 2020-06-16
- Inventor: Siddhartha Chhabra , David M. Durham
- Applicant: Intel Corporation
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Agency: Schwabe, Williamson & Wyatt, P.C.
- Main IPC: H04L9/32
- IPC: H04L9/32 ; G06F9/455 ; H04L9/06 ; G06F12/1009 ; G06F12/14 ; G06F21/74 ; G06F21/00 ; G06F21/62

Abstract:
Technologies for providing shared immutable code among untrusting domains are provided. The untrusting domains may be cryptographically separated within a cloud computing service or environment. The shared immutable code may be a shared virtual machine monitor (sVMM) that is setup by system software to indicate that the sVMM code pages need integrity alone and should be protected with an integrity key associated with individual domains. This indication may be stored in page tables and carried over the memory bus to a cryptographic engine. The cryptographic engine may use this indication to protect the integrity of data before storing the data to memory. In order to ensure cryptographic isolation, integrity values may be generated using a domain-specific key ensuring that an attempt to modify the code by one domain is detected by a different domain. Other embodiments are described herein and claimed.
Public/Granted literature
- US20190103976A1 TECHNOLOGIES FOR IMPLEMENTING MUTUALLY DISTRUSTING DOMAINS Public/Granted day:2019-04-04
Information query