Invention Grant
- Patent Title: Centralized volume encryption key management for edge devices with trusted platform modules
-
Application No.: US16661198Application Date: 2019-10-23
-
Publication No.: US11689365B2Publication Date: 2023-06-27
- Inventor: Alexey Makhalov , Maria Potapova , Ravishankar Chamarajnagar , Bo Gan , Raghunath Krishnamurthy , Sharath George , Sriram Nambakam
- Applicant: VMware, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: VMWARE, INC.
- Current Assignee: VMWARE, INC.
- Current Assignee Address: US CA Palo Alto
- Agency: Thomas Horstemeyer, LLP
- Main IPC: H04L9/14
- IPC: H04L9/14 ; H04L9/08 ; H04L9/32 ; G06F3/06

Abstract:
The present disclosure relates to centralized volume encryption key management for edge devices with trusted platform modules (TPM)s. In some aspects a volume encryption key is generated for a gateway device. A sealing authorization policy is also generated for the gateway device. The sealing authorization policy is generated based on a predetermined platform configuration register (PCR) mask and expected PCR values. The volume encryption key and the sealing authorization policy are transmitted from the management service to the gateway device to provision the gateway device with the volume encryption key.
Public/Granted literature
- US20210021418A1 CENTRALIZED VOLUME ENCRYPTION KEY MANAGEMENT FOR EDGE DEVICES WITH TRUSTED PLATFORM MODULES Public/Granted day:2021-01-21
Information query