Invention Application
- Patent Title: DYNAMIC SHARING IN SECURE MEMORY ENVIRONMENTS USING EDGE SERVICE SIDECARS
-
Application No.: US17668979Application Date: 2022-02-10
-
Publication No.: US20220239507A1Publication Date: 2022-07-28
- Inventor: Ned M. Smith , Kshitij Arun Doshi , Francesc Guim Bernat , Mona Vij
- Applicant: Intel Corporation
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Main IPC: H04L9/32
- IPC: H04L9/32 ; H04L9/40 ; G06F12/14 ; H04L9/08 ; G06F9/455 ; G06F16/23 ; G06F11/10 ; H04L9/06 ; H04L41/0893 ; H04L41/5009 ; H04L41/5025 ; H04L43/08 ; H04L67/1008 ; G06F9/54 ; G06F21/60 ; H04L41/0896 ; H04L41/142 ; H04L41/5051 ; H04L67/141 ; H04L41/14 ; H04L47/70 ; H04L67/12 ; G06F8/41 ; G06F9/38 ; G06F9/445 ; G06F9/48 ; G06F9/50 ; G06F11/34

Abstract:
Various approaches for memory encryption management within an edge computing system are described. In an edge computing system deployment, a computing device includes capabilities to store and manage encrypted data in memory, through processing circuitry configured to: allocate memory encryption keys according to a data isolation policy for a microservice domain, with respective keys used for encryption of respective sets of data within the memory (e.g., among different tenants or tenant groups); and, share data associated with a first microservice to a second microservice of the domain. Such sharing may be based on the communication of an encryption key, used to encrypt the data in memory, from a proxy (such as a sidecar) associated with the first microservice to a proxy associated with the second microservice; and maintaining the encrypted data within the memory, for use with the second microservice, as accessible with the communicated encryption key.
Information query