Invention Grant
- Patent Title: Platform secure execution modes
-
Application No.: US14921555Application Date: 2015-10-23
-
Publication No.: US09792143B1Publication Date: 2017-10-17
- Inventor: Nachiketh Rao Potlapally , Derek Del Miller , Mark Bradley Davis , Matthew Shawn Wilson , Eric Jason Brandwine , Anthony Nicholas Liguori , Rahul Gautam Patel
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: AMAZON TECHNOLOGIES, INC.
- Current Assignee: AMAZON TECHNOLOGIES, INC.
- Current Assignee Address: US WA Seattle
- Agency: Hogan Lovells US LLP
- Main IPC: G06F9/455
- IPC: G06F9/455 ; G06F21/74 ; G06F21/62 ; G06F21/72

Abstract:
The performing of virtual machine (VM)-based secure operations is enabled using a trusted co-processor that is able to operate in a secure mode to perform operations in a multi-tenant environment that are protected from other VMs and DOM-0, among other domains and components. A customer VM can contact a VM manager (VMM) to perform an operation with respect to sensitive data. The VMM can trigger secure mode operation, whereby memory pages are marked and access blocked to entities outside a trusted enclave. The trusted co-processer can measure the VMM and compare the result against an earlier result to ensure that the VMM has not been compromised. Once the operations are performed, the trusted co-processor can return the results, and the VMM can exit the secure mode such that access to the marked pages and customer data is restored.
Information query