SECURE KEY PROVISIONING AND HARDWARE-ASSISTED SECURE KEY STORAGE AND SECURE CRYPTOGRAPHIC FUNCTION OPERATION IN CONTAINER-BASED ENVIRONMENTS

    公开(公告)号:EP4064085A1

    公开(公告)日:2022-09-28

    申请号:EP22153672.5

    申请日:2022-01-27

    申请人: INTEL Corporation

    摘要: A key caching container provides for the secure storage of cryptographic keys and the secure operation of cryptographic functions for workload containers. A cryptographic call adapter in each workload container converts application cryptographic operation requests made by an application to workload container cryptographic operation requests that are sent to the key caching container. Secure provision of keys is enabled by a key broker service that acts as a proxy for a key management service. A secure enclave within the key caching container stores keys and instructions that perform cryptographic operations in an encrypted format. The key caching container provides a key handle associated with a cryptographic key to a requesting application, which the application uses in subsequent application cryptographic operation requests. The secure enclave is created and managed using securityrelated instructions in a security-enabled integrated circuit component that is part of a computing system's hardware platform.