ENCRYPTION AT REST FOR CLOUD-RESOURCED VIRTUAL MACHINES

    公开(公告)号:US20190354692A1

    公开(公告)日:2019-11-21

    申请号:US15981777

    申请日:2018-05-16

    IPC分类号: G06F21/60 H04L9/08

    摘要: A compute resource provider system is shown having an encryption agent that obtains a cryptographic key for a virtual machine and sends the cryptographic key to a host agent. The host agent receives the cryptographic key from the encryption agent and stores the received cryptographic key to a user key vault. The host agent generates a key vault secret reference (KVSR) locator pointing to the cryptographic key stored in the user key vault, associates the KVSR with the virtual diskset, and sends a success message to the encryption agent. The encryption agent receives the success message from the host and, responsive thereto, encrypts the virtual diskset using the cryptographic key. Subsequently, another host agent uses the KVSR to obtain the cryptographic key from the key vault and boot the virtual machine with the encrypted virtual diskset.