-
公开(公告)号:US11314882B2
公开(公告)日:2022-04-26
申请号:US16990003
申请日:2020-08-11
Applicant: Google LLC
Inventor: Nelly Porter , David Benson Cross , Uday Ramesh Savagaonkar , Brandon S. Baker , Sergey Simakov
IPC: G06F21/62 , H04L29/06 , H04L29/08 , H04L9/32 , G06F9/455 , G06F9/50 , G06F21/53 , G06F21/70 , G06F21/64 , H04L67/10
Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for instantiating and managing systems that utilize hierarchal enclaves in a cloud environment.
-
公开(公告)号:US11741251B2
公开(公告)日:2023-08-29
申请号:US17699554
申请日:2022-03-21
Applicant: Google LLC
Inventor: Nelly Porter , David Benson Cross , Uday Ramesh Savagaonkar , Brandon S. Baker , Sergey Simakov
IPC: G06F21/62 , H04L9/40 , H04L9/08 , H04L9/32 , G06F9/455 , G06F9/50 , G06F21/53 , G06F21/70 , G06F21/64 , H04L67/10
CPC classification number: G06F21/6218 , G06F21/6245 , G06F21/64 , G06F21/70 , H04L63/08 , H04L63/126 , H04L67/10 , G06F2221/2105
Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for instantiating and managing systems that utilize hierarchal enclaves in a cloud environment.
-
公开(公告)号:US12244582B2
公开(公告)日:2025-03-04
申请号:US18428700
申请日:2024-01-31
Applicant: Google LLC
IPC: H04L9/40 , G06Q30/018 , H04L9/08
Abstract: Aspects of the disclosure provide various methods relating to enclaves. For instance, a method of authentication for an enclave entity with a second entity may include receiving, by one or more processors of a host computing device of the enclave entity, a request and an assertion of identity for the second entity, the assertion including identity information for the second identity; using an assertion verifier of the enclave entity to determine whether the assertion is valid; when the assertion is valid, extracting the identity information; authenticating the second entity using an access control list for the enclave entity to determine whether the identity information meets expectations of the access control list; when the identity information meets the expectations of the access control list, completing the request.
-
公开(公告)号:US20240171560A1
公开(公告)日:2024-05-23
申请号:US18428700
申请日:2024-01-31
Applicant: Google LLC
CPC classification number: H04L63/08 , H04L9/0844 , H04L63/0428 , H04L63/101 , G06Q30/0185
Abstract: Aspects of the disclosure provide various methods relating to enclaves. For instance, a method of authentication for an enclave entity with a second entity may include receiving, by one or more processors of a host computing device of the enclave entity, a request and an assertion of identity for the second entity, the assertion including identity information for the second identity; using an assertion verifier of the enclave entity to determine whether the assertion is valid; when the assertion is valid, extracting the identity information; authenticating the second entity using an access control list for the enclave entity to determine whether the identity information meets expectations of the access control list; when the identity information meets the expectations of the access control list, completing the request.
-
公开(公告)号:US12235951B2
公开(公告)日:2025-02-25
申请号:US18428842
申请日:2024-01-31
Applicant: Google LLC
Inventor: Matthew Gingell , Peter Gonda , Alexander Thomas Cope , Sergey Karamov , Keith Moyer , Uday Ramesh Savagaonkar , Chong Cai
Abstract: A uniform enclave interface is provided for creating and operating enclaves across multiple different types of backends and system configurations. For instance, an enclave manager may be created in an untrusted environment of a host computing device. The enclave manager may include instructions for creating one or more enclaves. An enclave may be generated in memory of the host computing device using the enclave manager. One or more enclave clients of the enclave may be generated by the enclave manager such that the enclave clients configured to provide one or more entry points into the enclave. One or more trusted application instances may be created in the enclave.
-
公开(公告)号:US20240169054A1
公开(公告)日:2024-05-23
申请号:US18428842
申请日:2024-01-31
Applicant: Google LLC
Inventor: Matthew Gingell , Peter Gonda , Alexander Thomas Cope , Sergey Karamov , Keith Moyer , Uday Ramesh Savagaonkar , Chong Cai
CPC classification number: G06F21/53 , G06F21/12 , G06F21/57 , G06F21/6245 , G06F21/74
Abstract: A uniform enclave interface is provided for creating and operating enclaves across multiple different types of backends and system configurations. For instance, an enclave manager may be created in an untrusted environment of a host computing device. The enclave manager may include instructions for creating one or more enclaves. An enclave may be generated in memory of the host computing device using the enclave manager. One or more enclave clients of the enclave may be generated by the enclave manager such that the enclave clients configured to provide one or more entry points into the enclave. One or more trusted application instances may be created in the enclave.
-
公开(公告)号:US20220215112A1
公开(公告)日:2022-07-07
申请号:US17699554
申请日:2022-03-21
Applicant: Google LLC
Inventor: Nelly Porter , David Benson Cross , Uday Ramesh Savagaonkar , Brandon S. Baker , Sergey Simakov
Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for instantiating and managing systems that utilize hierarchal enclaves in a cloud environment.
-
公开(公告)号:US20200372166A1
公开(公告)日:2020-11-26
申请号:US16990003
申请日:2020-08-11
Applicant: Google LLC
Inventor: Nelly Porter , David Benson Cross , Uday Ramesh Savagaonkar , Brandon S. Baker , Sergey Simakov
Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for instantiating and managing systems that utilize hierarchal enclaves in a cloud environment.
-
-
-
-
-
-
-