-
公开(公告)号:US20240022405A1
公开(公告)日:2024-01-18
申请号:US18477370
申请日:2023-09-28
Applicant: Intel Corporation
Inventor: Kapil Sood , Shaojun Ding , Dong Guo , Huailong Zhang , Ruijing Guo , Hejie Xu , Qiming Liu
CPC classification number: H04L9/3073 , H04L9/0894 , H04L63/0281
Abstract: Systems, apparatus, articles of manufacture, and methods are disclosed to provide hardware enforced security for a service mesh. An example first server of a service mesh disclosed herein to provide hardware enforced security for a service mesh includes programmable circuitry to at least one of instantiate or execute the machine-readable instructions to detect a second server of the service mesh, cause a public key of the second server to be stored in the first enclave, and after an attestation for a second enclave is obtained, cause addition of the second server to the service mesh.
-
公开(公告)号:US20230188341A1
公开(公告)日:2023-06-15
申请号:US18106259
申请日:2023-02-06
Applicant: Intel Corporation
Inventor: Ruoyu Ying , Ruijing Guo , Shaojun Ding , Qiang Ren , Haibin Huang , Jie Ren
CPC classification number: H04L9/0897 , G06F21/53
Abstract: An apparatus can include an interface coupled to processing circuitry and cryptographic circuitry coupled to the interface. The cryptographic circuitry can receive a request from the processing circuitry over the interface to perform a cryptographic operation using a remote hardware security module (HSM) key component. The cryptographic circuitry can further transmit a command to a remote component to retrieve the remote HSM key component. Subsequent to receiving the cryptographic key component, the cryptographic circuitry can construct a trusted execution environment (TEE) instance and store the remote HSM key component in the TEE instance. The cryptographic circuitry can use the remote HSM key component to perform the cryptographic operation and provide a result of the cryptographic operation to the processing circuitry over the interface.
-