Virtualized shared security engine and creation of a protected zone
    1.
    发明授权
    Virtualized shared security engine and creation of a protected zone 有权
    虚拟化的共享安全引擎和创建保护区

    公开(公告)号:US07634650B1

    公开(公告)日:2009-12-15

    申请号:US11184306

    申请日:2005-07-18

    IPC分类号: G06F9/00

    摘要: Methods and apparatus are provided for creating a secure zone having multiple servers connected to a resource virtualization switch through I/O bus interfaces, such as PCI Express or PCI-AS. Servers connected to the resource virtualization switch using I/O bus interfaces share access to one or more virtualized cryptographic accelerators associated with the resource virtualization switch. Applications on a server or system images running on hypervisor inside server can use cryptographic accelerators associated with the resource virtualization switch as though the resources were included in the server itself. Connections between multiple servers and the resource virtualization switch are secure non-broadcast connections. Data provided to a resource virtualization switch can be cryptographically processed using one or more shared and virtualized cryptographic accelerators.

    摘要翻译: 提供了用于创建具有通过I / O总线接口(例如PCI Express或PCI-AS)连接到资源虚拟化交换机的多个服务器的安全区域的方法和装置。 使用I / O总线接口连接到资源虚拟化交换机的服务器共享对与资源虚拟化交换机相关联的一个或多个虚拟化加密加速器的访问。 在服务器或系统上运行的虚拟机管理程序上的应用程序中的应用程序可以使用与资源虚拟化交换机相关联的加密加速器,就像资源包含在服务器本身中一样。 多个服务器和资源虚拟化交换机之间的连接是安全的非广播连接。 提供给资源虚拟化交换机的数据可以使用一个或多个共享和虚拟化加密加速器进行加密处理。