Volume cryptographic key management

US10078754B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-10078754-B1
Application numberUS-201314035735-A
CountryUS
Kind codeB1
Filing dateSep 24, 2013
Priority dateSep 24, 2013
Publication dateSep 18, 2018
Grant dateSep 18, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for providing cryptographic keys for encrypted system volumes on machine instances in virtualized and/or distributed systems are described herein. At a time after detecting the requirement for a cryptographic key by a virtual machine instance, one or more computer system entities within a computer system invoke one or more computer system capabilities at least to create one or more virtual hardware devices capable of representing or providing appropriate cryptographic keys. The virtual hardware devices are connected to the machine instance under the control of the computer system so that the encrypted system volumes may be used. After the cryptographic key is no longer needed, it is detached from the machine instance.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, comprising: detecting, at a guest computing system, one or more encrypted volumes attached to the guest computing system; requesting a cryptographic key for decryption of the one or more encrypted volumes; determining whether the cryptographic key fulfills a requirement for reading the one or more encrypted volumes based at least in part on one or more computer system security policies; and as a result of determining the cryptographic key fulfills the requirement for reading the one or more encrypted volumes: providing, during a boot process, access to the cryptographic key to the guest computing system; monitoring the guest computing system, during the boot process, to detect when access to the cryptographic key has ended; and removing, during the boot process, from the guest computing system access to the cryptographic key after detecting that access to the cryptographic key has ended. 2. The computer-implemented method of claim 1 , wherein providing access to the cryptographic key to the guest computing system comprises attaching a virtual cryptographic hardware device to the guest computing system that provides the cryptographic key to the guest computing system. 3. The computer-implemented method of claim 1 , wherein providing access to the cryptographic key to the guest computing system comprises: determining that the guest computing system has sent a prompt for the cryptographic key; and sending a response to the prompt for the cryptographic key, the response at least including the cryptographic key, the cryptographic key generated by emulating one or more keystrokes via a virtual input device. 4. The computer-implemented method of claim 1 , wherein the method further comprises: logging the request for the cryptographic key to a system log; and logging the result of the determination whether the cryptographic key fulfills the requirement for reading the one or more encrypted volumes. 5. The computer-implemented method of claim 1 , wherein monitoring the guest computing system to detect when access to the cryptographic key has ended at least comprises determining that the guest computing system has at least reached a specified state in the boot process. 6. The computer-implemented method of claim 1 , wherein providing access to the cryptographic key to the guest computing system comprises: creating a virtual smart card that provides the cryptographic key; and enabling the computing system to read the cryptographic key from the virtual smart card. 7. The computer-implemented method of claim 1 , further comprising: receiving a provisioning request over an application processing interface to provision the guest computing system, the provisioning request including at least: an indication of an operating system image, wherein: the operating system image supports encrypted volumes via storage of the cryptographic key on a designated hardware device or via entry of the cryptographic key at startup; and the operating system image corresponds to an operating system provided by an operating system manufacturer with a capability for supporting encrypted volumes; an indication of one or more encrypted volumes under the control of the operating system of the one or more encrypted volumes of the guest computing system; and an indication of the cryptographic key; and causing the provisioning request to be fulfilled. 8. A computer system, comprising: one or more hardware processors; and memory having executable instructions stored thereon that, as a result of being executed by the one or more processors, cause the computer system to: provide an execution environment for a guest operating system; and provide a management component that controls operation of the provided execution environment that at least: determines, during a boot process, that a cryptographic key not available to the guest operating system is required to read one or more encrypted volumes associated with the guest operating system for continued execution of the guest operating system; and causes a change to a configuration of the execution environment to make the cryptographic key accessible to the guest operating system during the boot process in a manner that prevents the guest computing system from accessing the cryptographic key after the boot process. 9. The computer system of claim 8 , wherein prior to the management component changing the configuration of the guest operating system, the management component determines whether to change the configuration by at least evaluating one or more states of the guest operating system. 10. The computer system of claim 8 , wherein: the execution environment is a virtual machine or a server; and the management component is a virtual machine manager or a hardware device coupled to the server. 11. The computer system of claim 8 , wherein the cryptographic key is a volume encryption key used to read one or more encrypted volumes or a portion of the one or more encrypted volumes attached to the execution environment. 12. The computer system of claim 8 , wherein causing the cryptographic key to be made available includes at least attaching a virtual storage device that provides the cryptographic key to the execution environment. 13. The computer system of claim 8 , wherein the change to the configuration is performed by a dedicated device that is part of the computer system implementing the execution environment. 14. The computer system of claim 8 , wherein the executable instructions, as a result of being executed, further cause the management component to at least monitor the guest operating system to detect that a requirement for the cryptographic key has ended by at least determining that the guest operating system has at least begun the boot process. 15. The computer system of claim 8 , wherein the executable instructions, as a result of being executed, further cause the management component to at least: monitor the guest operating system to detect that the cryptographic key should be made unavailable to the guest operating system; and reverse the change to the configuration of the execution environment that caused the cryptographic key to be made available to the guest operating system. 16. The computer system of claim 8 , wherein: the guest operating system is one of a plurality of guest operating systems running on the computer system; the plurality of guest operating systems are launched by an automated process running on the computer system; the management component is provided by one or more key processing service processes that are running on the computer system; and the one or more key processing service processes at least: provide cryptographic keys; and monitor guest computing systems. 17. The computer system of claim 8 , wherein: the guest operating system is at least under the control of a customer of a plurality of customers of a service provider; and the management component is under the control of the service provider. 18. The computer system of claim 17 , wherein the executable instructions, as a result of being executed, cause the computer system to provide a provisioning component that at least: receives a provisioning request at the management component from the customer to instantiate one or more guest computing instances wherein the provisioning request at least comprises: an indication of an operating system image to base the guest operating system on, wherein: the operating system image supports encrypted volumes v

Assignees

Inventors

Classifications

  • G06F21/602Primary

    Providing cryptographic facilities or services · CPC title

  • to assure secure storage of data (address-based protection against unauthorised use of memory G06F12/14; record carriers for use with machines and with at least a part designed to carry digital markings G06K19/00) · CPC title

  • File encryption · CPC title

  • Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms (network architectures or network communication protocols for using time-dependent keys in a packet data network H04L63/068) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10078754B1 cover?
Techniques for providing cryptographic keys for encrypted system volumes on machine instances in virtualized and/or distributed systems are described herein. At a time after detecting the requirement for a cryptographic key by a virtual machine instance, one or more computer system entities within a computer system invoke one or more computer system capabilities at least to create one or more v…
Who is the assignee on this patent?
Amazon Tech Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/602. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Sep 18 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 10 related publications on this page (citations in our corpus or others sharing the same primary CPC).