System and method for managing secret information using virtualization

US10516528B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10516528-B2
Application numberUS-201715402240-A
CountryUS
Kind codeB2
Filing dateJan 10, 2017
Priority dateAug 31, 2016
Publication dateDec 24, 2019
Grant dateDec 24, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A distributed computer system and method for managing secret information for virtual entities in the distributed computer system utilizes multiple secret storage service entities to provide secret information to a virtual entity to be hosted in a host computer in the distributed computer system. At least one piece of the secret information for the virtual entity is distributed to the multiple secret storage service entities to provide the secret information to the virtual entity using the at least one piece of the secret information from one of the multiple secret storage service entities.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for managing secret information for virtual entities in a distributed computer system, the method comprising: generating secret information for a virtual entity, wherein the virtual entity is to be hosted in a host computer in the distributed computer system; partitioning the secret information into a plurality of secret pieces using a secret sharing scheme, wherein the secret sharing scheme includes a (k, n)-threshold secret sharing scheme, where n is equal to the number of parties that will be holding the secret pieces and k is the number of secret pieces that are needed to derive the secret information; distributing at least one piece of the secret information to multiple secret storage service entities, including distributing at least one of the secret pieces to each host computer in a group of host computers in the distributed computer system and to the virtual entity; deploying the virtual entity on the host computer; providing the secret information to the virtual entity, by the host computer, for consumption by the virtual entity using the at least one piece of the secret information from one of the multiple secret storage service entities, wherein the secret information is stored on the host computer; and erasing the secret information from the host computer on which the virtual entity is deployed. 2. The method of claim 1 , wherein distributing at least one piece of the secret information to multiple secret storage service entities includes distributing the entire secret information to the multiple secret storage service entities. 3. The method of claim 1 , wherein providing the secret information to the virtual entity for consumption includes requesting the secret information from one of the multiple secret storage service entities by the host computer, and transmitting the secret information from that secret storage service entity to the host computer in response to the request. 4. The method of claim 1 , further comprising: migrating the virtual entity from the host computer to another host computer in the distributed computer system; and providing the secret information to the virtual entity on the another host computer using the at least one piece of the secret information from one of the multiple secret storage service entities. 5. The method of claim 1 , wherein the (k, n)-threshold secret sharing scheme is a (2, n)-threshold secret sharing scheme so that at least two of the secret pieces are needed to derive the secret information. 6. The method of claim 1 , wherein providing the secret information to the virtual entity for consumption includes deriving the secret information using the secret piece from the virtual entity and the secret piece from the host computer. 7. The method of claim 1 , further comprising: migrating the virtual entity from the host computer to another host computer in the distributed computer system; deriving the secret information using the secret piece from the virtual entity and the secret piece from the another host computer; and providing the secret information to the virtual entity on the another host computer. 8. A non-transitory computer-readable storage medium containing program instructions for managing secret information for virtual entities in a distributed computer system, wherein execution of the program instructions by one or more processors of a computer system causes the one or more processors to perform steps comprising: generating secret information for a virtual entity to be hosted in a host computer in the distributed computer system; partitioning the secret information into a plurality of secret pieces using a secret sharing scheme, wherein the secret sharing scheme includes a (k, n)-threshold secret sharing scheme, where n is equal to the number of parties that will be holding the secret pieces and k is the number of secret pieces that are needed to derive the secret information; distributing at least one piece of the secret information to multiple secret storage service entities, including distributing at least one of the secret pieces to each host computer in a group of host computers in the distributed computer system and to the virtual entity; deploying the virtual entity on the host computer; providing the secret information to the virtual entity, by the host computer, for consumption using the at least one piece of the secret information from one of the multiple secret storage service entities, wherein the secret information is stored on the host computer; and erasing the secret information from the host computer on which the virtual entity is deployed. 9. The computer-readable storage medium of claim 8 , wherein distributing at least one piece of the secret information to multiple secret storage service entities includes distributing the entire secret information to the multiple secret storage service entities. 10. The computer-readable storage medium of claim 8 , wherein providing the secret information to the virtual entity for consumption includes requesting the secret information from one of the multiple secret storage service entities by the host computer, and transmitting the secret information from that secret storage service entity to the host computer in response to the request. 11. The computer-readable storage medium of claim 8 , wherein the steps further comprise: migrating the virtual entity from the host computer to another host computer in the distributed computer system; and providing the secret information to the virtual entity on the another host computer using the at least one piece of the secret information from one of the multiple secret storage service entities. 12. The computer-readable storage medium of claim 8 , wherein the (k, n)-threshold secret sharing scheme is a (2, n)-threshold secret sharing scheme so that at least two of the secret pieces are needed to derive the secret information. 13. The computer-readable storage medium of claim 8 , wherein providing the secret information to the virtual entity for consumption includes deriving the secret information using the secret piece from the virtual entity and the secret piece from the host computer. 14. The computer-readable storage medium of claim 8 , wherein the steps further comprise: migrating the virtual entity from the host computer to another host computer in the distributed computer system; deriving the secret information using the secret piece from the virtual entity and the secret piece from the another host computer; and providing the secret information to the virtual entity on the another host computer. 15. A distributed computer system comprising: a plurality of host computers with memories and processors; and a plurality of virtual entities hosted on at least some of the host computers, each of the virtual entities being assigned secret information; wherein at least one of the host computers is configured to partition the secret information for each of the virtual entities into a plurality of secret pieces using a secret sharing scheme, wherein the secret sharing scheme includes a (k, n)-threshold secret sharing scheme, where n is equal to the number of parties that will be holding the secret pieces and k is the number of secret pieces that are needed to derive the secret information, and wherein at least one of the secret pieces of each secret information is distributed to each of the host computers and to the virtual entity to which that secret information is assigned, and wherein at least one of the host computers is configured to provide the secret information of the particular virtual entity depl

Assignees

Inventors

Classifications

  • involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] · CPC title

  • H04L9/085Primary

    Secret sharing or secret splitting, e.g. threshold schemes · CPC title

  • Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10516528B2 cover?
A distributed computer system and method for managing secret information for virtual entities in the distributed computer system utilizes multiple secret storage service entities to provide secret information to a virtual entity to be hosted in a host computer in the distributed computer system. At least one piece of the secret information for the virtual entity is distributed to the multiple s…
Who is the assignee on this patent?
Nicira Inc
What technology area does this patent fall under?
Primary CPC classification H04L9/085. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 24 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).