Invention Grant
- Patent Title: Shielded networks for virtual machines
-
Application No.: US15635199Application Date: 2017-06-28
-
Publication No.: US10771439B2Publication Date: 2020-09-08
- Inventor: Alan Thomas Gavin Jowett , Ravi T. Rao , Gregory M. Cusanza , Nir Ben-Zvi , Dean A. Wells
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee Address: US WA Redmond
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/60 ; G06F21/44 ; G06F9/455 ; H04L9/32

Abstract:
Embodiments relate to a host encrypting network communications of virtual machines (VMs) in ways that minimize exposure of the network communications in cleartext form. The host captures and registers a measure of a secure state of the host. The measure is registered with a guardian service communicable via a network. The guardian service also securely stores keys of the VMs. Each VM's key is associated with authorization information indicating which machines are authorized to obtain the corresponding VM's key. The host obtains access to a VM's key based on a confirmation that its state matches the registered measured state and based on the authorization information of the VM indicating that the host is authorized to access the key. The VM's key is then used to transparently encrypt/decrypt network communications of the VM as they pass through a virtualization layer on the host that executes the VMs.
Public/Granted literature
- US20190007378A1 SHIELDED NETWORKS FOR VIRTUAL MACHINES Public/Granted day:2019-01-03
Information query