CA2918596C

A secure server on a system with virtual machines

Abstract

A system, an apparatus and a method for providing a secure computing environment may be provided. In one aspect, an apparatus may comprise a communication port and a computer processor coupled to the communication port. The computer processor may be configured to initialize a hypervisor, establish a first virtual machine under control of the hypervisor and execute code for a secure zone on the first virtual machine. To execute code for the secure zone, the computer processor may be further configured to verify an administrative task and execute the administrative task, which may include: establish a connection with an administrator device, ensure that the administrator device is one of a set of intended administrator devices, receive a command through the connection with the administrator device and establish a second virtual machine under control of the hypervisor. The command may relate to executing a task on the second virtual machine.

CA2918596C, drawing sheet 1
Sheet 1 of 15

Term

7.9 yearsleft in the term

Expires 1 August 2034.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

33 claims: 7 independent, 26 dependent

  1. 1
    A computer-implemented method for providing secure computing environment on a computer processor, comprising:initializing a hypervisor on the computer processor;establishing a first virtual machine under control of the hypervisor;and executing code for a secure zone on the first virtual machine, including: verifying an administrative task, and executing the administrative task, wherein the executing comprises: establishing a connection with an administrator device;ensuring that the administrator device is one of a set of intended administrator devices;receiving a command through the connection with the administrator device, wherein the command relates to executing a task on a second virtual machine and the task calls a subtask, wherein execution of the task is suspended according to one or more time slices apportioned to the first virtual machine by the hypervisor while the subtask is executed by the second virtual machine, and wherein executing the task on the second virtual machine comprises establishing the second virtual machine under control of the hypervisor. Date reçue / Date received 2021-12-02
  2. 2
    The computer-implemented method of daim 1, wherein ensuring that the administrator device is one of the set of intended administrator devices comprises verifying that the administrator device contains a private key that corresponds to a public key of a set of public keys.
  3. 11
    The computer-implemented method of daim 1, wherein verifying the administrative task further comprises:verifying that the administrative task is signed by a signature as an administrator task;and verifying the signature of the administrative task.
  4. 12
    An apparatus for providing a secure computing environment, comprising:a communication port;and a computer processor coupled to the communication port and configured to: initialize a hypervisor;establish a first virtual machine under control of the hypervisor;and execute code for a secure zone on the first virtual machine, including: verify an administrative task, and execute the administrative task, wherein to execute the administrative task the computer processor is further configured to: establish a connection with an administrator device;ensure that the administrator device is one of a set of intended administrator devices;receive a command through the connection with the administrator device, wherein the command relates to executing a task on a second virtual machine and the task calls a subtask, and wherein execution of the task is suspended according to one or more time slices apportioned to the first virtual machine by the hypervisor while the subtask is executed by the second virtual machine;and Date reçue / Date received 2021-12-02 establish the second virtual machine under control of the hypervisor.
  5. 23
    A system for providing a secure computing environment, comprising:an administrator device comprising a secure zone configured to execute a client administrative task;an apparatus, comprising: a communication port;and a computer processor coupled to the communication port and configured to: initialize a hypervisor;establish a first virtual machine under control of the hypervisor;and execute code for a secure zone on the first virtual machine, including: verify an administrative task, and Date reçue / Date received 2021-12-02 execute the administrative task, wherein to execute the administrative task the computer processor is further configured to: establish a connection with the administrator device;ensure that the administrator device is one of a set of intended administrator devices;receive a command through the connection with the administrator device, wherein the command relates to executing a task on a second virtual machine and the task calls a subtask, and wherein execution of the task is suspended according to one or more time slices apportioned to the first virtual machine by the hypervisor while the subtask is executed by the second virtual machine;and establish the second virtual machine under control of the hypervisor, wherein to execute the client administrative task, the secure zone of the administrator device is further configured to: establish the connection with the apparatus;and send the command through the connection with the apparatus.
  6. 25
    The system of daim 24, wherein the set of public keys are stored within data of the first virtual machine.
  7. 29
    The system of daim 23, wherein the apparatus further comprises a non-volatile storage exclusively accessible by the secure zone on the first virtual machine, and to verify the administrative task the computer processor is further configured to calculate a checksum of the administrative task and to verify the calculated checksum using information from the nonvolatile storage.