US20160127336A1

Preventing persistent storage of cryptographic information using signaling

Claim Score by NHIP

Read claim 5, the broadest

Abstract

Organizations maintain and generate large amounts of sensitive information using computer hardware resources and services of a service provider. Furthermore, there is a need to be able to delete large amounts of data securely and quickly by encrypting the data with a key and destroying the key. To ensure that information stored remotely is secured and capable of secure deletion, cryptographic keys used by the organization should be prevented from being persistently stored during serialization operations. Signaling methods are used to notify virtual machine instances of serialization events in order to prevent keying material from being stored persistently.

US20160127336A1, drawing sheet 1
Sheet 1 of 13

Term

7.1 yearsto projected expiry

Projected expiry 12 November 2033, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

20 claims: 3 independent, 17 dependent

  1. 1
    A non-transitory computer-readable storage medium having stored thereon executable instructions that, as a result of being executed by one or more processors of a computer system, cause the computer system to at least:execute a hypervisor that controls interaction between a computer system instances and physical hardware of the system;expose two functions to the computer system instances, the two functions including at least: a first function that causes one or more cryptographic keys maintained by the computer system instances to be unavailable for inclusion in serialization data;and a second function that restores the one or more cryptographic keys to the computer system instances;determine that a serialization event is to occur;cause the hypervisor to signal the computer system instance that the serialization event is scheduled to occur by at least calling the first function, prior to the serialization event such that one or more cryptographic keys contained in the computer system instance is made unavailable for inclusion in serialization data;and generate serialization data lacking the one or more cryptographic keys as a result of the first function having been called.
  2. 5
    Broadest claimClaim Score 67, broad(NHIP)A system, comprising:one or more processors;memory that includes instructions that, when executed by the one or more processors, cause the system to: execute a hypervisor and a guest computer system;expose at least two functions to the guest computer system, the at least two functions comprising at least: a first function of the at least two functions configured to cause a cryptographic key contained by the guest computer system to be unavailable during serialization events;and a second function of the at least two functions configured to restore the cryptographic key to the guest computer system;signal to the guest computer system that serialization will occur by at least causing the guest computer system to execute the first function;and provide the cryptographic key to the guest computer system by at least calling the second function.
  3. 13
    A computer-implemented method, comprising:under the control of one or more computer systems configured with executable instructions, exposing, to a computer system instance, at least two functions, the at least two functions comprising: a first function configured to cause sensitive information contained in memory of the computer system instance to be unavailable for inclusion in serialization data;and a second function configured to restore the sensitive information to the computer system instance;detecting, by a hypervisor, that an event will occur which will expose sensitive information of the computer system instance;signaling the event will occur to the computer system instance by at least calling the first function;and at a time after signaling the event will occur, generating serialization data based at least in part on the computer system instance.