WO2016036858A1

Systems and methods for securely provisioning the geographic location of physical infrastructure elements in cloud computing environments

Abstract

Systems and methods relating to improved security in cloud computing environments are disclosed. According to one illustrative implementation, a method for provisioning physical geographic location of a physical infrastructure device associated with a hypervisor host is provided. Further, the method may include performing processing to obtain initial geo location data of the device, determining verified geo location data of the device by performing validation, via an attestation service component, of the initial geo location data to provide verified geo location data, and writing the verified geo location data into HSM or TPM space of the hypervisor host.

WO2016036858A1, drawing sheet 1
Sheet 1 of 6

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

46 claims: 6 independent, 40 dependent

  1. 1
    Claims:1. A method for provisioning physical geographic location of a physical infrastructure device associated with a hypervisor host, the method comprising: performing processing to obtain initial geo location data of the device, including: invoking one or more attestation service component(s) to issue a unique geo acquisition code that is only valid for a predefined time;sending a request for the initial geo location data including the acquisition code to a geographic data acquisition component;and receiving the initial geo location data from the geographic data acquisition component in response to the request, the initial geo location data comprising location, date, time data, and the acquisition code, and being signed by a key of the geo data acquisition component;determining verified geo location data of the device by performing validation, via the attestation service component(s), of the initial geo location data to provide the verified geo location data upon successful validation;writing, via the attestation service component(s), the verified geo location data into a Hardware Security Module of the hypervisor host.
  2. 30
    A method for provisioning physical geographic location of a physical infrastructure device associated with a hypervisor host, the method comprising:invoking one or more attestation service component(s) to issue a unique geo acquisition code that is only valid for a predefined time;sending a request for initial geo location data including the acquisition code to a geographic data acquisition component;processing the initial geo location data from the geographic data acquisition component in response to the request, the initial geo location data comprising location, date, time data, and the acquisition code, and being signed by a key of the geo data acquisition component;performing validation, via the attestation service component(s), of the initial geo location data to provide the verified geo location data upon successful validation;writing, via the attestation service component(s), the verified geo location data into the hypervisor host.
  3. 34
    A method for provisioning physical geographic location of a physical infrastructure device associated with a hypervisor host, the method comprising:invoking one or more attestation service component(s) to issue a unique geo acquisition code that is only valid for a predefined time;performing processing regarding utilization of the unique geo acquisition code and secure signature from the attestation service component(s) to obtain initial geo location data from a geographic data acquisition component;transmitting the initial geo location data and the signature to the attestation service component(s);performing validation, via the attestation service component(s), of the initial geo location data to provide the verified geo location data upon successful validation;writing, via the attestation service component(s), the verified geo location data into the hypervisor host.
  4. 39
    A method for establishing a physical geographic location of a data processing device associated with a hypervisor host, the method comprising:receiving the data processing device at a data center;integrating the device into a physical rack of the data center;and performing a geographic location provisioning process in accordance with claim 1 or other claims herein to establish the physical geographic location of the device.
  5. 45
    A system comprising:at least one hypervisor host with one or more physical infrastructure devices;and one or more processing devices and/or computer readable media containing computer readable instructions executable by one or more processors to provision the hypervisor host with actual geographic location information of a physical infrastructure device, the instructions executable for: performing processing to obtain initial geo location data of the device, including: invoking one or more attestation service component(s) to issue a unique geo acquisition code that is only valid for a predefined time;sending a request for the initial geo location data including the acquisition code to a geographic data acquisition component;and receiving the initial geo location data from the geographic data acquisition component in response to the request, the initial geo location data comprising location, date, time data, and the acquisition code, and being signed by a key of the geo data acquisition component;determining verified geo location data of the device by performing validation, via the attestation service component(s), of the initial geo location data to provide the verified geo location data upon successful validation;writing, via the attestation service component(s), the verified geo location data into a Hardware Security Module of the hypervisor host.
  6. 46
    One or more computer readable media containing computer readable instructions executable by one or more processors to provision a hypervisor host with actual geographic location information of a physical infrastructure device associated with the hypervisor host, the instructions executable for:performing processing to obtain initial geo location data of the device, including: invoking one or more attestation service component(s) to issue a unique geo acquisition code that is only valid for a predefined time;sending a request for the initial geo location data including the acquisition code to a geographic data acquisition component;and receiving the initial geo location data from the geographic data acquisition component in response to the request, the initial geo location data comprising latitude, longitude, date, time data, and the acquisition code, and being signed by a key of the geo data acquisition component;determining verified geo location data of the device by performing validation, via the attestation service component(s), of the initial geo location data to provide the verified geo location data upon successful validation;and writing, via the attestation service component(s), the verified geo location data into a Hardware Security Module of the hypervisor host.