The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 14, 2020

Filed:

Jan. 01, 2019
Applicant:

Amazon Technologies, Inc., Reno, NV (US);

Inventors:

Matthew John Campagna, Bainbridge Island, WA (US);

Gregory Alan Rubin, Seattle, WA (US);

Eric Jason Brandwine, Haymarket, VA (US);

Matthew Shawn Wilson, Bainbridge Island, WA (US);

Cristian M. Ilac, Sammamish, WA (US);

Assignee:

Amazon Technologies, Inc., Seattle, WA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 11/30 (2006.01); G06F 21/60 (2013.01); G06F 21/57 (2013.01); G06F 9/455 (2018.01);
U.S. Cl.
CPC ...
G06F 21/602 (2013.01); G06F 9/45558 (2013.01); G06F 21/57 (2013.01); G06F 2009/4557 (2013.01); G06F 2009/45587 (2013.01); G06F 2221/2153 (2013.01);
Abstract

A tiered credentialing approach provides assurance to customers having virtual machines running in a remote environment that the virtual images for these machines are in a pristine state and running in a trusted execution environment. The environment can be divided into multiple subsystems, each having its own cryptographic boundary, secure storage, and trusted computing capabilities. A trusted, limited subsystem can handle the administrative tasks for virtual machines running on the main system of a host computing device. The limited system can receive a certificate from a certificate authority, and can act as a certificate authority to provide credentials to the main system. Upon an attestation request, the subsystems can provide attestation information using the respective credentials as well as the certificate chain. An entity having the appropriate credentials can determine the state of the system from the response and verify the state is as expected.


Find Patent Forward Citations

Loading…