US2015381362A1PendingUtilityA1

Encryption System in a Virtualized Environment

Assignee: NICIRA INCPriority: Jun 30, 2014Filed: Jul 31, 2015Published: Dec 31, 2015
Est. expiryJun 30, 2034(~7.9 yrs left)· nominal 20-yr term from priority
G06F 2009/45587G06F 21/602G06F 21/568H04L 63/1408H04L 9/14G09C 1/00H04L 63/1441G06F 21/6236G06F 2221/034G06F 9/45558H04L 63/0428G06F 21/56H04L 2209/24H04L 63/123G06F 9/542
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

For a host that executes one or more guest virtual machines (GVMs), some embodiments provide a novel encryption method for encrypting the data messages sent by the GVMs. The method initially receives a data message to send for a GVM executing on the host. The method then determines whether it should encrypt the data message based on a set of one or more encryption rules. When the process determines that it should encrypt the received data message, it encrypts the data message and forwards the encrypted data message to its destination; otherwise, the method just forwards the received data message unencrypted to its destination. In some embodiments, the host encrypts differently the data messages for different GVMs that execute on the host. When two different GVMs are part of two different logical overlay networks that are implemented on common network fabric, the method in some embodiments encrypts the data messages exchanged between the GVMs of one logical network differently than the data messages exchanged between the GVMs of another logical network. In some embodiments, the method can also encrypt different types of data messages from the same GVM differently. Also, in some embodiments, the method can dynamically enforce encryption rules in response to dynamically detected events, such as malware infections.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A non-transitory machine readable medium for storing a program for updating a keyring with a plurality of keys, the keyring stored on a host computing device that executes a plurality of virtual machines (VMs) and used for encryption operations for data messages associated with at least one particular VM, the program for execution by at least one processing unit, the program comprising sets of instructions for:
 receiving a command to (1) fetch a new key for the keyring and (2) remove a particular key from the plurality of keys in the keyring;   sending a request for the new key;   continuing to process data messages received from the particular VM by using a first set of keys in the keyring including the particular key, while processing data messages transmitted by the particular VM by using a second set of keys in the keyring excluding the particular key; and   upon receiving a new key, removing the particular key from the key ring.   
     
     
         2 . The non-transitory machine readable medium of  claim 1 , wherein the program further comprises a set of instructions for processing received and transmitted data messages for the particular VM by using the keyring that includes the new key upon receiving the new key. 
     
     
         3 . The non-transitory machine readable medium of  claim 1 , wherein the command is received when the particular key has been used for a certain duration of time. 
     
     
         4 . The non-transitory machine readable medium of  claim 1 , wherein the command is received when the particular key has been used to encrypt a certain number of data messages. 
     
     
         5 . The non-transitory machine readable medium of  claim 1 , wherein the command is received when the particular key has been used to encrypt a certain amount of data. 
     
     
         6 . The non-transitory machine readable medium of  claim 1 , wherein the received command is sent by a controller that generates the command based on statistics that the controller collects from the host computing device regarding data that the particular key was used to encrypt. 
     
     
         7 . The non-transitory machine readable medium of  claim 1 , wherein the program further comprises a set of instructions for receiving the new key from a key generator in response to the sent request, wherein the first and second set of keys are used because of a transit delay in receiving the new key from the key generator. 
     
     
         8 . The non-transitory machine readable medium of  claim 1 , wherein the program further comprises a set of instructions for receiving the new key from a key generator in response to the sent request, wherein the command is received from a controller that monitors usage of keys on the host computing device. 
     
     
         9 . The non-transitory machine readable medium of  claim 1 , wherein encryption operation are performed on data messages exchanged between the particular VM and other VMs in order to protect said data messages, said particular VM and other VMs forming a logical private network (LPN). 
     
     
         10 . The non-transitory machine readable medium of  claim 9 , wherein at least one of the other VMs executes on a different host computing device than the particular VM 
     
     
         11 . The non-transitory machine readable medium of  claim 9 , wherein at least one of the other VMs executes on a same host computing device as the particular VM. 
     
     
         12 . A method for updating a keyring with a plurality of keys, the keyring stored on a host computing device that executes a plurality of virtual machines (VMs) and used for encryption operations for data messages associated with at least one particular VM, the method comprises:
 receiving a command to (1) fetch a new key for the keyring and (2) remove a particular key from the plurality of keys in the keyring;   sending a request for the new key;   continuing to process data messages received from the particular VM by using a first set of keys in the keyring including the particular key, while processing data messages transmitted by the particular VM by using a second set of keys in the keyring excluding the particular key; and   upon receiving a new key, removing the particular key from the key ring.   
     
     
         13 . The method of  claim 12  further comprising processing received and transmitted data messages for the particular VM by using the keyring that includes the new key upon receiving the new key. 
     
     
         14 . The method of  claim 2 , wherein the first set of keys includes the particular key and the second set of keys excludes the particular key in order to rotate out the particular key and rotate in the new key when the new key is received, wherein upon receiving the new key both the first and second sets of keys are the same. 
     
     
         15 . The method of  claim 12 , wherein the command is received when the particular key has been used for a certain duration of time. 
     
     
         16 . The method of  claim 12 , wherein the command is received when the particular key has been used to encrypt at least one of a certain number of data messages and a certain amount of data. 
     
     
         17 . The method of  claim 12 , wherein the received command is sent by a controller that generates the command based on statistics that the controller collects from the host computing device regarding data that the particular key was used to encrypt. 
     
     
         18 . The method of  claim 12  further comprising receiving the new key from a key generator in response to the sent request, wherein the first and second set of keys are used because of a transit delay in receiving the new key from the key generator. 
     
     
         19 . The method of  claim 12  further comprising receiving the new key from a key generator in response to the sent request, wherein the command is received from a controller that monitors usage of keys on the host computing device. 
     
     
         20 . The method of  claim 12 , wherein encryption operation are performed on data messages exchanged between the particular VM and other VMs in order to protect said data messages, said particular VM and other VMs forming a logical private network (LPN).

Join the waitlist — get patent alerts

Track US2015381362A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.