Encryption System in a Virtualized Environment
Abstract
For a host that executes one or more guest virtual machines (GVMs), some embodiments provide a novel encryption method for encrypting the data messages sent by the GVMs. The method initially receives a data message to send for a GVM executing on the host. The method then determines whether it should encrypt the data message based on a set of one or more encryption rules. When the process determines that it should encrypt the received data message, it encrypts the data message and forwards the encrypted data message to its destination; otherwise, the method just forwards the received data message unencrypted to its destination. In some embodiments, the host encrypts differently the data messages for different GVMs that execute on the host. When two different GVMs are part of two different logical overlay networks that are implemented on common network fabric, the method in some embodiments encrypts the data messages exchanged between the GVMs of one logical network differently than the data messages exchanged between the GVMs of another logical network. In some embodiments, the method can also encrypt different types of data messages from the same GVM differently. Also, in some embodiments, the method can dynamically enforce encryption rules in response to dynamically detected events, such as malware infections.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A non-transitory machine readable medium for storing a program for updating a keyring with a plurality of keys, the keyring stored on a host computing device that executes a plurality of virtual machines (VMs) and used for encryption operations for data messages associated with at least one particular VM, the program for execution by at least one processing unit, the program comprising sets of instructions for:
receiving a command to (1) fetch a new key for the keyring and (2) remove a particular key from the plurality of keys in the keyring; sending a request for the new key; continuing to process data messages received from the particular VM by using a first set of keys in the keyring including the particular key, while processing data messages transmitted by the particular VM by using a second set of keys in the keyring excluding the particular key; and upon receiving a new key, removing the particular key from the key ring.
2 . The non-transitory machine readable medium of claim 1 , wherein the program further comprises a set of instructions for processing received and transmitted data messages for the particular VM by using the keyring that includes the new key upon receiving the new key.
3 . The non-transitory machine readable medium of claim 1 , wherein the command is received when the particular key has been used for a certain duration of time.
4 . The non-transitory machine readable medium of claim 1 , wherein the command is received when the particular key has been used to encrypt a certain number of data messages.
5 . The non-transitory machine readable medium of claim 1 , wherein the command is received when the particular key has been used to encrypt a certain amount of data.
6 . The non-transitory machine readable medium of claim 1 , wherein the received command is sent by a controller that generates the command based on statistics that the controller collects from the host computing device regarding data that the particular key was used to encrypt.
7 . The non-transitory machine readable medium of claim 1 , wherein the program further comprises a set of instructions for receiving the new key from a key generator in response to the sent request, wherein the first and second set of keys are used because of a transit delay in receiving the new key from the key generator.
8 . The non-transitory machine readable medium of claim 1 , wherein the program further comprises a set of instructions for receiving the new key from a key generator in response to the sent request, wherein the command is received from a controller that monitors usage of keys on the host computing device.
9 . The non-transitory machine readable medium of claim 1 , wherein encryption operation are performed on data messages exchanged between the particular VM and other VMs in order to protect said data messages, said particular VM and other VMs forming a logical private network (LPN).
10 . The non-transitory machine readable medium of claim 9 , wherein at least one of the other VMs executes on a different host computing device than the particular VM
11 . The non-transitory machine readable medium of claim 9 , wherein at least one of the other VMs executes on a same host computing device as the particular VM.
12 . A method for updating a keyring with a plurality of keys, the keyring stored on a host computing device that executes a plurality of virtual machines (VMs) and used for encryption operations for data messages associated with at least one particular VM, the method comprises:
receiving a command to (1) fetch a new key for the keyring and (2) remove a particular key from the plurality of keys in the keyring; sending a request for the new key; continuing to process data messages received from the particular VM by using a first set of keys in the keyring including the particular key, while processing data messages transmitted by the particular VM by using a second set of keys in the keyring excluding the particular key; and upon receiving a new key, removing the particular key from the key ring.
13 . The method of claim 12 further comprising processing received and transmitted data messages for the particular VM by using the keyring that includes the new key upon receiving the new key.
14 . The method of claim 2 , wherein the first set of keys includes the particular key and the second set of keys excludes the particular key in order to rotate out the particular key and rotate in the new key when the new key is received, wherein upon receiving the new key both the first and second sets of keys are the same.
15 . The method of claim 12 , wherein the command is received when the particular key has been used for a certain duration of time.
16 . The method of claim 12 , wherein the command is received when the particular key has been used to encrypt at least one of a certain number of data messages and a certain amount of data.
17 . The method of claim 12 , wherein the received command is sent by a controller that generates the command based on statistics that the controller collects from the host computing device regarding data that the particular key was used to encrypt.
18 . The method of claim 12 further comprising receiving the new key from a key generator in response to the sent request, wherein the first and second set of keys are used because of a transit delay in receiving the new key from the key generator.
19 . The method of claim 12 further comprising receiving the new key from a key generator in response to the sent request, wherein the command is received from a controller that monitors usage of keys on the host computing device.
20 . The method of claim 12 , wherein encryption operation are performed on data messages exchanged between the particular VM and other VMs in order to protect said data messages, said particular VM and other VMs forming a logical private network (LPN).Join the waitlist — get patent alerts
Track US2015381362A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.