Secure server and compute nodes

A computing system comprising: a node 118 for executing remotely-provided software; a secure enclave 120 to control the execution of trusted or untrusted software by the node, via the selective resetting the compute node 132; and an enclave memory 152 accessible by the compute node and the secure en...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
1. Verfasser: Milosch Meriac
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:A computing system comprising: a node 118 for executing remotely-provided software; a secure enclave 120 to control the execution of trusted or untrusted software by the node, via the selective resetting the compute node 132; and an enclave memory 152 accessible by the compute node and the secure enclave, to store remotely-provided software for execution by the node. The secure enclave comprises a cryptographic identity 122. The secure enclave verifies a remotely-provided boot image for execution by the compute node using public-key signature verification and is configured to, in the event of a successful verification of the boot image, enable the compute node to boot using the verified boot image and execute for a period defined by a time-bound certificate. The secure enclave then reverts control of the compute node once a tenancy period of the compute node expires by resetting the compute node.