首页> 外国专利> Restricting guest instances in a shared environment

Restricting guest instances in a shared environment

机译:在共享环境中限制来宾实例

摘要

A method includes a trusted component of a host computing system, obtaining, from a client, via a hypervisor of the host, a request to run an instance of a guest image within the hypervisor. The request includes a unique identifier of the guest image, contents of the guest image, and a communication key. The request is encrypted with a request key accessible to the owner and the trusted component and not accessible to the hypervisor. The trusted component generates an authorization request to an authorizing entity of the client requesting authorization for the hypervisor to run the instance. The authorization request includes the unique identifier, a use counter, and a unique challenge. The trusted component encrypts the authorization request with the communication key and communicates the authorization request to the authorizing entity, via the hypervisor.
机译:一种方法,包括主机计算系统的受信组件,其经由主机的管理程序从客户端获得在管理程序内运行来宾图像的实例的请求。该请求包括访客图像的唯一标识符,访客图像的内容和通信密钥。该请求使用所有者和受信任组件可访问且虚拟机管理程序不可访问的请求密钥进行加密。可信组件向客户端的授权实体生成授权请求,以请求管理程序运行实例的授权。授权请求包括唯一标识符,使用计数器和唯一质询。可信组件使用通信密钥对授权请求进行加密,并通过系统管理程序将授权请求传达给授权实体。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号