Patent attributes
A system for securing kernel metadata communication in environments employing distributed software services includes a first and a second host linked by a network, where a distributed software service stack at each host includes a respective user-mode software layer and a respective kernel-mode software layer. The first host may be configured to establish a user-mode connection with the second host, e.g., using a secure user-mode communication protocol such as SSL (Secure Sockets Layer). The first and the second hosts may then exchange respective security keys over the secure user-mode connection, upload the security keys to the respective kernel-mode software layers, and use the security keys to secure communication over a kernel-mode connection between the two hosts.