Invention Grant
- Patent Title: Secure execution environment on a server
-
Application No.: US15377991Application Date: 2016-12-13
-
Publication No.: US10691803B2Publication Date: 2020-06-23
- Inventor: Anthony Nicholas Liguori , Jason Alexander Harland , Matthew Shawn Wilson , Nafea Bshara , Ziv Harel , Darin Lee Frink
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US WA Seattle
- Agency: Kilpatrick Townsend & Stockton LLP
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F9/4401 ; G06F21/44

Abstract:
Disclosed herein are techniques for maintaining a secure execution environment on a server. In one embodiment, the server includes a non-volatile memory storing firmware, a programmable security logic coupled to the non-volatile memory, an adapter device coupled to the programmable security logic, and a processor communicatively coupled to the non-volatile memory via the programmable security logic. The adapter device and/or the programmable security logic can verify the firmware in the non-volatile memory while holding the processor and/or a baseboard management controller (BMC) in power reset, release the processor and the BMC from reset to boot the processor and the BMC after the firmware is verified, and then disable communications between the processor and the BMC and deny at least some requests to write to the non-volatile memory by the processor or the BMC.
Public/Granted literature
- US20180165455A1 SECURE EXECUTION ENVIRONMENT ON A SERVER Public/Granted day:2018-06-14
Information query