发明授权
US08812830B2 Attestation protocol for securely booting a guest operating system
有权
用于安全引导客户机操作系统的认证协议
- 专利标题: Attestation protocol for securely booting a guest operating system
- 专利标题(中): 用于安全引导客户机操作系统的认证协议
-
申请号: US13222379申请日: 2011-08-31
-
公开(公告)号: US08812830B2公开(公告)日: 2014-08-19
- 发明人: Himanshu Raj , Stefan Saroiu , Alastair Wolman , Paul England , Anh M. Nguyen , Shravan Rayanchu
- 申请人: Himanshu Raj , Stefan Saroiu , Alastair Wolman , Paul England , Anh M. Nguyen , Shravan Rayanchu
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 代理商 Dan Choi; Carole Boelitz; Micky Minhas
- 主分类号: G06F9/00
- IPC分类号: G06F9/00 ; G06F15/177 ; G06F9/455 ; G06F7/04
摘要:
In a cloud computing environment, a production server virtualization stack is minimized to present fewer security vulnerabilities to malicious software running within a guest virtual machine. The minimal virtualization stack includes support for those virtual devices necessary for the operation of a guest operating system, with the code base of those virtual devices further reduced. Further, a dedicated, isolated boot server provides functionality to securely boot a guest operating system. The boot server is isolated through use of an attestation protocol, by which the boot server presents a secret to a network switch to attest that the boot server is operating in a clean mode. The attestation protocol may further employ a secure co-processor to seal the secret, so that it is only accessible when the boot server is operating in the clean mode.
公开/授权文献
信息查询