METHOD AND APPARATUS FOR PROVIDING SECURE VIRTUALIZATION OF A TRUSTED PLATFORM MODULE
    2.
    发明授权
    METHOD AND APPARATUS FOR PROVIDING SECURE VIRTUALIZATION OF A TRUSTED PLATFORM MODULE 有权
    用于提供可信平台模块的安全虚拟化的方法和装置(TPM)

    公开(公告)号:EP1759261B1

    公开(公告)日:2012-08-01

    申请号:EP05757249.7

    申请日:2005-06-03

    申请人: Intel Corporation

    IPC分类号: G06F21/00

    摘要: A method and a related apparatus provide a virtual trusted platform module (TPM). In an example embodiment, a virtual TPM service creates a virtual TPM for use in a processing system that contains a physical TPM. The virtual TPM service may store a key for the virtual TPM in the physical TPM. The virtual TPM service may then use the virtual TPM to provide emulated physical TPM features. In one embodiment, the virtual TPM service may use the virtual TPM to emulate a physical TPM for a virtual machine in the processing system. Other embodiments are described and claimed.

    METHOD AND APPARATUS FOR PROVIDING SOFTWARE-BASED SECURITY COPROCESSORS
    4.
    发明公开
    METHOD AND APPARATUS FOR PROVIDING SOFTWARE-BASED SECURITY COPROCESSORS 审中-公开
    VERFAHREN UND VORRICHTUNG ZUR BEREITSTELLUNG VON SOFTWAREBASIERTEN SICHERHEITS-KOPROZESSOREN

    公开(公告)号:EP1880339A2

    公开(公告)日:2008-01-23

    申请号:EP06759818.5

    申请日:2006-05-11

    申请人: Intel Corporation

    IPC分类号: G06F21/00

    摘要: A virtual security coprocessor framework supports creation of at least one device model to emulate a predetermined cryptographic coprocessor. In one embodiment, the virtual security coprocessor framework uses a cryptographic coprocessor in a processing system to create an instance of the device model (DM) in the processing system. The DM may be based at least in part on a predetermined device model design. The DM may emulate the predetermined cryptographic coprocessor in accordance with the control logic of the device model design. In one embodiment, the virtual security coprocessor framework uses a physical trusted platform module (TPM) in a processing system to support one or more virtual TPMs (vTPMs) for one or more virtual machines (VMs) in the processing system. Other embodiments are described and claimed.

    摘要翻译: 虚拟安全协处理器框架支持创建至少一个设备模型来模拟预定的密码协处理器。 在一个实施例中,虚拟安全协处理器框架在处理系统中使用密码协处理器来在处理系统中创建设备模型(DM)的实例。 DM可以至少部分地基于预定的设备模型设计。 DM可以根据设备模型设计的控制逻辑来模拟预定的密码协处理器。 在一个实施例中,虚拟安全协处理器框架使用处理系统中的物理可信平台模块(TPM)来支持处理系统中的一个或多个虚拟机(VM)的一个或多个虚拟TPM(vTPM)。 描述和要求保护其他实施例。

    MUTUALLY ASSURED DATA SHARING BETWEEN DISTRUSTING PARTIES IN A NETWORK ENVIRONMENT
    5.
    发明公开
    MUTUALLY ASSURED DATA SHARING BETWEEN DISTRUSTING PARTIES IN A NETWORK ENVIRONMENT 有权
    对方MISS TRAU各方相互保证的数据共享在网络邻居

    公开(公告)号:EP2973184A1

    公开(公告)日:2016-01-20

    申请号:EP14769762.7

    申请日:2014-03-12

    申请人: Intel Corporation

    IPC分类号: G06F21/60 G06F15/16

    摘要: An apparatus for sharing information between entities includes a processor and a trusted execution module executing on the processor. The trusted execution module is configured to receive first confidential information from a first client device associated with a first entity, seal the first confidential information within a trusted execution environment, receive second confidential information from a second client device associated with a second entity, seal the second confidential information within the trusted execution environment, and execute code within the trusted execution environment. The code is configured to compute a confidential result based upon the first confidential information and the second confidential information.

    摘要翻译: 用于实体之间共享信息的一种装置包括处理器,并且所述处理器上执行的可信执行模块。 可信执行模块被配置为从与第一实体相关联的第一客户端设备接收第一保密信息,密封可信执行环境内的所述第一保密信息,从与第二实体相关联的第二客户端设备接收第二机密信息,密封 受信任执行环境内第二保密信息,和受信任执行环境内执行的代码。 该代码被配置为计算基于所述第一秘密信息和第二机密信息的机密的结果。

    COOPERATIVE EMBEDDED AGENTS
    6.
    发明公开
    COOPERATIVE EMBEDDED AGENTS 有权
    KOOPIERENDE剂在嵌入式系统

    公开(公告)号:EP1727625A2

    公开(公告)日:2006-12-06

    申请号:EP05725651.3

    申请日:2005-03-14

    申请人: Intel Corporation

    IPC分类号: B05D1/36 G06F9/06

    CPC分类号: G06F9/4411

    摘要: An electronic apparatus has an embeded firmware agent having instructions for selectively operating in a management mode and an embedded controller agent operating independent of a host operating system and selectively invoking the management mode. A bidirectional agent bus is coupled in between the embedded firmware agent and embedded controller agent to transmit messages between both the agents. Manageability and security operations that can be performed on a host system having these cooperative embedded agents.

    AN APPARATUS AND METHOD FOR MEMORY ENCRYPTION WITH REDUCED DECRYPTION LATENCY
    9.
    发明公开
    AN APPARATUS AND METHOD FOR MEMORY ENCRYPTION WITH REDUCED DECRYPTION LATENCY 审中-公开
    装置和方法进行加密以减少的时延解码的存储器

    公开(公告)号:EP1654661A2

    公开(公告)日:2006-05-10

    申请号:EP04754772.4

    申请日:2004-06-09

    申请人: INTEL CORPORATION

    IPC分类号: G06F12/14 G06F1/00

    摘要: A method and apparatus for memory encryption with reduced decryption latency. In one embodiment, the method includes reading an encrypted data block from memory. During reading of the encrypted data block, a keystream used to encrypt the data block is regenerated according to one or more stored criteria of the encrypted data block. Once the encrypted data block is read, the encrypted data block is decrypted using the regenerated keystream. Accordingly, in one embodiment, encryption of either random access memory (RAM) or disk memory is performed. A keystream is regenerated during data retrieval such that once the data is received, the data may be decrypted using a single clock operation. As a result, memory encryption is performed without exacerbating memory latency between the processor and memory.

    摘要翻译: 一种用于具有降低的解密等待时间的存储器的加密方法和设备。 在一个,实施例的方法包括:从存储器的加密数据块的读出。 期间读取的加密数据块的,密钥流用于加密所述数据块被再生gemäß到一个或多个存储的加密数据块的条件。 一旦加密数据块被读取,加密的数据块使用再生的密钥流解密。 因此,在一个实施方式中,进行任一随机存取存储器(RAM)或磁盘存储器的加密。 密钥流被再生期间的数据检索搜索做一旦接收到数据时,数据可以使用单个时钟操作被解密。 其结果是,存储器加密进行不加剧了处理器和存储器之间的存储器等待时间。