NAND-BASED VERIFIED BOOT
    2.
    发明公开

    公开(公告)号:EP3356986A1

    公开(公告)日:2018-08-08

    申请号:EP16775421.7

    申请日:2016-09-20

    申请人: Google LLC

    IPC分类号: G06F21/57 G06F21/60

    摘要: A device including a NAND-flash memory comprising a read-only portion storing boot code and a key, and a system on a chip (SoC) coupled to the NAND-flash memory is provided. The SoC includes a read-only memory (ROM) storing one or more instructions and a processor configured to execute, upon startup, the one or more instructions stored in the ROM to request from the NAND-flash memory the boot code and the key. The processor further configured to load and execute the boot code to perform a chain of trust verification process on subsequent code during a booting process using the key. A method for using the device is also presented.

    SECURE CREATION OF ENCRYPTED VIRTUAL MACHINES FROM ENCRYPTED TEMPLATES
    10.
    发明公开
    SECURE CREATION OF ENCRYPTED VIRTUAL MACHINES FROM ENCRYPTED TEMPLATES 审中-公开
    从加密模板安全地创建加密的虚拟机

    公开(公告)号:EP3218839A2

    公开(公告)日:2017-09-20

    申请号:EP15860036.1

    申请日:2015-11-03

    IPC分类号: G06F21/57

    摘要: Booting a machine in a secure fashion in a potentially unsecure environment. The method includes a target machine beginning a boot process. The method further includes the target machine determining that it needs provisioning data to continue booting. The target machine contacts a secure infrastructure to obtain the provisioning data. The target machine provides an identity claim that can be verified by the secure infrastructure. As a result of the secure infrastructure verifying the identity claim, the target machine receives a request from the secure infrastructure to establish a key sealed to the target machine. The target machine provides the established key to the secure infrastructure. The target machine receives the provisioning data from the secure infrastructure. The provisioning data is encrypted to the established key. The target machine decrypts the encrypted provisioning data, and uses the provisioning data to finish booting.

    摘要翻译: 在可能不安全的环境中以安全的方式引导机器。 该方法包括目标机器开始启动过程。 该方法还包括目标机器确定它需要供应数据以继续引导。 目标机器联系安全基础设施以获取供应数据。 目标机器提供可以由安全基础结构验证的身份声明。 由于安全基础设施验证身份声明,目标机器收到来自安全基础设施的请求以建立密封到目标机器的密钥。 目标机器将建立的密钥提供给安全基础设施。 目标机器从安全基础架构接收配置数据。 配置数据被加密到已建立的密钥。 目标机器解密加密的供应数据,并使用供应数据完成引导。