Method and system for providing a trusted platform module in a hypervisor environment
    31.
    发明授权
    Method and system for providing a trusted platform module in a hypervisor environment 有权
    在管理程序环境中提供可信平台模块的方法和系统

    公开(公告)号:US07707411B2

    公开(公告)日:2010-04-27

    申请号:US12261060

    申请日:2008-10-30

    IPC分类号: G06F21/00

    CPC分类号: G06F21/53

    摘要: A method is presented for implementing a trusted computing environment within a data processing system. A hypervisor is initialized within the data processing system, and the hypervisor supervises a plurality of logical, partitionable, runtime environments within the data processing system. The hypervisor reserves a logical partition for a hypervisor-based trusted platform module (TPM) and presents the hypervisor-based trusted platform module to other logical partitions as a virtual device via a device interface. Each time that the hypervisor creates a logical partition within the data processing system, the hypervisor also instantiates a logical TPM within the reserved partition such that the logical TPM is anchored to the hypervisor-based TPM. The hypervisor manages multiple logical TPM's within the reserved partition such that each logical TPM is uniquely associated with a logical partition.

    摘要翻译: 呈现一种用于在数据处理系统内实现可信计算环境的方法。 在数据处理系统内初始化管理程序,并且管理程序监视数据处理系统内的多个逻辑,可分割的运行时环境。 虚拟机管理程序为基于虚拟机管理程序的可信平台模块(TPM)预留逻辑分区,并通过设备接口将基于虚拟机管理程序的可信平台模块作为虚拟设备呈现给其他逻辑分区。 每当虚拟机管理程序在数据处理系统内创建一个逻辑分区时,管理程序也会在保留的分区内实例化一个逻辑TPM,使得逻辑TPM被锚定到基于管理程序的TPM。 虚拟机管理程序管理保留分区内的多个逻辑TPM,使得每个逻辑TPM与逻辑分区唯一相关联。

    Trust evaluation
    32.
    发明授权
    Trust evaluation 有权
    信任评估

    公开(公告)号:US07266475B1

    公开(公告)日:2007-09-04

    申请号:US11355719

    申请日:2006-02-16

    IPC分类号: G06F11/30

    摘要: A solution for evaluating trust in a computer infrastructure is provided. In particular, a plurality of computing devices in the computer infrastructure evaluate one or more other computing devices in the computer infrastructure based on a set of device measurements for the other computing device(s) and a set of reference measurements. To this extent, each of the plurality of computing devices also provides a set of device measurements for processing by the other computing device(s) in the computer infrastructure.

    摘要翻译: 提供了一种评估计算机基础设施信任的解决方案。 特别地,计算机基础设施中的多个计算设备基于用于其他计算设备的一组设备测量值和一组参考测量结果来评估计算机基础结构中的一个或多个其他计算设备。 在这种程度上,多个计算设备中的每一个还提供一组设备测量值以供计算机基础设施中的其他计算设备处理。

    Trusted platform module data harmonization during trusted server rendevous
    33.
    发明授权
    Trusted platform module data harmonization during trusted server rendevous 有权
    受信任的平台模块数据在可信服务器集成期间进行协调

    公开(公告)号:US09122875B2

    公开(公告)日:2015-09-01

    申请号:US11381237

    申请日:2006-05-02

    IPC分类号: G06F21/57

    摘要: Embodiments of the present invention address deficiencies of the art in respect to trusted platform module (TPM) unification in a trusted computing environment and provide a novel and non-obvious method, system and computer program product for trusted platform module data harmonization. In one embodiment of the invention, a TPM log harmonization method can include designating both a single master TPM for a master node among multiple nodes, and also a multiplicity of subsidiary TPMs for remaining ones of the nodes. The method further can include extending the single master TPM with a measurement representing a rendezvous operation for the nodes.

    摘要翻译: 本发明的实施例解决了可信计算环境中可信任平台模块(TPM)统一方面的技术缺陷,并提供了一种用于可信平台模块数据协调的新颖且非显而易见的方法,系统和计算机程序产品。 在本发明的一个实施例中,TPM对数协调方法可以包括指定多个节点之间的主节点的单个主TPM,以及用于剩余节点的多个辅助TPM。 该方法还可以包括使用表示节点的会合操作的测量来扩展单个主TPM。

    Controlling execution of executables between partitions in a multi-partitioned data processing system
    34.
    发明授权
    Controlling execution of executables between partitions in a multi-partitioned data processing system 失效
    控制多分区数据处理系统中分区之间可执行文件的执行

    公开(公告)号:US08695102B2

    公开(公告)日:2014-04-08

    申请号:US11380951

    申请日:2006-05-01

    IPC分类号: G06F21/00

    摘要: A computer implemented method, apparatus, and computer usable program code for assuring data integrity is shown. A partition receives a request to execute an executable file from a source external to the partition. A memory region is created within the partition. The partition or service interface makes an authentication determination. The partition executes an executable file in the memory region based on the request, provided there is a positive authentication determination.

    摘要翻译: 示出了用于确保数据完整性的计算机实现的方法,装置和计算机可用程序代码。 分区从分区外部的源接收执行可执行文件的请求。 在分区内创建一个内存区域。 分区或服务接口进行认证确定。 分区根据请求执行存储器区域中的可执行文件,只要存在肯定的认证确定。

    Method, apparatus, and product for asserting physical presence with a trusted platform module in a hypervisor environment
    36.
    发明授权
    Method, apparatus, and product for asserting physical presence with a trusted platform module in a hypervisor environment 失效
    用于在管理程序环境中用可信平台模块断言物理存在的方法,装置和产品

    公开(公告)号:US07484099B2

    公开(公告)日:2009-01-27

    申请号:US10902712

    申请日:2004-07-29

    IPC分类号: H04L9/00

    摘要: A method, apparatus, and computer program product are described for asserting physical presence in a trusted computing environment included within a data processing system. The trusted computing environment includes a trusted platform module (TPM). The data processing system is coupled to a hardware management console. The trusted platform module determines whether the hardware management console is a trusted entity. The trusted platform module also determines whether the hardware management console has knowledge of a secret key that is possessed by the TPM. If the TPM determines that the hardware management console is a trusted entity and has knowledge of the secret key, the TPM determines that physical presence has been asserted. Otherwise, if the TPM determines that either the hardware management console is not a trusted entity or the TPM determines that the hardware management console does not have knowledge of the secret key, the TPM determines that physical presence has not been asserted and will not execute commands that require the successful assertion of “physical presence”.

    摘要翻译: 描述了一种用于断定包括在数据处理系统内的可信计算环境中的物理存在的方法,装置和计算机程序产品。 可信计算环境包括可信平台模块(TPM)。 数据处理系统耦合到硬件管理控制台。 可信平台模块确定硬件管理控制台是否是可信实体。 可信平台模块还确定硬件管理控制台是否具有TPM拥有的秘密密钥的知识。 如果TPM确定硬件管理控制台是可信赖的实体并具有秘密密钥的知识,则TPM确定物理存在已经被断言。 否则,如果TPM确定硬件管理控制台不是可信实体,或者TPM确定硬件管理控制台不具有秘密密钥的知识,则TPM确定物理存在尚未被断言,并且将不执行命令 这要求成功地断言“身体存在”。

    Method and system for providing a trusted platform module in a hypervisor environment
    37.
    发明授权
    Method and system for providing a trusted platform module in a hypervisor environment 失效
    在管理程序环境中提供可信平台模块的方法和系统

    公开(公告)号:US07484091B2

    公开(公告)日:2009-01-27

    申请号:US10835350

    申请日:2004-04-29

    IPC分类号: G06F21/00

    CPC分类号: G06F21/53

    摘要: A method is presented for implementing a trusted computing environment within a data processing system. A hypervisor is initialized within the data processing system, and the hypervisor supervises a plurality of logical, partitionable, runtime environments within the data processing system. The hypervisor reserves a logical partition for a hypervisor-based trusted platform module (TPM) and presents the hypervisor-based trusted platform module to other logical partitions as a virtual device via a device interface. Each time that the hypervisor creates a logical partition within the data processing system, the hypervisor also instantiates a logical TPM within the reserved partition such that the logical TPM is anchored to the hypervisor-based TPM. The hypervisor manages multiple logical TPM's within the reserved partition such that each logical TPM is uniquely associated with a logical partition.

    摘要翻译: 呈现一种用于在数据处理系统内实现可信计算环境的方法。 在数据处理系统内初始化管理程序,并且管理程序监视数据处理系统内的多个逻辑,可分割的运行时环境。 虚拟机管理程序为基于虚拟机管理程序的可信平台模块(TPM)预留逻辑分区,并通过设备接口将基于虚拟机管理程序的可信平台模块作为虚拟设备呈现给其他逻辑分区。 每当虚拟机管理程序在数据处理系统内创建一个逻辑分区时,管理程序也会在保留的分区内实例化一个逻辑TPM,使得逻辑TPM被锚定到基于管理程序的TPM。 虚拟机管理程序管理保留分区内的多个逻辑TPM,使得每个逻辑TPM与逻辑分区唯一相关联。

    METHOD AND SYSTEM FOR PROVIDING A TRUSTED PLATFORM MODULE IN A HYPERVISOR ENVIRONMENT
    38.
    发明申请
    METHOD AND SYSTEM FOR PROVIDING A TRUSTED PLATFORM MODULE IN A HYPERVISOR ENVIRONMENT 有权
    在高级环境中提供有争议的平台模块的方法和系统

    公开(公告)号:US20090006843A1

    公开(公告)日:2009-01-01

    申请号:US12207487

    申请日:2008-09-09

    IPC分类号: G06F21/00

    CPC分类号: G06F21/53

    摘要: A method is presented for implementing a trusted computing environment within a data processing system. A hypervisor is initialized within the data processing system, and the hypervisor supervises a plurality of logical, partitionable, runtime environments within the data processing system. The hypervisor reserves a logical partition for a hypervisor-based trusted platform module (TPM) and presents the hypervisor-based trusted platform module to other logical partitions as a virtual device via a device interface. Each time that the hypervisor creates a logical partition within the data processing system, the hypervisor also instantiates a logical TPM within the reserved partition such that the logical TPM is anchored to the hypervisor-based TPM. The hypervisor manages multiple logical TPM's within the reserved partition such that each logical TPM is uniquely associated with a logical partition.

    摘要翻译: 呈现一种用于在数据处理系统内实现可信计算环境的方法。 在数据处理系统内初始化管理程序,并且管理程序监视数据处理系统内的多个逻辑,可分割的运行时环境。 虚拟机管理程序为基于虚拟机管理程序的可信平台模块(TPM)预留逻辑分区,并通过设备接口将基于虚拟机管理程序的可信平台模块作为虚拟设备呈现给其他逻辑分区。 每当虚拟机管理程序在数据处理系统内创建一个逻辑分区时,管理程序也会在保留的分区内实例化一个逻辑TPM,使得逻辑TPM被锚定到基于管理程序的TPM。 虚拟机管理程序管理保留分区内的多个逻辑TPM,使得每个逻辑TPM与逻辑分区唯一相关联。

    Trust Evaluation
    39.
    发明申请
    Trust Evaluation 失效
    信任评估

    公开(公告)号:US20090006597A1

    公开(公告)日:2009-01-01

    申请号:US11913193

    申请日:2007-02-16

    IPC分类号: G06F15/173

    摘要: A solution for evaluating trust in a computer infrastructure is provided. In particular, a plurality of computing devices in the computer infrastructure evaluate one or more other computing devices in the computer infrastructure based on a set of device measurements for the other computing device(s) and a set of reference measurements. To this extent, each of the plurality of computing devices also provides a set of device measurements for processing by the other computing device(s) in the computer infrastructure.

    摘要翻译: 提供了一种评估计算机基础设施信任的解决方案。 特别地,计算机基础设施中的多个计算设备基于用于其他计算设备的一组设备测量值和一组参考测量结果来评估计算机基础结构中的一个或多个其他计算设备。 在这种程度上,多个计算设备中的每一个还提供一组设备测量值以供计算机基础设施中的其他计算设备处理。

    Method and system for virtualization of trusted platform modules
    40.
    发明授权
    Method and system for virtualization of trusted platform modules 有权
    可信平台模块虚拟化的方法和系统

    公开(公告)号:US07380119B2

    公开(公告)日:2008-05-27

    申请号:US10835330

    申请日:2004-04-29

    IPC分类号: G06F1/24

    摘要: A method, an apparatus, a system, and a computer program product is presented for virtualizing trusted platform modules within a data processing system. A virtual trusted platform module along with a virtual endorsement key is created within a physical trusted platform module within the data processing system using a platform signing key of the physical trusted platform module, thereby providing a transitive trust relationship between the virtual trusted platform module and the core root of trust for the trusted platform. The virtual trusted platform module can be uniquely associated with a partition in a partitionable runtime environment within the data processing system.

    摘要翻译: 提出了一种方法,装置,系统和计算机程序产品,用于虚拟化数据处理系统内的可信平台模块。 使用物理可信平台模块的平台签名密钥在数据处理系统内的物理可信平台模块内创建虚拟可信平台模块以及虚拟认证密钥,从而在虚拟可信平台模块和虚拟可信平台模块之间提供传递信任关系 信任平台的核心信任根源。 虚拟可信平台模块可以与数据处理系统内的可分区运行时环境中的分区唯一关联。