-
公开(公告)号:US10318765B2
公开(公告)日:2019-06-11
申请号:US14530020
申请日:2014-10-31
Inventor: Stephane Rodgers , Shashank Shekhar , Flaviu Dorin Turean
IPC: G06F11/30 , G06F12/14 , G06F21/71 , H04L9/32 , G06F21/50 , G06F9/455 , G06F21/44 , G06F21/53 , G06F21/57
Abstract: A system and method for securing a hypervisor and operating systems that execute on a computing device. An encrypted hypervisor is uploaded to a hardware chip. Prior to being executed, the hypervisor is decrypted using a secure security processor and stored in an on-chip memory. When a processor on the hardware chip executes the hypervisor, at least one on-chip component continuously authenticates the hypervisor during execution. A hypervisor configures a processor with access rights associated with an operating system, where the access rights determine access of the operating system to an at least one resource. A transaction filter then uses the access rights associated with the operating system to monitor the access of the operating system to the at least one resource in real-time as the operating system executes on a processor.