-
公开(公告)号:US20240364531A1
公开(公告)日:2024-10-31
申请号:US18250838
申请日:2023-03-22
申请人: Google LLC
发明人: Vidya Bharat Satyamsetti , Jeffrey Thomas Andersen , Jordan Thomas Hand , Christopher Edward Fenner
CPC分类号: H04L9/3242 , G06F21/57 , H04L9/0825 , H04L9/0877
摘要: Provided are computing systems that feature a centralized attestation device able to perform attestation on behalf of a number of different platform components. More particularly, the present disclosure provides extensible mechanisms for representing trustworthiness statements by an attester device within a platform either as implicit attestation or explicit attestation. Thus, according to one aspect of the present disclosure, a computing system can include an attester device that implements a hybrid model for presenting evidence of measurements of all the components in a platform to a verifier.
-
公开(公告)号:US20240333513A1
公开(公告)日:2024-10-03
申请号:US18250851
申请日:2023-03-22
申请人: Google LLC
发明人: Jordan Thomas Hand , Christopher Edward Fenner , Jeffrey Thomas Andersen , Vidya Bharat Satyamsetti
CPC分类号: H04L9/3234 , H04L9/0877 , H04L9/3271
摘要: The present disclosure provides systems and methods for demonstrating the identity of a central processing unit (CPU) to a Trusted Platform Module (TPM) with improved security against, for example, interposers on a communications bus. In particular, according to an aspect of the present disclosure, a CPU can generate a policy alias key that can be used to sign a challenge to prove the identity of the CPU to the TPM. Specifically, the policy alias key can be generated by the CPU by performing a key derivation function on a combined identity value generated by the CPU for the CPU and TPM. The combined identity value can be generated by the CPU from a CPU device identity value and a public endorsement key (EK) associated with the TPM.
-