COMPOSABLE TRUSTED EXECUTION ENVIRONMENTS

    公开(公告)号:US20220019667A1

    公开(公告)日:2022-01-20

    申请号:US17354733

    申请日:2021-06-22

    Abstract: In one embodiment, an apparatus comprises a processor to: receive a request to configure a secure execution environment for a first workload; configure a first set of secure execution enclaves for execution of the first workload, wherein the first set of secure execution enclaves is configured on a first set of processing resources, wherein the first set of processing resources comprises one or more central processing units and one or more accelerators; configure a first set of secure datapaths for communication among the first set of secure execution enclaves during execution of the first workload, wherein the first set of secure datapaths is configured over a first set of interconnect resources; configure the secure execution environment for the first workload, wherein the secure execution environment comprises the first set of secure execution enclaves and the first set of secure datapaths.

    Composable trustworthy execution environments

    公开(公告)号:US11048800B2

    公开(公告)日:2021-06-29

    申请号:US16362218

    申请日:2019-03-22

    Abstract: In one embodiment, an apparatus comprises a processor to: receive a request to configure a secure execution environment for a first workload; configure a first set of secure execution enclaves for execution of the first workload, wherein the first set of secure execution enclaves is configured on a first set of processing resources, wherein the first set of processing resources comprises one or more central processing units and one or more accelerators; configure a first set of secure datapaths for communication among the first set of secure execution enclaves during execution of the first workload, wherein the first set of secure datapaths is configured over a first set of interconnect resources; configure the secure execution environment for the first workload, wherein the secure execution environment comprises the first set of secure execution enclaves and the first set of secure datapaths.

    Technologies for supporting multiple digital rights management protocols on a client device

    公开(公告)号:US09781113B2

    公开(公告)日:2017-10-03

    申请号:US14360161

    申请日:2013-12-19

    CPC classification number: H04L63/10 G06F21/10 G06F2221/0708 H04L67/42

    Abstract: Technologies for supporting and implementing multiple digital rights management protocols on a client device are described. In some embodiments, the technologies include a client device having an architectural enclave which may function to identify one of a plurality of digital rights management protocols for protecting digital information to be received from a content provider or a sensor. The architectural enclave select a preexisting secure information processing environment (SIPE) to process said digital information, if a preexisting SIPE supporting the DRM protocol is present on the client. If a preexisting SIPE supporting the DRM protocol is not present on the client, the architectural enclave may general a new SIPE that supports the DRM protocol on the client. Transmission of the digital information may then be directed to the selected preexisting SIPE or the new SIPE, as appropriate.

    METHOD AND APPARATUS FOR MANAGING THE PRIVACY AND DISCLOSURE OF LOCATION INFORMATION
    7.
    发明申请
    METHOD AND APPARATUS FOR MANAGING THE PRIVACY AND DISCLOSURE OF LOCATION INFORMATION 有权
    管理隐私和发布位置信息的方法和装置

    公开(公告)号:US20130326629A1

    公开(公告)日:2013-12-05

    申请号:US13893860

    申请日:2013-05-14

    CPC classification number: G06F21/60 G06F21/6245 H04W12/02

    Abstract: An approach for managing the privacy and disclosure of location information associated with a computer system. For one aspect, a request is received from a requestor for a location property associated with a location of a computer system. It is then determined whether a privacy preference associated with the requestor has been specified. If not, a user may be prompted to supply privacy preferences associated with the requestor. The privacy preferences are then applied to determine whether or not to provide the requested information. A user setting, such as a basic input-output system memory location setting, may also be implemented to enable and/or disable location-aware computing.

    Abstract translation: 用于管理与计算机系统相关联的位置信息的隐私和公开的方法。 一方面,从请求者接收与计算机系统的位置相关联的位置属性的请求。 然后确定是否已经指定了与请求者相关联的隐私偏好。 如果不是,则可能提示用户提供与请求者相关联的隐私偏好。 然后应用隐私偏好以确定是否提供所请求的信息。 还可以实现诸如基本输入 - 输出系统存储器位置设置的用户设置以启用和/或禁用位置感知计算。

    Technologies for supporting multiple digital rights management protocols on a client device

    公开(公告)号:US10187389B2

    公开(公告)日:2019-01-22

    申请号:US15653125

    申请日:2017-07-18

    Abstract: Technologies for supporting and implementing multiple digital rights management protocols on a client device are described. In some embodiments, the technologies include a client device having an architectural enclave which may function to identify one of a plurality of digital rights management protocols for protecting digital information to be received from a content provider or a sensor. The architectural enclave select a preexisting secure information processing environment (SIPE) to process said digital information, if a preexisting SIPE supporting the DRM protocol is present on the client. If a preexisting SIPE supporting the DRM protocol is not present on the client, the architectural enclave may general a new SIPE that supports the DRM protocol on the client. Transmission of the digital information may then be directed to the selected preexisting SIPE or the new SIPE, as appropriate.

    Techniques for securing use of one-time passwords
    10.
    发明授权
    Techniques for securing use of one-time passwords 有权
    确保使用一次性密码的技术

    公开(公告)号:US09208354B2

    公开(公告)日:2015-12-08

    申请号:US13797915

    申请日:2013-03-12

    CPC classification number: G06F21/72 G06F21/31 G06F21/57

    Abstract: Various embodiments are generally directed to the provision and use of a secure enclave defined within a storage of a computing device by a processor element thereof to store executable instructions of an OTP component implementing logic to generate and use one-time passwords (OTPs) to enable access to services provided by another computing device. An apparatus includes a storage; a first processor element; and first logic to receive a one-time password (OTP) routine, store the OTP routine within a first secure enclave defined by the first processor element within the storage, obtain a measure of the contents of the first secure enclave with the OTP routine stored therein, transmit the first measure to a computing device, and receive an OTP seed. Other embodiments are described and claimed.

    Abstract translation: 各种实施例通常涉及提供和使用通过其处理器元件在计算设备的存储器内定义的安全空间,以存储实现逻辑的OTP组件的可执行指令,以生成和使用一次性密码(OTP)来实现 访问由另一计算设备提供的服务。 一种装置包括存储装置; 第一处理器元件; 以及接收一次密码(OTP)例程的第一逻辑,将OTP例程存储在由存储器内的第一处理器元件定义的第一安全空间内,获得存储有OTP例程的第一安全飞地的内容的度量 在其中将第一测量发送到计算设备,并且接收OTP种子。 描述和要求保护其他实施例。

Patent Agency Ranking