PROTECTION SCHEME FOR REMOTELY-STORED DATA
    2.
    发明申请
    PROTECTION SCHEME FOR REMOTELY-STORED DATA 有权
    远程存储数据保护方案

    公开(公告)号:US20150220745A1

    公开(公告)日:2015-08-06

    申请号:US14358789

    申请日:2013-09-27

    申请人: INTEL CORPORATION

    IPC分类号: G06F21/60 G06F9/455

    摘要: The present disclosure is directed to a protection scheme for remotely-stored data. A system may comprise, for example, at least one device including at least one virtual machine (VM) and a trusted execution environment (TEE). The TEE may include an encryption service to encrypt or decrypt data received from the at least one VM. In one embodiment, the at least one VM may include an encryption agent to interact with interfaces in the encryption service. For example, the encryption agent may register with the encryption service, at which time an encryption key corresponding to the at least one VM may be generated. After verifying the registration of the encryption agent, the encryption service may utilize the encryption key corresponding to the at least one VM to encrypt or decrypt data received from the encryption agent. The encryption service may then return the encrypted or decrypted data to the encryption agent.

    摘要翻译: 本公开涉及用于远程存储的数据的保护方案。 系统可以包括例如至少一个包括至少一个虚拟机(VM)和可信执行环境(TEE)的设备。 TEE可以包括加密或加密从至少一个VM接收的数据的加密服务。 在一个实施例中,所述至少一个VM可以包括与加密服务中的接口交互的加密代理。 例如,加密代理可以向加密服务注册,此时可以生成与至少一个VM相对应的加密密钥。 在验证加密代理的注册之后,加密服务可以利用与至少一个VM相对应的加密密钥来加密或解密从加密代理接收的数据。 加密服务然后可以将加密或解密的数据返回给加密代理。

    Apparatus for hardware accelerated runtime integrity measurement

    公开(公告)号:US10146571B2

    公开(公告)日:2018-12-04

    申请号:US15175874

    申请日:2016-06-07

    申请人: Intel Corporation

    摘要: Techniques are described for providing processor-based dedicated fixed function hardware to perform runtime integrity measurements for detecting attacks on system supervisory software, such as a hypervisor or native Operating System (OS). The dedicated fixed function hardware is provided with memory addresses of the system supervisory software for monitoring. After obtaining the memory addresses and other information required to facilitate integrity monitoring, the dedicated fixed function hardware activates a lock-out to prevent reception of any additional information, such as information from a corrupted version of the system supervisory software. The dedicated fixed function hardware then automatically performs periodic integrity measurements of the system supervisory software. Upon detection of an integrity failure, the dedicated fixed function hardware uses out-of-band signaling to report that an integrity failure has occurred.The dedicated fixed function hardware provides for runtime integrity verification of a platform in a secure manner without impacting the performance of the platform.

    Protection scheme for remotely-stored data

    公开(公告)号:US09852299B2

    公开(公告)日:2017-12-26

    申请号:US14358789

    申请日:2013-09-27

    申请人: INTEL CORPORATION

    摘要: The present disclosure is directed to a protection scheme for remotely-stored data. A system may comprise, for example, at least one device including at least one virtual machine (VM) and a trusted execution environment (TEE). The TEE may include an encryption service to encrypt or decrypt data received from the at least one VM. In one embodiment, the at least one VM may include an encryption agent to interact with interfaces in the encryption service. For example, the encryption agent may register with the encryption service, at which time an encryption key corresponding to the at least one VM may be generated. After verifying the registration of the encryption agent, the encryption service may utilize the encryption key corresponding to the at least one VM to encrypt or decrypt data received from the encryption agent. The encryption service may then return the encrypted or decrypted data to the encryption agent.

    Apparatus for Hardware Accelerated Runtime Integrity Measurement
    5.
    发明申请
    Apparatus for Hardware Accelerated Runtime Integrity Measurement 审中-公开
    硬件加速运行时完整性测量装置

    公开(公告)号:US20170024238A1

    公开(公告)日:2017-01-26

    申请号:US15175874

    申请日:2016-06-07

    申请人: Intel Corporation

    IPC分类号: G06F9/455 G06F3/06

    摘要: Techniques are described for providing processor-based dedicated fixed function hardware to perform runtime integrity measurements for detecting attacks on system supervisory software, such as a hypervisor or native Operating System (OS). The dedicated fixed function hardware is provided with memory addresses of the system supervisory software for monitoring. After obtaining the memory addresses and other information required to facilitate integrity monitoring, the dedicated fixed function hardware activates a lock-out to prevent reception of any additional information, such as information from a corrupted version of the system supervisory software. The dedicated fixed function hardware then automatically performs periodic integrity measurements of the system supervisory software. Upon detection of an integrity failure, the dedicated fixed function hardware uses out-of-band signaling to report that an integrity failure has occurred.The dedicated fixed function hardware provides for runtime integrity verification of a platform in a secure manner without impacting the performance of the platform.

    摘要翻译: 专用固定功能硬件以安全的方式提供平台的运行时完整性验证,而不会影响平台的性能。

    Constructing persistent file system from scattered persistent regions
    6.
    发明授权
    Constructing persistent file system from scattered persistent regions 有权
    从分散的持续区域构建持久性文件系统

    公开(公告)号:US09323539B2

    公开(公告)日:2016-04-26

    申请号:US13928875

    申请日:2013-06-27

    申请人: Intel Corporation

    IPC分类号: G06F9/44 G06F12/02 G06F17/30

    摘要: Methods and apparatus related to constructing a persistent file system from scattered persistent regions are described. In one embodiment, stored information in a storage unit corresponds to one or more persistent memory regions that are scattered amongst one or more non-volatile memory devices. The one or more persistent memory regions are byte addressable. Also, the one or more persistent memory regions are used to form a virtual contiguous region. Other embodiments are also disclosed and claimed.

    摘要翻译: 描述了从分散的持续区域构建持久性文件系统的方法和装置。 在一个实施例中,存储单元中存储的信息对应于分散在一个或多个非易失性存储器件中的一个或多个持久性存储器区域。 一个或多个持久性存储器区域是字节可寻址的。 此外,一个或多个持久性存储器区域用于形成虚拟连续区域。 还公开并要求保护其他实施例。

    Controlling memory redundancy in a system
    7.
    发明授权
    Controlling memory redundancy in a system 有权
    控制系统中的内存冗余

    公开(公告)号:US08751864B2

    公开(公告)日:2014-06-10

    申请号:US13848830

    申请日:2013-03-22

    申请人: Intel Corporation

    IPC分类号: G06F11/00

    摘要: In one embodiment, the present invention provides an ability to handle an error occurring during a memory migration operation in a high availability system. In addition, a method can be used to dynamically remap a memory page stored in a non-mirrored memory region of memory to a mirrored memory region. This dynamic remapping may be responsive to a determination that the memory page has been accessed more than a threshold number of times, indicating a criticality of information on the page. Other embodiments are described and claimed.

    摘要翻译: 在一个实施例中,本发明提供了处理在高可用性系统中的存储器迁移操作期间发生的错误的能力。 此外,可以使用一种方法来将存储在存储器的非镜像存储器区域中的存储器页面动态重映射到镜像存储器区域。 该动态重新映射可以响应于确定存储器页已经被访问多于阈值次数,指示页面上的信息的关键性。 描述和要求保护其他实施例。