Apparatus for controlling processor execution in a secure environment
    3.
    发明授权
    Apparatus for controlling processor execution in a secure environment 有权
    用于在安全环境中控制处理器执行的装置

    公开(公告)号:US09043902B2

    公开(公告)日:2015-05-26

    申请号:US14026143

    申请日:2013-09-13

    申请人: Nagrastar LLC

    摘要: Various embodiments described herein relate to apparatus for executing software in a secure computing environment. A secure processor can be used and configured to request a context swap from a first context to a second context when switching execution from a first portion of software to a second portion of software. A context manager, which can be in communication with the secure processor, can be configured to receive and initiate a requested context swap. A trust vector verifier, which can be in communication with the secure processor and the context manager, can be configured to load a trust vector descriptor upon command from a context manager.

    摘要翻译: 本文描述的各种实施例涉及用于在安全计算环境中执行软件的装置。 当将软件的第一部分切换到软件的第二部分时,安全处理器可以被使用和配置为请求从第一上下文到第二上下文的上下文交换。 可以与安全处理器通信的上下文管理器可被配置为接收和发起所请求的上下文交换。 可以将可与安全处理器和上下文管理器通信的信任向量验证器配置成从上下文管理器命令加载信任向量描述符。

    Systems and methods for performing transport I/O

    公开(公告)号:US10382816B2

    公开(公告)日:2019-08-13

    申请号:US15710340

    申请日:2017-09-20

    申请人: NAGRASTAR, LLC

    摘要: Systems and methods for implementing a Transport I/O system are described. Network encrypted content may be received by a device. The device may provide the network encrypted content to a secure processor, such as, for example, a smart card. The secure processor obtains a network control work that may be used to decrypt the network encrypted content. The secure processor may decrypt the network encrypted content to produce clear content. In embodiments, the secure processor may then use a local control word to generate locally encrypted content specific to the device. The device may then receive the locally encrypted content from the secure processor and proceed to decrypt the locally encrypted content using a shared local encryption key. The transport I/O system ensures the protection of the network control word by maintaining the network control word on the secure processor.

    SYSTEMS AND METHODS FOR PERFORMING TRANSPORT I/O
    9.
    发明申请
    SYSTEMS AND METHODS FOR PERFORMING TRANSPORT I/O 有权
    用于执行运输I / O的系统和方法

    公开(公告)号:US20140282685A1

    公开(公告)日:2014-09-18

    申请号:US13799891

    申请日:2013-03-13

    申请人: NAGRASTAR LLC

    摘要: Systems and methods for implementing a Transport I/O system are described. Network encrypted content may be received by a device. The device may provide the network encrypted content to a secure processor, such as, for example, a smart card. The secure processor obtains a network control word that may be used to decrypt the network encrypted content. The secure processor may decrypt the network encrypted content to produce clear content. In embodiments, the secure processor may then use a local control word to generate locally encrypted content specific to the device. The device may then receive the locally encrypted content from the secure processor and proceed to decrypt the locally encrypted content using a shared local encryption key. The Transport I/O system ensures the protection of the network control word by maintaining the network control word on the secure processor.

    摘要翻译: 描述了用于实现传输I / O系统的系统和方法。 网络加密内容可能被设备接收。 该设备可以将网络加密内容提供给安全处理器,例如智能卡。 安全处理器获得可用于解密网络加密内容的网络控制字。 安全处理器可以解密网络加密的内容以产生清晰的内容。 在实施例中,安全处理器然后可以使用本地控制字来产生特定于设备的本地加密的内容。 然后,设备可以从安全处理器接收本地加密的内容,并使用共享的本地加密密钥继续解密本地加密的内容。 传输I / O系统通过维护安全处理器上的网络控制字来确​​保网络控制字的保护。