Hardware enforced memory access permissions
    3.
    发明授权
    Hardware enforced memory access permissions 有权
    硬件强制执行内存访问权限

    公开(公告)号:US09286245B2

    公开(公告)日:2016-03-15

    申请号:US13995360

    申请日:2011-12-30

    摘要: Embodiments of apparatuses and methods for hardware enforced memory access permissions are disclosed. In one embodiment, a processor includes address translation hardware and memory access hardware. The address translation hardware is to support translation of a first address, used by software to access a memory, to a second address, used by the processor to access the memory. The memory access hardware is to detect an access permission violation.

    摘要翻译: 公开了用于硬件强制存储器访问许可的装置和方法的实施例。 在一个实施例中,处理器包括地址转换硬件和存储器访问硬件。 地址转换硬件是支持由软件使用的访问存储器的第一地址到由处理器使用以访问存储器的第二地址的翻译。 内存访问硬件是检测访问权限冲突。

    HARDWARE ENFORCED MEMORY ACCESS PERMISSIONS
    5.
    发明申请
    HARDWARE ENFORCED MEMORY ACCESS PERMISSIONS 有权
    硬件执行存储器访问许可

    公开(公告)号:US20140041033A1

    公开(公告)日:2014-02-06

    申请号:US13995360

    申请日:2011-12-30

    IPC分类号: G06F12/14

    摘要: Embodiments of apparatuses and methods for hardware enforced memory access permissions are disclosed. In one embodiment, a processor includes address translation hardware and memory access hardware. The address translation hardware is to support translation of a first address, used by software to access a memory, to a second address, used by the processor to access the memory. The memory access hardware is to detect an access permission violation.

    摘要翻译: 公开了用于硬件强制存储器访问许可的装置和方法的实施例。 在一个实施例中,处理器包括地址转换硬件和存储器访问硬件。 地址转换硬件是支持由软件使用的访问存储器的第一地址到由处理器使用以访问存储器的第二地址的翻译。 内存访问硬件是检测访问权限冲突。

    Executing trusted applications with reduced trusted computing base
    6.
    发明授权
    Executing trusted applications with reduced trusted computing base 有权
    通过减少可信计算基础执行可信应用程序

    公开(公告)号:US08776245B2

    公开(公告)日:2014-07-08

    申请号:US12645900

    申请日:2009-12-23

    IPC分类号: G06F21/00 G06F21/57 G06F21/50

    摘要: A system for executing trusted applications with a reduced trusted computing base. In one embodiment, the system includes a processor to dynamically instantiate an application protection module in response to a request by a program to be executed under a trusted mode. The system further includes memory to store the program which is capable of interacting with a remote service for security verification. In one embodiment, the application protection module includes a processor-measured application protection service (P-MAPS) operable to measure and to provide protection to the application.

    摘要翻译: 用于使用减少的可信计算基础来执行可信应用的系统。 在一个实施例中,系统包括处理器,以响应于在可信模式下执行的程序的请求来动态地实例化应用保护模块。 该系统还包括用于存储能够与远程服务进行交互以进行安全验证的程序的存储器。 在一个实施例中,应用保护模块包括可操作以测量并向应用提供保护的经处理器测量的应用保护服务(P-MAPS)。

    Executing Trusted Applications with Reduced Trusted Computing Base
    7.
    发明申请
    Executing Trusted Applications with Reduced Trusted Computing Base 有权
    使用可信赖的计算机基础执行可信赖的应用程序

    公开(公告)号:US20110154500A1

    公开(公告)日:2011-06-23

    申请号:US12645900

    申请日:2009-12-23

    IPC分类号: G06F21/00

    摘要: A system for executing trusted applications with a reduced trusted computing base. In one embodiment, the system includes a processor to dynamically instantiate an application protection module in response to a request by a program to be executed under a trusted mode. The system further includes memory to store the program which is capable of interacting with a remote service for security verification. In one embodiment, the application protection module includes a processor-measured application protection service (P-MAPS) operable to measure and to provide protection to the application.

    摘要翻译: 用于使用减少的可信计算基础来执行可信应用的系统。 在一个实施例中,系统包括处理器,以响应于在可信模式下执行的程序的请求来动态地实例化应用保护模块。 该系统还包括用于存储能够与远程服务进行交互以进行安全验证的程序的存储器。 在一个实施例中,应用保护模块包括可操作以测量并向应用提供保护的经处理器测量的应用保护服务(P-MAPS)。

    Secure video ouput path
    8.
    发明授权
    Secure video ouput path 有权
    安全视频输出路径

    公开(公告)号:US09501668B2

    公开(公告)日:2016-11-22

    申请号:US14036263

    申请日:2013-09-25

    摘要: Systems and methods for secure delivery of output surface bitmaps to a display engine. An example processing system comprises: an architecturally protected memory; and a processing core communicatively coupled to the architecturally protected memory, the processing core comprising a processing logic configured to implement an architecturally-protected execution environment by performing at least one of: executing instructions residing in the architecturally protected memory and preventing an unauthorized access to the architecturally protected memory; wherein the processing logic is further configured to provide a secure video output path by generating an output surface bitmap encrypted with a first encryption key and storing an encrypted first encryption key in an external memory, wherein the encrypted first encryption key is produced by encrypting the first encryption key with a second encryption key.

    摘要翻译: 用于将输出表面位图安全传递到显示引擎的系统和方法。 一个示例处理系统包括:架构受保护的存储器; 以及处理核心,其通信地耦合到所述体系结构保护的存储器,所述处理核心包括处理逻辑,所述处理逻辑被配置为通过执行以下中的至少一个来实现架构保护的执行环境:执行驻留在所述体系结构保护的存储器中的指令, 建筑保护记忆; 其中所述处理逻辑还被配置为通过生成用第一加密密钥加密并将加密的第一加密密钥存储在外部存储器中的输出表面位图来提供安全视频输出路径,其中所述加密的第一加密密钥是通过加密所述第一加密密钥 具有第二加密密钥的加密密钥。

    DEVICE, METHOD, AND SYSTEM FOR CONTROLLING ACCESS TO WEB OBJECTS OF A WEBPAGE OR WEB-BROWSER APPLICATION
    10.
    发明申请
    DEVICE, METHOD, AND SYSTEM FOR CONTROLLING ACCESS TO WEB OBJECTS OF A WEBPAGE OR WEB-BROWSER APPLICATION 审中-公开
    用于控制访问网页或网络浏览器应用程序的WEB对象的设备,方法和系统

    公开(公告)号:US20140095870A1

    公开(公告)日:2014-04-03

    申请号:US13631419

    申请日:2012-09-28

    IPC分类号: G06F21/00 H04L9/32

    摘要: A method and device for securely displaying web content with secure web objects across untrusted channels includes downloading web content from a web server. The web content includes tags that a web browser uses to authenticate the current user and identify encrypted web objects packaged in the web content. The computing device authenticates the current user using a biometric recognition procedure. If the current user is authenticated and determined to be authorized to view the decrypted web object, the encrypted web object is decrypted and displayed to the user. If the user is unauthenticated, the encrypted web object is displayed in place of the encrypted web object such that the decrypted web object is displayed for only authorized persons physically present at the computing device. The biometric recognition procedure and web object decryption processes are protected through secure media path circuitry and secure memory.

    摘要翻译: 用于在不受信任的频道上安全地显示具有安全web对象的web内容的方法和装置包括从Web服务器下载web内容。 网页内容包括网页浏览器用来验证当前用户并识别打包在网页内容中的加密网页对象的标签。 计算设备使用生物识别程序认证当前用户。 如果当前用户被认证并被确定为被授权以查看解密的web对象,则加密的web对象被解密并显示给用户。 如果用户未经身份验证,则加密的web对象被显示代替加密的web对象,使得被解密的web对象被显示给仅在物理存在于计算设备处的授权人员。 生物识别程序和web对象解密过程通过安全媒体路径电路和安全存储器进行保护。