Runtime platform firmware verification
    3.
    发明授权
    Runtime platform firmware verification 有权
    运行时平台固件验证

    公开(公告)号:US08590040B2

    公开(公告)日:2013-11-19

    申请号:US12976523

    申请日:2010-12-22

    IPC分类号: G06F21/00

    CPC分类号: G06F21/572

    摘要: Embodiments of the invention are directed towards logic and/or modules stored in processor secure storage to determine whether a first platform firmware image (e.g., basic input/output system (BIOS), device read-only memory (ROM), manageability engine firmware) loaded onto a processor cache is valid. The processor executes the first platform firmware image if it is determined to be valid. If the first platform image is determined to be invalid, a second platform firmware image is located. If this platform firmware image is determined to be valid, the processor will execute said second platform image.In some embodiments of the invention, the determination of whether the first platform firmware image is valid is based, at least in part, on verification of a digital signature associated with the first platform firmware image. The digital signature may be created, for example, from a private key, wherein the digital signature is verified via a public key.

    摘要翻译: 本发明的实施例针对存储在处理器安全存储器中的逻辑和/或模块来确定第一平台固件映像(例如,基本输入/输出系统(BIOS),设备只读存储器(ROM),可管理性引擎固件) 加载到处理器缓存中是有效的。 如果判定为有效,则处理器执行第一平台固件映像。 如果第一平台图像被确定为无效,则定位第二平台固件图像。 如果该平台固件图像被确定为有效,则处理器将执行所述第二平台图像。 在本发明的一些实施例中,确定第一平台固件图像是否有效是至少部分地基于与第一平台固件图像相关联的数字签名的验证。 可以例如从私钥来创建数字签名,其中通过公钥验证数字签名。

    RUNTIME PLATFORM FIRMWARE VERIFICATION
    5.
    发明申请
    RUNTIME PLATFORM FIRMWARE VERIFICATION 有权
    运行平台固件验证

    公开(公告)号:US20120167205A1

    公开(公告)日:2012-06-28

    申请号:US12976523

    申请日:2010-12-22

    IPC分类号: G06F21/00

    CPC分类号: G06F21/572

    摘要: Embodiments of the invention are directed towards logic and/or modules stored in processor secure storage to determine whether a first platform firmware image (e.g., basic input/output system (BIOS), device read-only memory (ROM), manageability engine firmware) loaded onto a processor cache is valid. The processor executes the first platform firmware image if it is determined to be valid. If the first platform image is determined to be invalid, a second platform firmware image is located. If this platform firmware image is determined to be valid, the processor will execute said second platform image.In some embodiments of the invention, the determination of whether the first platform firmware image is valid is based, at least in part, on verification of a digital signature associated with the first platform firmware image. The digital signature may be created, for example, from a private key, wherein the digital signature is verified via a public key.

    摘要翻译: 本发明的实施例针对存储在处理器安全存储器中的逻辑和/或模块来确定第一平台固件映像(例如,基本输入/输出系统(BIOS),设备只读存储器(ROM),可管理性引擎固件) 加载到处理器缓存中是有效的。 如果判定为有效,则处理器执行第一平台固件映像。 如果第一平台图像被确定为无效,则定位第二平台固件图像。 如果该平台固件图像被确定为有效,则处理器将执行所述第二平台图像。 在本发明的一些实施例中,确定第一平台固件图像是否有效是至少部分地基于与第一平台固件图像相关联的数字签名的验证。 可以例如从私钥来创建数字签名,其中通过公钥验证数字签名。

    VIRTUALIZING INTERRUPT PRIORITY AND DELIVERY
    8.
    发明申请
    VIRTUALIZING INTERRUPT PRIORITY AND DELIVERY 审中-公开
    虚拟中断优先和交付

    公开(公告)号:US20150058510A1

    公开(公告)日:2015-02-26

    申请号:US14538941

    申请日:2014-11-12

    IPC分类号: G06F13/26 G06F9/455

    摘要: Embodiments of processors, methods, and systems for virtualizing interrupt prioritization and delivery are disclosed. In one embodiment, a processor includes instruction hardware and execution hardware. The instruction hardware is to receive a plurality of instructions, including a first instruction to transfer the processor from a root mode to a non-root mode for executing guest software in a virtual machine, wherein the processor is to return to the root mode upon the detection of any of a plurality of virtual machine exit events. The execution hardware is to execute the first instruction, execution of the first instruction to include determining a first virtual processor-priority value and storing the first virtual processor-priority value in a virtual copy of a processor-priority field, where the virtual copy of the processor-priority field is a virtual resource corresponding to a physical resource associated with an interrupt controller.

    摘要翻译: 公开了用于虚拟化中断优先级和传送的处理器,方法和系统的实施例。 在一个实施例中,处理器包括指令硬件和执行硬件。 指令硬件是接收多个指令,包括将处理器从根模式传送到非根模式的第一指令,用于在虚拟机中执行客户软件,其中处理器将根据该模式返回到根模式 检测多个虚拟机退出事件中的任何一个。 执行硬件是执行第一指令,执行第一指令以包括确定第一虚拟处理器优先级值并将第一虚拟处理器优先级值存储在处理器优先级字段的虚拟副本中,其中虚拟副本 处理器优先级字段是对应于与中断控制器相关联的物理资源的虚拟资源。