Method and apparatus for scalable integrity attestation in virtualization environments
    2.
    发明授权
    Method and apparatus for scalable integrity attestation in virtualization environments 失效
    在虚拟化环境中可扩展完整性认证的方法和设备

    公开(公告)号:US08615788B2

    公开(公告)日:2013-12-24

    申请号:US12539912

    申请日:2009-08-12

    摘要: A computer implemented method for logging extensions to platform configuration registers inside a trusted platform module instance is provided. A request to extend the current state of at least one of a plurality of platform configuration register is received. At least one platform configuration register within the trusted platform module instance is extended. The extension of the at least one platform configuration register is logged inside the trusted platform module instance as a logged entry by storing at least a tuple of platform configuration register indexes and hash values used for extending the platform configuration register. Information about new entries in the consolidated logs can be retrieved by polling or by subscribing to events that are automatically generated. A report of an extend operation and its logged hash value is sent to subscribers interested in receiving notifications of extend operations on a set of PCR registers.

    摘要翻译: 提供了一种用于在可信平台模块实例内记录扩展到平台配置寄存器的计算机实现的方法。 接收到扩展多个平台配置寄存器中的至少一个的当前状态的请求。 可信平台模块实例中至少有一个平台配置寄存器被扩展。 至少一个平台配置寄存器的扩展通过存储用于扩展平台配置寄存器的平台配置寄存器索引和散列值的至少一个元组来记录在可信平台模块实例内作为记录条目。 可以通过轮询或订阅自动生成的事件来检索关于合并日志中的新条目的信息。 扩展操作的报告及其记录的哈希值被发送给有兴趣接收一组PCR寄存器的扩展操作通知的用户。

    Migrating a virtual TPM instance and preserving uniqueness and completeness of the instance
    4.
    发明授权
    Migrating a virtual TPM instance and preserving uniqueness and completeness of the instance 有权
    迁移虚拟TPM实例并保留实例的唯一性和完整性

    公开(公告)号:US08356347B2

    公开(公告)日:2013-01-15

    申请号:US13189418

    申请日:2011-07-22

    IPC分类号: G06F21/00

    摘要: A migration scheme for virtualized Trusted Platform Modules is presented. The procedure is capable of securely migrating an instance of a virtual Trusted Platform Module from one physical platform to another. A virtual Trusted Platform Module instance's state is downloaded from a source virtual Trusted Platform Module and all its state information is encrypted using a hybrid of public and symmetric key cryptography. The encrypted state is transferred to the target physical platform, decrypted and the state of the virtual Trusted Platform Module instance is rebuilt.

    摘要翻译: 介绍了虚拟化可信平台模块的迁移方案。 该过程能够将虚拟可信平台模块的实例从一个物理平台安全迁移到另一个物理平台。 虚拟可信平台模块实例的状态从源虚拟可信平台模块下载,其所有状态信息都使用公共和对称密钥密码术的混合进行加密。 将加密状态传送到目标物理平台,进行解密,重建虚拟可信平台模块实例的状态。

    Circuit for separating or combining high frequency power
    6.
    发明授权
    Circuit for separating or combining high frequency power 有权
    用于分离或组合高频电源的电路

    公开(公告)号:US08120444B2

    公开(公告)日:2012-02-21

    申请号:US12516726

    申请日:2007-10-31

    IPC分类号: H01P5/20 H01P5/12

    CPC分类号: H01P5/12

    摘要: An improved component for the separation or combination of high frequency outputs includes a coaxial input port located at the front end of the outer conductor. At the opposite end of the outer conductor, a head is located with at least two, and preferably three or four, single ports which cover the outer conductor connections. The head with the single ports is built as a single part to avoid any mechanical connection junctions. The head with the single ports which form integral outer conductor connectors consists of a forged part or a cast part.

    摘要翻译: 用于分离或组合高频输出的改进组件包括位于外导体前端的同轴输入端口。 在外部导体的相对端,头部具有覆盖外部导体连接的至少两个,优选三个或四个单个端口。 具有单个端口的头部构建为单个部件,以避免任何机械连接接头。 具有形成一体的外部导体连接器的单个端口的头部由锻造部件或铸造部件组成。

    Method and apparatus for migrating a virtual TPM instance and preserving uniqueness and completeness of the instance
    7.
    发明授权
    Method and apparatus for migrating a virtual TPM instance and preserving uniqueness and completeness of the instance 有权
    用于迁移虚拟TPM实例并保留实例的唯一性和完整性的方法和设备

    公开(公告)号:US08020204B2

    公开(公告)日:2011-09-13

    申请号:US12114133

    申请日:2008-05-02

    IPC分类号: G06F21/00 H04L9/32

    摘要: A migration scheme for virtualized Trusted Platform Modules is presented. The procedure is capable of securely migrating an instance of a virtual Trusted Platform Module from one physical platform to another. A virtual Trusted Platform Module instance's state is downloaded from a source virtual Trusted Platform Module and all its state information is encrypted using a hybrid of public and symmetric key cryptography. The encrypted state is transferred to the target physical platform, decrypted and the state of the virtual Trusted Platform Module instance is rebuilt.

    摘要翻译: 介绍了虚拟化可信平台模块的迁移方案。 该过程能够将虚拟可信平台模块的实例从一个物理平台安全迁移到另一个物理平台。 虚拟可信平台模块实例的状态从源虚拟可信平台模块下载,其所有状态信息都使用公共和对称密钥密码术的混合进行加密。 将加密状态传送到目标物理平台,进行解密,重建虚拟可信平台模块实例的状态。

    Architecture for supporting attestation of a virtual machine in a single step
    8.
    发明授权
    Architecture for supporting attestation of a virtual machine in a single step 有权
    用于在一个步骤中支持验证虚拟机的体系结构

    公开(公告)号:US07840801B2

    公开(公告)日:2010-11-23

    申请号:US11624911

    申请日:2007-01-19

    摘要: The presented method allows a virtual TRUSTED PLATFORM MODULE (TPM) instance to map the Platform Configuration Registers (PCR) register state of a parent virtual TPM instance into its own register space and export the state of those registers to applications inside the virtual machine associated with the virtual TPM instance. Through the mapping of PCR registers, the procedure of attesting to the overall state of a virtual machine can be accelerated, since the state of all measurements relevant to the trustworthiness of a virtual machine are all visible in the combined view of mapped and non-mapped PCR registers. Registers that are mapped into the register space of a virtual TPM instance reflect the state of trustworthiness of those virtual machines that were involved in the creation of the virtual machine that is being challenged.

    摘要翻译: 所提出的方法允许虚拟TRUSTED PLATFORM MODULE(TPM)实例将父虚拟TPM实例的平台配置寄存器(PCR)寄存器状态映射到其自己的寄存器空间中,并将这些寄存器的状态导出到与虚拟机相关联的虚拟机内的应用 虚拟TPM实例。 通过PCR寄存器的映射,可以加速验证虚拟机整体状态的过程,因为与映射和未映射的组合视图中虚拟机的可信赖性相关的所有测量的状态都是可见的 PCR寄存器。 映射到虚拟TPM实例的寄存器空间的寄存器反映了参与创建正在受到挑战的虚拟机的虚拟机的可信赖状态。