System and method for limiting exposure of hardware failure information for a secured execution environment
    1.
    发明授权
    System and method for limiting exposure of hardware failure information for a secured execution environment 有权
    用于限制安全执行环境的硬件故障信息暴露的系统和方法

    公开(公告)号:US07934076B2

    公开(公告)日:2011-04-26

    申请号:US10956322

    申请日:2004-09-30

    IPC分类号: G06F9/00

    CPC分类号: G06F21/74 G06F2221/2101

    摘要: A method and apparatus for limiting the exposure of hardware failure information is described. In one embodiment, an error reporting system of a processor may log various status and error address data into registers that retain their contents through a warm reset event. But the error reporting system of the processor may then determine whether the processor is operating in a trusted or secure mode. If not, then the processor's architectural state variables may also be logged into registers. But if the processor is operating in a trusted or secure mode, then the logging of the architectural state variables may be inhibited, or flagged as invalid.

    摘要翻译: 描述了用于限制硬件故障信息的暴露的方法和装置。 在一个实施例中,处理器的错误报告系统可以将各种状态和错误地址数据记录到通过热复位事件保留其内容的寄存器中。 但是处理器的错误报告系统然后可以确定处理器是否以可信任或安全模式操作。 如果没有,则处理器的体系结构状态变量也可能被记录到寄存器中。 但是,如果处理器以可信任或安全模式运行,则可能会禁止对架构状态变量的日志记录或标记为无效。

    Methods and apparatuses for recovering usage of trusted platform module
    9.
    发明授权
    Methods and apparatuses for recovering usage of trusted platform module 有权
    恢复信任平台模块使用的方法和装置

    公开(公告)号:US08812828B2

    公开(公告)日:2014-08-19

    申请号:US12947218

    申请日:2010-11-16

    摘要: Methods and systems to perform platform security in conjunction with hardware-base root of trust logic are presented. In one embodiment, a method includes determining whether a status from an authenticated code module is indicative of an error or not. The method further includes determining whether the hardware-based root of trust logic is enabled based on content in a non-volatile memory location. If the hardware-based root of trust is enabled and the status is indicative of an error, the method further includes writing to the non-volatile memory location to disable hardware-based root of trust logic during a next boot sequence. In one embodiment, a platform initializes and uses the trusted platform module in conjunction with the hardware-based root of trust logic or with a platform-based root of trust logic.

    摘要翻译: 提出了结合信任逻辑的硬件根本来执行平台安全性的方法和系统。 在一个实施例中,一种方法包括确定来自认证代码模块的状态是否指示错误。 该方法还包括基于非易失性存储器位置中的内容来确定信任逻辑的基于硬件的根是否被启用。 如果启用了基于硬件的信任根,并且状态指示了错误,则该方法还包括在下一个引导序列期间写入非易失性存储器位置以禁用基于硬件的信任逻辑根。 在一个实施例中,平台与基于硬件的信任逻辑根或基于平台的信任逻辑逻辑基础一起初始化并使用可信平台模块。

    System and method for trusted early boot flow
    10.
    发明授权
    System and method for trusted early boot flow 失效
    可信早期启动流的系统和方法

    公开(公告)号:US07752428B2

    公开(公告)日:2010-07-06

    申请号:US11096832

    申请日:2005-03-31

    IPC分类号: G06F9/00

    CPC分类号: G06F21/575 H04L9/3234

    摘要: In some embodiments, the invention involves extending trusted computing environments to the boot firmware. In at least one embodiment, the present invention is intended to enable the trusted environment to be extended forward to the pre-boot environment in addition to post-OS load environment. Embodiments of the present invention enable the trusted environment to extend to the firmware at power-on. The firmware is integrated within the secure perimeter which was previously only available to the OS. In other words, the BIOS is made to be a trusted entity, as well as the OS. Extensible firmware interface (EFI) modules are signed with a public key. The processor has an embedded private key. EFI modules are verified using the keys to ensure a trusted environment from boot to OS launch. Other embodiments are described and claimed.

    摘要翻译: 在一些实施例中,本发明涉及将可信计算环境扩展到引导固件。 在至少一个实施例中,本发明旨在使可信环境除了后OS负载环境之外还能够向前扩展到预引导环境。 本发明的实施例使可信环境能够在上电时扩展到固件。 固件集成在安全周边内,以前只可用于操作系统。 换句话说,BIOS被做成可靠的实体以及操作系统。 可扩展固件接口(EFI)模块使用公共密钥进行签名。 处理器具有嵌入式私钥。 EFI模块使用密钥进行验证,以确保从引导到操作系统启动的受信任环境。 描述和要求保护其他实施例。