Method and device for speeding up key use in key management software with tree structure
    1.
    发明授权
    Method and device for speeding up key use in key management software with tree structure 有权
    用于树结构的密钥管理软件中加密密钥使用的方法和装置

    公开(公告)号:US08223972B2

    公开(公告)日:2012-07-17

    申请号:US12146255

    申请日:2008-06-25

    IPC分类号: H04L9/00

    CPC分类号: H04L9/0836 H04L9/088

    摘要: In the key management software having a key database with a tree structure, a high-speed data encryption/decryption process is achieved by changing the tree structure without reducing the security strength when deleting or adding a key from/to the tree structure. The key management software having the key database with the tree structure, when deleting or adding a key from/to the tree structure, refers to the encryption strength comparison table and the process time comparison table to change the tree structure without reducing the security strength. This reduces the number of times an encrypted key is loaded onto the encryption/decryption processing device during the data encryption/decryption process, thus achieving a high-speed data encryption/decryption.

    摘要翻译: 在具有树结构的密钥数据库的密钥管理软件中,通过在从树结构中删除或添加密钥时改变树结构而不降低安全强度来实现高速数据加密/解密处理。 具有树结构的密钥数据库的密钥管理软件在从树结构中删除或添加密钥时,参考加密强度比较表和处理时间比较表来改变树结构而不降低安全强度。 这减少了在数据加密/解密处理期间将加密密钥加载到加密/解密处理设备上的次数,从而实现高速数据加密/解密。

    PROGRAM EXECUTION APPARATUS, CONTROL METHOD, CONTROL PROGRAM, AND INTEGRATED CIRCUIT
    2.
    发明申请
    PROGRAM EXECUTION APPARATUS, CONTROL METHOD, CONTROL PROGRAM, AND INTEGRATED CIRCUIT 有权
    程序执行装置,控制方法,控制程序和集成电路

    公开(公告)号:US20100174919A1

    公开(公告)日:2010-07-08

    申请号:US12652256

    申请日:2010-01-05

    IPC分类号: G06F21/00

    摘要: Information processing apparatus 100 ensures confidentiality of encryption and reduces overhead associated with processing not directly related to the encryption. The information processing apparatus 100 includes: application program A158 that includes an instruction for encryption which uses a key; tampering detection unit 135x that detects tampering of the program; CPU 141 that operates according to instructions and outputs a direction for encryption upon detecting the instruction for encryption; data encryption/decryption function unit 160 that controls switching to the protective mode according to the direction; and protected data operation unit 155 that stores a key in correspondence with the program, outputs the key in the protective mode, and controls switching to the normal mode, and the data encryption/decryption function unit 160 executes the encryption in the normal mode using the received key.

    摘要翻译: 信息处理装置100确保加密的机密性,并减少与加密无直接关系的处理相关的开销。 信息处理装置100包括:应用程序A158,其包括使用密钥的用于加密的指令; 检测程序的篡改的篡改检测单元135x; CPU141,根据指令进行操作,并在检测到加密指令时输出加密方向; 数据加密/解密功能单元160,其根据方向控制切换到保护模式; 和保存数据操作单元155,其存储与节目对应的密钥,将密钥输出为保护模式,并控制切换到正常模式,数据加密/解密功能单元160使用 收到钥匙

    DATA PROCESSING DEVICE, DATA PROCESSING METHOD, DATA PROCESSING PROGRAM, RECORDING MEDIUM, AND INTEGRATED CIRCUIT
    3.
    发明申请
    DATA PROCESSING DEVICE, DATA PROCESSING METHOD, DATA PROCESSING PROGRAM, RECORDING MEDIUM, AND INTEGRATED CIRCUIT 有权
    数据处理设备,数据处理方法,数据处理程序,记录介质和集成电路

    公开(公告)号:US20100229168A1

    公开(公告)日:2010-09-09

    申请号:US12377320

    申请日:2008-06-04

    IPC分类号: G06F9/455 G06F3/00

    摘要: When notifying virtual machines of a change to shared data, it is impossible to realize power saving for the apparatus if always notifying a virtual machine in the power-saving state.The present invention is equipped with an inter-VM notification management unit 1242, a resuming judgment unit 1244 and a scheduled interruption time acquisition unit 1245, and when it is necessary to notify a virtual machine in the power-saving state, the resuming judgment unit 1244 judges whether to cause the virtual machine to return from the power saving state, based on the time until the interruption acquired by the scheduled interruption time acquisition unit 1245. With this structure, the present invention prevents unnecessary transitions between the states, and realizes the power saving for the apparatus.

    摘要翻译: 通知虚拟机对共享数据进行更改时,如果总是通知虚拟机处于省电状态,则不可能实现设备的省电。 本发明装备有VM间通知管理单元1242,恢复判断单元1244和调度中断时间获取单元1245,并且当需要在省电状态下通知虚拟机时,恢复判断单元 1244根据直到调度中断时间获取单元1245获取的中断的时间来判断是否使虚拟机从省电状态返回。利用这种结构,本发明防止了状态之间的不必要的转换,并且实现了 为设备省电。

    Program execution apparatus, control method, control program, and integrated circuit
    4.
    发明授权
    Program execution apparatus, control method, control program, and integrated circuit 有权
    程序执行装置,控制方法,控制程序和集成电路

    公开(公告)号:US08555089B2

    公开(公告)日:2013-10-08

    申请号:US12652256

    申请日:2010-01-05

    IPC分类号: G06F11/00

    摘要: Information processing apparatus (100) ensures confidentiality of encryption and reduces overhead associated with processing not directly related to the encryption. The information processing apparatus (100) includes: application program (A158) that includes an instruction for encryption which uses a key; tampering detection unit (135x) that detects tampering of the program; CPU (141) that operates according to instructions and outputs a direction for encryption upon detecting the instruction for encryption; data encryption/decryption function unit (160) that controls switching to the protective mode according to the direction; and protected data operation unit (155) that stores a key in correspondence with the program, outputs the key in the protective mode, and controls switching to the normal mode, and the data encryption/decryption function unit (160) executes the encryption in the normal mode using the received key.

    摘要翻译: 信息处理装置(100)确保加密的机密性,并减少与加密无直接关系的处理相关的开销。 信息处理装置(100)包括:应用程序(A158),其包括使用密钥的用于加密的指令; 篡改检测单元(135x),用于检测程序的篡改; CPU(141),其根据指令进行操作,并且在检测到加密指令时输出加密方向; 数据加密/解密功能单元(160),其根据所述方向控制切换到所述保护模式; 和存储与程序对应的密钥的保护数据操作单元(155),将该密钥输出为保护模式,并控制切换到正常模式,并且数据加密/解密功能单元(160)执行加密 正常模式使用接收的键。

    INFORMATION PROCESSOR AND METHOD FOR CONTROLLING THE SAME
    6.
    发明申请
    INFORMATION PROCESSOR AND METHOD FOR CONTROLLING THE SAME 有权
    信息处理器及其控制方法

    公开(公告)号:US20130212575A1

    公开(公告)日:2013-08-15

    申请号:US12918918

    申请日:2009-02-09

    IPC分类号: G06F9/455

    摘要: It is an object of the present invention to provide an information processing device that verifies the authorization of an application that has issued an access request to access a device. For the present invention to fulfill the above object, when an application 102 on a universal OS issues a processing request to a secure device driver 105, a secure VMM 100 and an application identification unit 106 on a management dedicated OS 104 lock a page table of the application 102 and refer to the page table to generate a hash value. The application is determined to be authorized or unauthorized by comparing the generated hash value with a reference hash value.

    摘要翻译: 本发明的目的是提供一种信息处理设备,其验证已经发出访问设备的访问请求的应用的授权。 为了实现上述目的,为了实现上述目的,当通用OS上的应用102向安全设备驱动器105发出处理请求时,管理专用OS 104上的安全VMM100和应用识别单元106锁定 应用程序102并参考页表来生成哈希值。 通过将生成的散列值与引用散列值进行比较,确定应用程序被授权或未授权。

    SECURE BOOT WITH OPTIONAL COMPONENTS METHOD
    8.
    发明申请
    SECURE BOOT WITH OPTIONAL COMPONENTS METHOD 有权
    安全启动与可选组件方法

    公开(公告)号:US20090320110A1

    公开(公告)日:2009-12-24

    申请号:US12484537

    申请日:2009-06-15

    IPC分类号: G06F21/00 H04L9/32

    摘要: A method is executed which is for managing the optional trusted components that are active within a device, such that the device itself controls the availability of trusted components. The device includes: a storing unit which stores a plurality of pieces of software and a plurality of certificates; a receiving unit which receives the certificates; and a selecting unit which selects one of the certificates. The device further includes an executing unit which verifies an enabled one of the plurality of pieces of software using the selected and updated one of the certificates.

    摘要翻译: 执行用于管理在设备内活动的可选可信组件的方法,使得设备本身控制可信组件的可用性。 该装置包括:存储单元,存储多个软件和多个证书; 接收证书的接收单元; 以及选择单元,其选择证书之一。 该设备还包括执行单元,其使用所选择和更新的一个证书来验证多个软件中启用的一个软件。

    Starts up of modules of a second module group only when modules of a first group have been started up legitimately
    10.
    发明授权
    Starts up of modules of a second module group only when modules of a first group have been started up legitimately 有权
    仅当第一组的模块合法启动时,才启动第二个模块组的模块

    公开(公告)号:US08510544B2

    公开(公告)日:2013-08-13

    申请号:US12991516

    申请日:2009-05-25

    IPC分类号: G06F9/00 G06F9/24 H04L29/06

    摘要: The present invention provides an information processing apparatus that is capable of continuously performing secure boot between module groups in the case where software of a terminal device consists of module groups provided by a plurality of providers, while keeping independence between the providers. The information processing apparatus is provided with a linkage certificate that contains a first configuration comparison value, which indicates a cumulative hash value of the first module group to be started up by secure boot, and a module measurement value, which indicates a hash value of the first module of the second module group to be started up by secure boot. After the secure boot of the first module group, it is verified that the first module group has been started up by comparison with the first configuration comparison value.

    摘要翻译: 本发明提供一种信息处理装置,其能够在终端装置的软件由多个提供者提供的模块组成的情况下连续地执行模块组之间的安全引导,同时保持提供者之间的独立性。 该信息处理装置具有包含第一配置比较值的连接证书,该第一配置比较值指示通过安全引导来启动的第一模块组的累积散列值,以及指示所述第一配置比较值的散列值 第二个模块组的第一个模块通过安全启动启动。 在第一模块组的安全引导之后,通过与第一配置比较值进行比较来验证第一模块组是否被启动。