-
公开(公告)号:US20200026857A1
公开(公告)日:2020-01-23
申请号:US16042338
申请日:2018-07-23
Applicant: VMware, Inc.
Inventor: Daniel MULLER , Samyuktha SUBRAMANIAN , Mukund GUNTI
Abstract: An example method of authenticating software executing in a computer system includes: receiving, from the computer system over a network at a server computer, a trusted platform module (TPM) quote, an event log, and a metadata database, the TPM quote provided by a TPM in the computer system, the event log including first checksums for the software executing in the computer system, and the metadata database including second checksums of binary files stored in packages from which the software is installed; establishing a root of trust in the computer system at the server computer based on the TPM quote and the event log; and determining, at the server computer in response to establishing the root of trust, integrity of the software executing in the computer system by comparing the first checksums with the second checksums.
-
公开(公告)号:US20200026858A1
公开(公告)日:2020-01-23
申请号:US16042373
申请日:2018-07-23
Applicant: VMware, Inc.
Inventor: Samyuktha SUBRAMANIAN , Daniel MULLER , Mukund GUNTI , Adrian DRZEWIECKI
Abstract: An example method of authenticating software executing in a computer system includes verifying first software executing on the computer system, the software including a hypervisor, verifying second software executing in a virtual machine (VM) managed by the hypervisor, generating a binding key having public and private portions, signing an object to identifies the VM using the private portion of the binding key, and verifying a signature of the object using a public portion of the binding key.
-