会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 2. 发明公开
    • PRIVILEGED CRYPTOGRAPHIC SERVICES IN A VIRTUALIZED ENVIRONMENT
    • EINER VIRTUALISIERTEN UMGEBUNG特别荣誉
    • EP2949074A4
    • 2016-09-21
    • EP14743982
    • 2014-01-22
    • AMAZON TECH INC
    • ROTH GREGORY BRANCHEKPOTLAPALLY NACHIKETH RAO
    • G06F21/53G06F21/57G06F21/64G06F21/72
    • G06F21/72G06F21/53G06F21/57G06F21/575G06F21/602G06F21/64
    • A privileged cryptographic service is described, such as a service running in system management mode (SMM). The privileged service is operable to store and manage cryptographic keys and/or other security resources in a multitenant remote program execution environment. The privileged service can receive requests to use the cryptographic keys and issue responses to these requests. In addition, the privileged service can measure the hypervisor at runtime (e.g., either periodically or in response to the requests) in an attempt to detect evidence of tampering with the hypervisor. Because the privileged service is operating in system management mode that is more privileged than the hypervisor, the privileged service can be robust against virtual machine escape and other hypervisor attacks.
    • 描述了一种特权密码服务,例如以系统管理模式运行的服务(SMM)。 特权服务可操作以在多租户远程程序执行环境中存储和管理加密密钥和/或其他安全资源。 特权服务可以接收使用加密密钥的请求并发出对这些请求的响应。 此外,特权服务可以在运行时(例如,周期性地或响应于请求)来测量管理程序,以试图检测篡改管理程序的证据。 由于特权服务在比管理程序更具特权的系统管理模式下运行,因此特权服务可以针对虚拟机逃脱和其他管理程序攻击而强大。
    • 4. 发明公开
    • HOST RECOVERY USING A SECURE STORE
    • HOSTWIEDERHERSTELLUNG麻省理工EINEM SICHEREN SPEICHER
    • EP2987107A4
    • 2016-11-16
    • EP14785721
    • 2014-04-11
    • AMAZON TECH INC
    • POTLAPALLY NACHIKETH RAOCHAWLA RACHITVOLKMAN JEREMY RYANMARR MICHAEL DAVID
    • G06F21/57G06F21/44
    • G06F21/575G06F21/44G06F21/57
    • Approaches are described for enabling a host computing device to store credentials and other security information useful for recovering the state of the host computing device in a secure store, such as a trusted platform module (TPM) on the host computing device. When recovering the host computing device in the event of a failure (e.g., power outage, network failure, etc.), the host computing device can obtain the necessary credentials from the secure store and use those credentials to boot various services, restore the state of the host and perform various other functions. In addition, the secure store (e.g., TPM) may provide boot firmware measurement and remote attestation of the host computing devices to other devices on a network, such as when the recovering host needs to communicate with the other devices on the network.
    • 描述了使主机计算设备能够存储用于在诸如主机计算设备上的可信平台模块(TPM)的安全存储器中恢复主机计算设备的状态的凭证和其他安全信息的方法。 在主机计算设备发生故障(例如断电,网络故障等)的情况下恢复时,主机计算设备可以从安全存储中获取必要的凭证,并使用这些凭据来启动各种服务,恢复状态 的主机并执行各种其他功能。 此外,安全存储(例如,TPM)可以提供主机计算设备的引导固件测量和远程认证到网络上的其他设备,例如当恢复的主机需要与网络上的其他设备进行通信时。
    • 5. 发明公开
    • CONFIGURABLE-QUALITY RANDOM DATA SERVICE
    • ZUFALLSDATENDIENST MIT KONFIGURIERBARERQUALITÄT
    • EP2962441A4
    • 2016-10-05
    • EP14756576
    • 2014-02-28
    • AMAZON TECH INC
    • POTLAPALLY NACHIKETH RAOMIKULSKI ANDREW PAULBAILEY JR DONALD LEEFITZGERALD ROBERT ERIC
    • H04L29/06G06F7/58H04L9/08H04L29/08
    • H04L63/12H04L63/062
    • Methods and apparatus for a configurable-quality random data service are disclosed. A method includes implementing programmatic interfaces enabling a determination of respective characteristics of random data to be delivered to one or more clients of a random data service of a provider network. The method includes implementing security protocols for transmission of random data to the clients, including a protocol for transmission of random data to trusted clients at devices within the provider network. The method further includes obtaining, on behalf of a particular client and in accordance with the determined characteristics, random data from one or more servers of the provider network, and initiating a transmission of the random data directed to a destination associated with the particular client.
    • 公开了可配置质量随机数据服务的方法和装置。 一种方法包括实现程序化接口,使得能够确定要提供给提供商网络的随机数据服务的一个或多个客户端的随机数据的相应特性。 该方法包括实现用于向客户端发送随机数据的安全协议,包括用于在提供商网络内的设备处将随机数据传输到可信客户端的协议。 该方法还包括代表特定客户端并根据确定的特征获得来自提供商网络的一个或多个服务器的随机数据,以及发起指向与特定客户端相关联的目的地的随机数据的传输。