会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • Method and system for verifying binding of an initial trusted device to a secured processing system
    • 用于验证初始可信设备与安全处理系统的绑定的方法和系统
    • US07143287B2
    • 2006-11-28
    • US10970461
    • 2004-10-21
    • Steven A. BadeDavid Carroll Challener
    • Steven A. BadeDavid Carroll Challener
    • G06F17/30
    • G06F21/57
    • A method and system for verifying binding of an initial trusted device to a secured processing system binds an initial device or replacement when no binding information is available from another device in the system. A platform credential is issued only when a valid binding is verified, by sending a proof of binding to a credential provider, such as the manufacturer. The method secures against security breaches that can occur when a device is removed from the system during the binding process. The binding information is generated in the device upon installation and includes system identification information so that at each initialization, upon return of binding information from the system to the device, the device can ensure that it is installed in the proper system and abort operation if the system does not match.
    • 用于验证初始可信设备与安全处理系统的绑定的方法和系统在没有绑定信息可用于系统中的另一设备时绑定初始设备或替换。 只有当有效的绑定被验证时,才通过发送绑定到证书提供商(如制造商)的证明来颁发平台凭据。 该方法可以防止在绑定过程中从系统中删除设备时可能发生的安全漏洞。 捆绑信息在安装时在设备中生成,并且包括系统识别信息,使得在每次初始化时,从系统返回到设备的绑定信息,设备可以确保其被安装在适当的系统中并且如果 系统不匹配。
    • 5. 发明授权
    • Method and system for bootstrapping a trusted server having redundant trusted platform modules
    • 用于引导具有冗余可信平台模块的可信服务器的方法和系统
    • US08055912B2
    • 2011-11-08
    • US12621524
    • 2009-11-19
    • Steven A. BadeLinda Nancy BetzAndrew Gregory KegelDavid R. SaffordLeendert Peter Van Doorn
    • Steven A. BadeLinda Nancy BetzAndrew Gregory KegelDavid R. SaffordLeendert Peter Van Doorn
    • G06F11/30
    • G06F21/575
    • Multiple trusted platform modules within a data processing system are used in a redundant manner that provides a reliable mechanism for securely storing secret data at rest that is used to bootstrap a system trusted platform module. A hypervisor requests each trusted platform module to encrypt a copy of the secret data, thereby generating multiple versions of encrypted secret data values, which are then stored within a non-volatile memory within the trusted platform. At some later point in time, the encrypted secret data values are retrieved, decrypted by the trusted platform module that performed the previous encryption, and then compared to each other. If any of the decrypted values do not match a quorum of values from the comparison operation, then a corresponding trusted platform module for a non-matching decrypted value is designated as defective because it has not been able to correctly decrypt a value that it previously encrypted.
    • 以冗余的方式使用数据处理系统内的多个可信任的平台模块,其提供用于安全地存储用于引导系统可信平台模块的休息处的秘密数据的可靠机制。 管理程序请求每个可信平台模块加密秘密数据的副本,从而生成加密的秘密数据值的多个版本,然后存储在可信平台内的非易失性存储器中。 在稍后的时间点,加密的秘密数据值由执行先前加密的可信任平台模块进行解密,然后进行比较。 如果解密值中的任何一个与比较操作中的值的数量不匹配,则用于非匹配解密值的相应的可信平台模块被指定为有缺陷的,因为它不能正确解密之前加密的值 。