CN109643352B - 跨安全引导更新保留受保护机密 - Google Patents
跨安全引导更新保留受保护机密 Download PDFInfo
- Publication number
- CN109643352B CN109643352B CN201780053248.6A CN201780053248A CN109643352B CN 109643352 B CN109643352 B CN 109643352B CN 201780053248 A CN201780053248 A CN 201780053248A CN 109643352 B CN109643352 B CN 109643352B
- Authority
- CN
- China
- Prior art keywords
- condition
- blobs
- secret
- conditions
- sealed
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/575—Secure boot
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/085—Secret sharing or secret splitting, e.g. threshold schemes
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/14—Error detection or correction of the data by redundancy in operations
- G06F11/1402—Saving, restoring, recovering or retrying
- G06F11/1415—Saving, restoring, recovering or retrying at system level
- G06F11/1417—Boot up procedures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/14—Error detection or correction of the data by redundancy in operations
- G06F11/1402—Saving, restoring, recovering or retrying
- G06F11/1415—Saving, restoring, recovering or retrying at system level
- G06F11/1433—Saving, restoring, recovering or retrying at system level during software upgrading
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/572—Secure firmware programming, e.g. of basic input output system [BIOS]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/12—Details relating to cryptographic hardware or logic circuitry
- H04L2209/127—Trusted platform modules [TPM]
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Quality & Reliability (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
- Stored Programmes (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US15/253,521 US10177910B2 (en) | 2016-08-31 | 2016-08-31 | Preserving protected secrets across a secure boot update |
| US15/253,521 | 2016-08-31 | ||
| PCT/US2017/048517 WO2018044696A1 (en) | 2016-08-31 | 2017-08-25 | Preserving protected secrets across a secure boot update |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN109643352A CN109643352A (zh) | 2019-04-16 |
| CN109643352B true CN109643352B (zh) | 2023-07-18 |
Family
ID=59791182
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201780053248.6A Active CN109643352B (zh) | 2016-08-31 | 2017-08-25 | 跨安全引导更新保留受保护机密 |
Country Status (19)
| Country | Link |
|---|---|
| US (1) | US10177910B2 (enExample) |
| EP (1) | EP3507737B1 (enExample) |
| JP (1) | JP6994022B2 (enExample) |
| KR (1) | KR102386111B1 (enExample) |
| CN (1) | CN109643352B (enExample) |
| AU (1) | AU2017318962B2 (enExample) |
| BR (1) | BR112019000763A8 (enExample) |
| CA (1) | CA3030983A1 (enExample) |
| CL (1) | CL2019000507A1 (enExample) |
| CO (1) | CO2019001414A2 (enExample) |
| IL (1) | IL264706B (enExample) |
| MX (1) | MX2019002063A (enExample) |
| MY (1) | MY202112A (enExample) |
| NZ (1) | NZ749830A (enExample) |
| PH (1) | PH12019550006A1 (enExample) |
| RU (1) | RU2748392C2 (enExample) |
| SG (1) | SG11201901127YA (enExample) |
| WO (1) | WO2018044696A1 (enExample) |
| ZA (1) | ZA201900424B (enExample) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP7367471B2 (ja) * | 2019-11-07 | 2023-10-24 | 株式会社リコー | 情報処理装置、ファイル保証方法、及びファイル保証プログラム |
| KR20220154879A (ko) * | 2021-05-14 | 2022-11-22 | 현대자동차주식회사 | 차량 제어 장치 및 방법 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1716199A (zh) * | 2004-06-30 | 2006-01-04 | 微软公司 | 使用状态证实的受保护操作系统引导的系统和方法 |
| US8190916B1 (en) * | 2006-07-27 | 2012-05-29 | Hewlett-Packard Development Company, L.P. | Methods and systems for modifying an integrity measurement based on user authentication |
| CN102983886A (zh) * | 2011-05-16 | 2013-03-20 | 美国博通公司 | 在安全元件的设计中使用主存储器的安全架构 |
| CN103038745A (zh) * | 2010-05-21 | 2013-04-10 | 惠普发展公司,有限责任合伙企业 | 扩展完整性测量 |
Family Cites Families (28)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7058807B2 (en) | 2002-04-15 | 2006-06-06 | Intel Corporation | Validation of inclusion of a platform within a data center |
| US7890771B2 (en) * | 2002-04-17 | 2011-02-15 | Microsoft Corporation | Saving and retrieving data based on public key encryption |
| US7062764B2 (en) * | 2002-06-17 | 2006-06-13 | Microsoft Corporation | System and method for manipulating offline software |
| US20060095505A1 (en) * | 2004-09-30 | 2006-05-04 | Zimmer Vincent J | Providing a trustworthy configuration server |
| US7725703B2 (en) * | 2005-01-07 | 2010-05-25 | Microsoft Corporation | Systems and methods for securely booting a computer with a trusted processing module |
| US7565553B2 (en) | 2005-01-14 | 2009-07-21 | Microsoft Corporation | Systems and methods for controlling access to data on a computer with a secure boot process |
| EP1866825A1 (en) * | 2005-03-22 | 2007-12-19 | Hewlett-Packard Development Company, L.P. | Methods, devices and data structures for trusted data |
| US7809957B2 (en) | 2005-09-29 | 2010-10-05 | Intel Corporation | Trusted platform module for generating sealed data |
| US8631507B2 (en) * | 2006-03-27 | 2014-01-14 | Intel Corporation | Method of using signatures for measurement in a trusted computing environment |
| US8108940B2 (en) | 2006-12-19 | 2012-01-31 | International Business Machines Corporation | Method for protecting data from unauthorised access |
| JP4903071B2 (ja) * | 2007-03-15 | 2012-03-21 | 株式会社リコー | 情報処理装置、ソフトウェア更新方法及び画像処理装置 |
| JP2009169841A (ja) | 2008-01-18 | 2009-07-30 | Panasonic Corp | 情報処理装置および携帯電話装置 |
| WO2010041462A1 (ja) | 2008-10-10 | 2010-04-15 | パナソニック株式会社 | 情報処理装置、情報処理方法、情報処理プログラム及び集積回路 |
| US8495036B2 (en) * | 2008-10-24 | 2013-07-23 | Microsoft Corporation | Blob manipulation in an integrated structured storage system |
| US8266448B2 (en) * | 2008-12-09 | 2012-09-11 | Nvidia Corporation | Apparatus, system, method, and computer program product for generating and securing a program capable of being executed utilizing a processor to decrypt content |
| JP5493951B2 (ja) * | 2009-04-17 | 2014-05-14 | 株式会社リコー | 情報処理装置、正当性検証方法及びプログラム |
| US8588422B2 (en) | 2009-05-28 | 2013-11-19 | Novell, Inc. | Key management to protect encrypted data of an endpoint computing device |
| US8490179B2 (en) * | 2009-10-27 | 2013-07-16 | Hewlett-Packard Development Company, L.P. | Computing platform |
| MY150362A (en) | 2010-11-02 | 2013-12-31 | Mimos Berhad | A system and method for securing data storage |
| US8612766B2 (en) * | 2011-07-05 | 2013-12-17 | Microsoft Corporation | Secure credential unlock using trusted execution environments |
| US8694786B2 (en) * | 2011-10-04 | 2014-04-08 | International Business Machines Corporation | Virtual machine images encryption using trusted computing group sealing |
| CN102650947B (zh) * | 2012-04-01 | 2015-06-24 | 广东欧珀移动通信有限公司 | 一种Android手持设备连续增量的空中升级方法 |
| US20150134965A1 (en) | 2012-05-24 | 2015-05-14 | Telefonaktiebolaget L M Ericsson (Publ) | Enhanced Secure Virtual Machine Provisioning |
| JP5980050B2 (ja) | 2012-08-29 | 2016-08-31 | キヤノン株式会社 | 情報処理装置 |
| US9596085B2 (en) * | 2013-06-13 | 2017-03-14 | Intel Corporation | Secure battery authentication |
| US9652631B2 (en) * | 2014-05-05 | 2017-05-16 | Microsoft Technology Licensing, Llc | Secure transport of encrypted virtual machines with continuous owner access |
| US9264410B2 (en) * | 2014-06-05 | 2016-02-16 | Sony Corporation | Dynamic configuration of trusted executed environment resources |
| US9519787B2 (en) | 2014-11-14 | 2016-12-13 | Microsoft Technology Licensing, Llc | Secure creation of encrypted virtual machines from encrypted templates |
-
2016
- 2016-08-31 US US15/253,521 patent/US10177910B2/en active Active
-
2017
- 2017-08-25 CN CN201780053248.6A patent/CN109643352B/zh active Active
- 2017-08-25 JP JP2019511846A patent/JP6994022B2/ja not_active Expired - Fee Related
- 2017-08-25 MY MYPI2019001024A patent/MY202112A/en unknown
- 2017-08-25 KR KR1020197006214A patent/KR102386111B1/ko not_active Expired - Fee Related
- 2017-08-25 WO PCT/US2017/048517 patent/WO2018044696A1/en not_active Ceased
- 2017-08-25 BR BR112019000763A patent/BR112019000763A8/pt active Search and Examination
- 2017-08-25 SG SG11201901127YA patent/SG11201901127YA/en unknown
- 2017-08-25 EP EP17762008.5A patent/EP3507737B1/en active Active
- 2017-08-25 AU AU2017318962A patent/AU2017318962B2/en not_active Ceased
- 2017-08-25 RU RU2019105575A patent/RU2748392C2/ru active
- 2017-08-25 MX MX2019002063A patent/MX2019002063A/es unknown
- 2017-08-25 CA CA3030983A patent/CA3030983A1/en active Pending
- 2017-08-25 NZ NZ749830A patent/NZ749830A/en not_active IP Right Cessation
-
2019
- 2019-01-08 PH PH12019550006A patent/PH12019550006A1/en unknown
- 2019-01-21 ZA ZA2019/00424A patent/ZA201900424B/en unknown
- 2019-02-07 IL IL264706A patent/IL264706B/en unknown
- 2019-02-18 CO CONC2019/0001414A patent/CO2019001414A2/es unknown
- 2019-02-26 CL CL2019000507A patent/CL2019000507A1/es unknown
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1716199A (zh) * | 2004-06-30 | 2006-01-04 | 微软公司 | 使用状态证实的受保护操作系统引导的系统和方法 |
| US8190916B1 (en) * | 2006-07-27 | 2012-05-29 | Hewlett-Packard Development Company, L.P. | Methods and systems for modifying an integrity measurement based on user authentication |
| CN103038745A (zh) * | 2010-05-21 | 2013-04-10 | 惠普发展公司,有限责任合伙企业 | 扩展完整性测量 |
| CN102983886A (zh) * | 2011-05-16 | 2013-03-20 | 美国博通公司 | 在安全元件的设计中使用主存储器的安全架构 |
Also Published As
| Publication number | Publication date |
|---|---|
| CL2019000507A1 (es) | 2019-07-05 |
| JP6994022B2 (ja) | 2022-01-14 |
| WO2018044696A1 (en) | 2018-03-08 |
| CA3030983A1 (en) | 2018-03-08 |
| BR112019000763A8 (pt) | 2023-01-31 |
| MY202112A (en) | 2024-04-04 |
| PH12019550006A1 (en) | 2020-01-20 |
| EP3507737A1 (en) | 2019-07-10 |
| KR102386111B1 (ko) | 2022-04-12 |
| IL264706B (en) | 2021-12-01 |
| ZA201900424B (en) | 2020-05-27 |
| CN109643352A (zh) | 2019-04-16 |
| US10177910B2 (en) | 2019-01-08 |
| BR112019000763A2 (pt) | 2019-04-24 |
| MX2019002063A (es) | 2019-06-06 |
| KR20190042018A (ko) | 2019-04-23 |
| JP2019532402A (ja) | 2019-11-07 |
| RU2748392C2 (ru) | 2021-05-25 |
| RU2019105575A3 (enExample) | 2020-11-02 |
| RU2019105575A (ru) | 2020-08-27 |
| CO2019001414A2 (es) | 2019-02-28 |
| AU2017318962B2 (en) | 2021-10-28 |
| NZ749830A (en) | 2022-09-30 |
| EP3507737B1 (en) | 2021-06-02 |
| SG11201901127YA (en) | 2019-03-28 |
| US20180062833A1 (en) | 2018-03-01 |
| AU2017318962A1 (en) | 2019-01-24 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10409978B2 (en) | Hypervisor and virtual machine protection | |
| US10419216B2 (en) | Keying infrastructure | |
| CN108140093B (zh) | 使用用于设备的硬件信任根来迁移秘密 | |
| US8590040B2 (en) | Runtime platform firmware verification | |
| US9058504B1 (en) | Anti-malware digital-signature verification | |
| US9563774B1 (en) | Apparatus and method for securely logging boot-tampering actions | |
| KR20030082485A (ko) | 대칭 키 암호화에 기초한 데이터의 저장 및 검색 | |
| TW201500960A (zh) | 在配有適用統一可延伸韌體介面(uefi)之韌體之計算裝置中的安全性變數變化檢測技術 | |
| KR20030082484A (ko) | 공개 키 암호화에 기초한 데이터의 저장 및 검색 | |
| US9385869B1 (en) | Systems and methods for trusting digitally signed files in the absence of verifiable signature conditions | |
| US12387011B2 (en) | Secured computer memory | |
| US9893882B1 (en) | Apparatus, system, and method for detecting device tampering | |
| KR102256249B1 (ko) | 통합 보안 SoC를 이용한 IoT 디바이스의 안전한 펌웨어 업데이트 방법 | |
| CN109643352B (zh) | 跨安全引导更新保留受保护机密 | |
| US12413407B2 (en) | Ciphers to protect keystrokes | |
| TWI841919B (zh) | 在一開蓋竄改事件中使一安全啟動失敗的電腦系統 | |
| HK40006241A (en) | Preserving protected secrets across a secure boot update | |
| HK40006241B (en) | Preserving protected secrets across a secure boot update | |
| US12602234B1 (en) | Staged measured boot sequence of a computer |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PB01 | Publication | ||
| PB01 | Publication | ||
| SE01 | Entry into force of request for substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| REG | Reference to a national code |
Ref country code: HK Ref legal event code: DE Ref document number: 40006241 Country of ref document: HK |
|
| GR01 | Patent grant | ||
| GR01 | Patent grant |