JP2012533128A - セキュア仮想マシンを提供するためのシステムおよび方法 - Google Patents
セキュア仮想マシンを提供するためのシステムおよび方法 Download PDFInfo
- Publication number
- JP2012533128A JP2012533128A JP2012520055A JP2012520055A JP2012533128A JP 2012533128 A JP2012533128 A JP 2012533128A JP 2012520055 A JP2012520055 A JP 2012520055A JP 2012520055 A JP2012520055 A JP 2012520055A JP 2012533128 A JP2012533128 A JP 2012533128A
- Authority
- JP
- Japan
- Prior art keywords
- secure
- processor
- virtual machine
- public
- zone manager
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 title claims description 34
- 238000004891 communication Methods 0.000 claims description 19
- 230000006870 function Effects 0.000 claims description 13
- 239000011159 matrix material Substances 0.000 claims description 10
- 230000004044 response Effects 0.000 claims description 3
- 238000010200 validation analysis Methods 0.000 claims description 2
- 230000011664 signaling Effects 0.000 abstract 1
- 230000002093 peripheral effect Effects 0.000 description 11
- 239000003607 modifier Substances 0.000 description 6
- 238000012545 processing Methods 0.000 description 4
- 230000008901 benefit Effects 0.000 description 3
- 238000005516 engineering process Methods 0.000 description 3
- 239000003795 chemical substances by application Substances 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 230000007246 mechanism Effects 0.000 description 2
- 206010016275 Fear Diseases 0.000 description 1
- 230000009471 action Effects 0.000 description 1
- 230000008859 change Effects 0.000 description 1
- 238000006243 chemical reaction Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 230000003993 interaction Effects 0.000 description 1
- 239000000463 material Substances 0.000 description 1
- 230000003449 preventive effect Effects 0.000 description 1
- 238000012360 testing method Methods 0.000 description 1
- 238000013519 translation Methods 0.000 description 1
- 238000012795 verification Methods 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/52—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
- G06F21/53—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/572—Secure firmware programming, e.g. of basic input output system [BIOS]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Stored Programmes (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (15)
- 所有者の要求で作成される複数のセキュア仮想マシンをホストするためのプロセッサであって、
プロセッサの秘密鍵を格納するメモリと、
ゾーンマネージャのインスタンスと関連付けられる第1の公開/秘密鍵のペアを生成するための第1の生成器と、
前記プロセッサの秘密鍵によって前記第1の公開/秘密鍵のペアを証明するための第1の認証エージェントと、
前記所有者から仮想マシンインスタンス化コマンドをセキュアに受信する受信機と、
前記インスタンス化コマンドに応えて作成された、前記複数の仮想マシンのうちの1つの仮想マシンのインスタンスと関連付けられる第2の公開/秘密鍵のペアを生成するための第2の生成器と、
前記第1の公開/秘密鍵のペアによって前記第2の公開/秘密鍵のペアを証明するための第2の認証エージェントと
を含む、プロセッサ。 - 初期ブートプログラムを格納するための、プライベートブートエリア(410)をさらに含む、請求項1に記載のプロセッサ。
- 前記ゾーンマネージャを含むイメージファイルを受信して正当性を確認するための手段をさらに含む、請求項1または2に記載のプロセッサ。
- 前記複数のセキュア仮想マシンによって使用されるメモリをさらに含み、前記メモリへのアクセスが、前記複数のセキュア仮想マシンのセキュア仮想マシン毎に異なる暗号鍵によってセキュリティ保護される、請求項1から3のいずれかに記載のプロセッサ。
- 前記複数のセキュア仮想マシンのデジタルアクセス許可情報を格納するメモリをさらに含む、請求項1から4のいずれかに記載のプロセッサ。
- 所有者の要求でプロセッサ内のセキュア仮想マシンをセットアップするための方法であって、
ゾーンマネージャのイメージを使用して前記プロセッサをブートすることと、
前記プロセッサでゾーンマネージャのセッションと関連する第1の公開/秘密鍵のペアを入手することと、
前記第1の公開/秘密鍵のペアの公開鍵を前記プロセッサで前記プロセッサと関連する秘密鍵を使用して証明することと、
前記ゾーンマネージャでセキュア仮想マシンインスタンス化コマンドを前記所有者から受信することと、
前記ゾーンマネージャと前記ユーザとの間でセキュア通信チャネルを作成することと、
セキュア仮想マシンと関連する第2の公開/秘密鍵のペアを入手することと、
前記第1の公開/秘密鍵のペアの秘密鍵を使用して前記第2の公開/秘密鍵のペアの公開鍵を証明することと
を含む、方法。 - プライベートブートエリアに格納されたプログラムからプロセッサをブートすることをさらに含む、請求項6に記載の方法。
- 前記ゾーンマネージャのイメージを前記プロセッサにダウンロードすることと、前記プロセッサで、前記ゾーンマネージャのイメージの前記ブートすることのための前提条件として、前記ゾーンマネージャのイメージに関するバリデーション値を検証することとをさらに含む、請求項6に記載の方法。
- 前記プロセッサの共有メモリに格納された特定のコンテンツにアクセスするための暗号鍵を、前記セキュア仮想マシンと関連付けることをさらに含む、請求項6に記載の方法。
- 前記セキュア仮想マシンのインスタンス化コマンドが前記ユーザに関する証明書を含む、請求項6に記載の方法。
- 前記セキュア通信チャネルのセキュリティ面が、前記ユーザに関する前記証明書に依存する、請求項10に記載の方法。
- 前記ユーザに関する前記証明書を前記ゾーンマネージャに提供することをさらに含む、請求項10または11に記載の方法。
- 前記セキュア通信チャネルが、公開鍵暗号化技術を用いてセキュリティ保護される、請求項10または11に記載の方法。
- 前記仮想マシンのアクセス許可で機能マトリックスを更新することをさらに含む、請求項6から13のいずれかに記載の方法。
- 前記セキュア仮想マシンにブートプログラムを提供することによって、前記セキュア仮想マシンを準備することと、
前記セキュア仮想マシンを起動することと
をさらに含む、請求項6から14のいずれかに記載の方法。
Applications Claiming Priority (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
EP09165682.7A EP2278514B1 (en) | 2009-07-16 | 2009-07-16 | System and method for providing secure virtual machines |
EP09165682.7 | 2009-07-16 | ||
PCT/EP2010/060341 WO2011006997A1 (en) | 2009-07-16 | 2010-07-16 | System and method for providing secure virtual machines |
Publications (2)
Publication Number | Publication Date |
---|---|
JP2012533128A true JP2012533128A (ja) | 2012-12-20 |
JP5497171B2 JP5497171B2 (ja) | 2014-05-21 |
Family
ID=41198539
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
JP2012520055A Active JP5497171B2 (ja) | 2009-07-16 | 2010-07-16 | セキュア仮想マシンを提供するためのシステムおよび方法 |
Country Status (6)
Country | Link |
---|---|
US (1) | US8856544B2 (ja) |
EP (1) | EP2278514B1 (ja) |
JP (1) | JP5497171B2 (ja) |
KR (1) | KR101318524B1 (ja) |
CN (1) | CN102473213B (ja) |
WO (1) | WO2011006997A1 (ja) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2016511610A (ja) * | 2013-03-15 | 2016-04-14 | インターナショナル・ビジネス・マシーンズ・コーポレーションInternational Business Machines Corporation | マルチテナント・コンピューティング・インフラストラクチャにおける鍵管理の方法、装置、コンピュータ・プログラム製品、およびクラウド・コンピュート・インフラストラクチャ(マルチテナント環境における鍵管理) |
Families Citing this family (75)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US9386021B1 (en) * | 2011-05-25 | 2016-07-05 | Bromium, Inc. | Restricting network access to untrusted virtual machines |
US8996851B2 (en) * | 2010-08-10 | 2015-03-31 | Sandisk Il Ltd. | Host device and method for securely booting the host device with operating system code loaded from a storage device |
US8694777B2 (en) * | 2010-08-13 | 2014-04-08 | International Business Machines Corporation | Securely identifying host systems |
US9818079B2 (en) | 2011-05-21 | 2017-11-14 | Ortho-Clinical Diagnostics, Inc. | System and method of inventory management |
US9178698B1 (en) * | 2011-12-21 | 2015-11-03 | Google Inc. | Dynamic key management |
US9992024B2 (en) * | 2012-01-25 | 2018-06-05 | Fujitsu Limited | Establishing a chain of trust within a virtual machine |
US8938611B1 (en) * | 2012-02-02 | 2015-01-20 | Trend Micro, Inc. | Enterprise cloud security gateway |
US8880882B2 (en) * | 2012-04-04 | 2014-11-04 | Google Inc. | Securely performing programmatic cloud-based data analysis |
TW201349009A (zh) | 2012-04-13 | 2013-12-01 | Ologn Technologies Ag | 用於數位通信之安全區 |
WO2013153437A1 (en) | 2012-04-13 | 2013-10-17 | Ologn Technologies Ag | Apparatuses, methods and systems for computer-based secure transactions |
TW201403375A (zh) | 2012-04-20 | 2014-01-16 | 歐樂岡科技公司 | 用於安全購買之安全區 |
US9385918B2 (en) * | 2012-04-30 | 2016-07-05 | Cisco Technology, Inc. | System and method for secure provisioning of virtualized images in a network environment |
US9210162B2 (en) * | 2012-05-02 | 2015-12-08 | Microsoft Technology Licensing, Llc | Certificate based connection to cloud virtual machine |
US9027102B2 (en) | 2012-05-11 | 2015-05-05 | Sprint Communications Company L.P. | Web server bypass of backend process on near field communications and secure element chips |
US9282898B2 (en) | 2012-06-25 | 2016-03-15 | Sprint Communications Company L.P. | End-to-end trusted communications infrastructure |
US9066230B1 (en) | 2012-06-27 | 2015-06-23 | Sprint Communications Company L.P. | Trusted policy and charging enforcement function |
GB2513826A (en) * | 2012-06-29 | 2014-11-12 | Ibm | Trusted boot of a virtual machine |
US8649770B1 (en) | 2012-07-02 | 2014-02-11 | Sprint Communications Company, L.P. | Extended trusted security zone radio modem |
US8667607B2 (en) | 2012-07-24 | 2014-03-04 | Sprint Communications Company L.P. | Trusted security zone access to peripheral devices |
US9183412B2 (en) * | 2012-08-10 | 2015-11-10 | Sprint Communications Company L.P. | Systems and methods for provisioning and using multiple trusted security zones on an electronic device |
US9015068B1 (en) | 2012-08-25 | 2015-04-21 | Sprint Communications Company L.P. | Framework for real-time brokering of digital content delivery |
US9215180B1 (en) | 2012-08-25 | 2015-12-15 | Sprint Communications Company L.P. | File retrieval in real-time brokering of digital content |
RU2648941C2 (ru) * | 2012-10-12 | 2018-03-28 | Конинклейке Филипс Н.В. | Безопасная обработка данных виртуальной машиной |
US9161227B1 (en) | 2013-02-07 | 2015-10-13 | Sprint Communications Company L.P. | Trusted signaling in long term evolution (LTE) 4G wireless communication |
US9578664B1 (en) | 2013-02-07 | 2017-02-21 | Sprint Communications Company L.P. | Trusted signaling in 3GPP interfaces in a network function virtualization wireless communication system |
US9104840B1 (en) | 2013-03-05 | 2015-08-11 | Sprint Communications Company L.P. | Trusted security zone watermark |
US9613208B1 (en) | 2013-03-13 | 2017-04-04 | Sprint Communications Company L.P. | Trusted security zone enhanced with trusted hardware drivers |
US9049013B2 (en) | 2013-03-14 | 2015-06-02 | Sprint Communications Company L.P. | Trusted security zone containers for the protection and confidentiality of trusted service manager data |
US9374363B1 (en) | 2013-03-15 | 2016-06-21 | Sprint Communications Company L.P. | Restricting access of a portable communication device to confidential data or applications via a remote network based on event triggers generated by the portable communication device |
US9021585B1 (en) | 2013-03-15 | 2015-04-28 | Sprint Communications Company L.P. | JTAG fuse vulnerability determination and protection using a trusted execution environment |
WO2014141202A1 (en) | 2013-03-15 | 2014-09-18 | Ologn Technologies Ag | Systems, methods and apparatuses for securely storing and providing payment information |
US9191388B1 (en) | 2013-03-15 | 2015-11-17 | Sprint Communications Company L.P. | Trusted security zone communication addressing on an electronic device |
US9171243B1 (en) | 2013-04-04 | 2015-10-27 | Sprint Communications Company L.P. | System for managing a digest of biographical information stored in a radio frequency identity chip coupled to a mobile communication device |
US9454723B1 (en) | 2013-04-04 | 2016-09-27 | Sprint Communications Company L.P. | Radio frequency identity (RFID) chip electrically and communicatively coupled to motherboard of mobile communication device |
US9324016B1 (en) | 2013-04-04 | 2016-04-26 | Sprint Communications Company L.P. | Digest of biographical information for an electronic device with static and dynamic portions |
US9838869B1 (en) | 2013-04-10 | 2017-12-05 | Sprint Communications Company L.P. | Delivering digital content to a mobile device via a digital rights clearing house |
US9443088B1 (en) | 2013-04-15 | 2016-09-13 | Sprint Communications Company L.P. | Protection for multimedia files pre-downloaded to a mobile device |
US9069952B1 (en) | 2013-05-20 | 2015-06-30 | Sprint Communications Company L.P. | Method for enabling hardware assisted operating system region for safe execution of untrusted code using trusted transitional memory |
US9560519B1 (en) | 2013-06-06 | 2017-01-31 | Sprint Communications Company L.P. | Mobile communication device profound identity brokering framework |
US9183606B1 (en) | 2013-07-10 | 2015-11-10 | Sprint Communications Company L.P. | Trusted processing location within a graphics processing unit |
US9948640B2 (en) | 2013-08-02 | 2018-04-17 | Ologn Technologies Ag | Secure server on a system with virtual machines |
US9208339B1 (en) | 2013-08-12 | 2015-12-08 | Sprint Communications Company L.P. | Verifying Applications in Virtual Environments Using a Trusted Security Zone |
FR3011654B1 (fr) * | 2013-10-08 | 2016-12-23 | Commissariat Energie Atomique | Procede et dispositif d'authentification et d'execution securisee de programmes |
US9185626B1 (en) | 2013-10-29 | 2015-11-10 | Sprint Communications Company L.P. | Secure peer-to-peer call forking facilitated by trusted 3rd party voice server provisioning |
US9191522B1 (en) | 2013-11-08 | 2015-11-17 | Sprint Communications Company L.P. | Billing varied service based on tier |
US9161325B1 (en) | 2013-11-20 | 2015-10-13 | Sprint Communications Company L.P. | Subscriber identity module virtualization |
US9118655B1 (en) | 2014-01-24 | 2015-08-25 | Sprint Communications Company L.P. | Trusted display and transmission of digital ticket documentation |
US9226145B1 (en) | 2014-03-28 | 2015-12-29 | Sprint Communications Company L.P. | Verification of mobile device integrity during activation |
US9652631B2 (en) * | 2014-05-05 | 2017-05-16 | Microsoft Technology Licensing, Llc | Secure transport of encrypted virtual machines with continuous owner access |
US9230085B1 (en) | 2014-07-29 | 2016-01-05 | Sprint Communications Company L.P. | Network based temporary trust extension to a remote or mobile device enabled via specialized cloud services |
WO2016081867A1 (en) * | 2014-11-20 | 2016-05-26 | Interdigital Patent Holdings, Inc. | Providing security to computing systems |
US9779232B1 (en) | 2015-01-14 | 2017-10-03 | Sprint Communications Company L.P. | Trusted code generation and verification to prevent fraud from maleficent external devices that capture data |
US10068092B2 (en) | 2015-01-21 | 2018-09-04 | Microsoft Technology Licensing, Llc | Upgrading a secure boot policy on a virtual machine |
US9838868B1 (en) | 2015-01-26 | 2017-12-05 | Sprint Communications Company L.P. | Mated universal serial bus (USB) wireless dongles configured with destination addresses |
US9560078B2 (en) * | 2015-02-04 | 2017-01-31 | Intel Corporation | Technologies for scalable security architecture of virtualized networks |
US9473945B1 (en) | 2015-04-07 | 2016-10-18 | Sprint Communications Company L.P. | Infrastructure for secure short message transmission |
US9819679B1 (en) | 2015-09-14 | 2017-11-14 | Sprint Communications Company L.P. | Hardware assisted provenance proof of named data networking associated to device data, addresses, services, and servers |
US10282719B1 (en) | 2015-11-12 | 2019-05-07 | Sprint Communications Company L.P. | Secure and trusted device-based billing and charging process using privilege for network proxy authentication and audit |
US9817992B1 (en) | 2015-11-20 | 2017-11-14 | Sprint Communications Company Lp. | System and method for secure USIM wireless network access |
US10404470B2 (en) * | 2017-01-13 | 2019-09-03 | Microsoft Technology Licensing, Llc | Signature verification of field-programmable gate array programs |
US10499249B1 (en) | 2017-07-11 | 2019-12-03 | Sprint Communications Company L.P. | Data link layer trust signaling in communication network |
US10685106B2 (en) | 2018-03-10 | 2020-06-16 | International Business Machines Corporation | Protecting cognitive code and client data in a public cloud via deployment of data and executables into a stateless secure partition |
US11068607B2 (en) | 2018-03-10 | 2021-07-20 | International Business Machines Corporation | Protecting cognitive code and client data in a public cloud via deployment of data and executables into a secure partition with persistent data |
US10853498B2 (en) * | 2018-09-19 | 2020-12-01 | Dell Products L.P. | Secure boot orchestration device in a virtual desktop infrastructure |
US11165575B2 (en) | 2019-01-02 | 2021-11-02 | Citrix Systems, Inc. | Tracking tainted connection agents |
US11061711B2 (en) | 2019-09-23 | 2021-07-13 | Red Hat, Inc. | Storage deduplication for virtual machines with encrypted storage |
US11656891B2 (en) | 2019-09-27 | 2023-05-23 | Red Hat, Inc. | Copy-on-write for virtual machines with encrypted storage |
US11232030B2 (en) | 2019-09-27 | 2022-01-25 | Red Hat Inc. | Storage deduplication for virtual machines with encrypted storage |
KR20210069473A (ko) | 2019-12-03 | 2021-06-11 | 삼성전자주식회사 | 사용자에 대한 인증을 통해 유저 데이터에 대한 권한을 부여하는 시큐리티 프로세서 및 이를 포함하는 컴퓨팅 시스템 |
US11768611B2 (en) * | 2020-04-02 | 2023-09-26 | Axiado Corporation | Secure boot of a processing chip |
CN112257064B (zh) * | 2020-10-31 | 2024-02-09 | 海光信息技术股份有限公司 | 一种嵌套页表度量方法、装置及相关设备 |
US11995197B2 (en) | 2021-07-27 | 2024-05-28 | International Business Machines Corporation | Sensitive data encryption |
US20240320322A1 (en) * | 2021-12-20 | 2024-09-26 | Intel Corporation | Circuitry and methods for implementing a trusted execution environment security manager |
CN114611163A (zh) * | 2022-03-16 | 2022-06-10 | 中电(海南)联合创新研究院有限公司 | 一种虚拟机迁移方法、装置、设备及存储介质 |
CN118749097A (zh) * | 2022-03-28 | 2024-10-08 | 英特尔公司 | 用于受信任执行环境虚拟机之间的通信的安全共享存储器缓冲器 |
Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20030188165A1 (en) * | 2002-03-29 | 2003-10-02 | Sutton James A. | System and method for execution of a secured environment initialization instruction |
JP2007141096A (ja) * | 2005-11-21 | 2007-06-07 | Sony Corp | 情報処理装置、情報記録媒体製造装置、情報記録媒体、および方法、並びにコンピュータ・プログラム |
JP2007188520A (ja) * | 2005-06-28 | 2007-07-26 | Matsushita Electric Ind Co Ltd | 検証方法、情報処理装置、記録媒体、検証システム、証明プログラム及び検証プログラム |
JP2007233704A (ja) * | 2006-03-01 | 2007-09-13 | Nec Corp | 仮想マシンを利用した情報処理装置および情報処理システム、並びに、アクセス制御方法 |
WO2009044461A1 (ja) * | 2007-10-03 | 2009-04-09 | Fujitsu Limited | デバイスアクセス制御プログラム、デバイスアクセス制御方法および情報処理装置 |
JP2009124520A (ja) * | 2007-11-16 | 2009-06-04 | Fujitsu Ltd | データ送付方法および電子機器 |
Family Cites Families (15)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US6560706B1 (en) * | 1998-01-26 | 2003-05-06 | Intel Corporation | Interface for ensuring system boot image integrity and authenticity |
US7137004B2 (en) * | 2001-11-16 | 2006-11-14 | Microsoft Corporation | Manifest-based trusted agent management in a trusted operating system environment |
ES2218484T3 (es) * | 2002-03-26 | 2004-11-16 | Soteres Gmbh | Un metodo de proteger la integridad de un programa de ordenador. |
US7380119B2 (en) * | 2004-04-29 | 2008-05-27 | International Business Machines Corporation | Method and system for virtualization of trusted platform modules |
JP5016189B2 (ja) * | 2004-08-03 | 2012-09-05 | 株式会社リコー | 電子装置、電子装置の制御方法、プログラム及び記録媒体 |
US7836299B2 (en) * | 2005-03-15 | 2010-11-16 | Microsoft Corporation | Virtualization of software configuration registers of the TPM cryptographic processor |
EP1975830A1 (en) * | 2007-03-30 | 2008-10-01 | British Telecommunications Public Limited Company | Distributed computer system |
US8010763B2 (en) * | 2007-08-02 | 2011-08-30 | International Business Machines Corporation | Hypervisor-enforced isolation of entities within a single logical partition's virtual address space |
US8171301B2 (en) * | 2007-10-07 | 2012-05-01 | Embotics Corporation | Method and system for integrated securing and managing of virtual machines and virtual appliances |
US8336094B2 (en) * | 2008-03-27 | 2012-12-18 | Juniper Networks, Inc. | Hierarchical firewalls |
US20090276774A1 (en) * | 2008-05-01 | 2009-11-05 | Junji Kinoshita | Access control for virtual machines in an information system |
JP5369502B2 (ja) * | 2008-06-04 | 2013-12-18 | 株式会社リコー | 機器、管理装置、機器管理システム、及びプログラム |
US8479015B2 (en) * | 2008-10-17 | 2013-07-02 | Oracle International Corporation | Virtual image management |
US8560825B2 (en) * | 2010-06-30 | 2013-10-15 | International Business Machines Corporation | Streaming virtual machine boot services over a network |
US8707301B2 (en) * | 2010-11-08 | 2014-04-22 | Microsoft Corporation | Insertion of management agents during machine deployment |
-
2009
- 2009-07-16 EP EP09165682.7A patent/EP2278514B1/en active Active
-
2010
- 2010-07-16 KR KR1020127000969A patent/KR101318524B1/ko active IP Right Grant
- 2010-07-16 JP JP2012520055A patent/JP5497171B2/ja active Active
- 2010-07-16 WO PCT/EP2010/060341 patent/WO2011006997A1/en active Application Filing
- 2010-07-16 US US13/379,398 patent/US8856544B2/en active Active
- 2010-07-16 CN CN201080031632.4A patent/CN102473213B/zh active Active
Patent Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20030188165A1 (en) * | 2002-03-29 | 2003-10-02 | Sutton James A. | System and method for execution of a secured environment initialization instruction |
JP2007188520A (ja) * | 2005-06-28 | 2007-07-26 | Matsushita Electric Ind Co Ltd | 検証方法、情報処理装置、記録媒体、検証システム、証明プログラム及び検証プログラム |
JP2007141096A (ja) * | 2005-11-21 | 2007-06-07 | Sony Corp | 情報処理装置、情報記録媒体製造装置、情報記録媒体、および方法、並びにコンピュータ・プログラム |
JP2007233704A (ja) * | 2006-03-01 | 2007-09-13 | Nec Corp | 仮想マシンを利用した情報処理装置および情報処理システム、並びに、アクセス制御方法 |
WO2009044461A1 (ja) * | 2007-10-03 | 2009-04-09 | Fujitsu Limited | デバイスアクセス制御プログラム、デバイスアクセス制御方法および情報処理装置 |
JP2009124520A (ja) * | 2007-11-16 | 2009-06-04 | Fujitsu Ltd | データ送付方法および電子機器 |
Non-Patent Citations (1)
Title |
---|
JPN5012016192; GARFINKEL T: 'TERRA: A VIRTUAL MACHINE-BASED PLATFORM FOR TRUSTED COMPUTING' ACM SOSP. PROCEEDINGS OF THE ACM SYMPOSIUM ON OPERATING SYSTEMSPRINCIPLES , 20031019 * |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2016511610A (ja) * | 2013-03-15 | 2016-04-14 | インターナショナル・ビジネス・マシーンズ・コーポレーションInternational Business Machines Corporation | マルチテナント・コンピューティング・インフラストラクチャにおける鍵管理の方法、装置、コンピュータ・プログラム製品、およびクラウド・コンピュート・インフラストラクチャ(マルチテナント環境における鍵管理) |
Also Published As
Publication number | Publication date |
---|---|
EP2278514A1 (en) | 2011-01-26 |
KR20120018820A (ko) | 2012-03-05 |
EP2278514B1 (en) | 2018-05-30 |
CN102473213B (zh) | 2015-06-17 |
US8856544B2 (en) | 2014-10-07 |
CN102473213A (zh) | 2012-05-23 |
WO2011006997A1 (en) | 2011-01-20 |
JP5497171B2 (ja) | 2014-05-21 |
KR101318524B1 (ko) | 2013-11-21 |
US20120137117A1 (en) | 2012-05-31 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
JP5497171B2 (ja) | セキュア仮想マシンを提供するためのシステムおよび方法 | |
US11258605B2 (en) | Out-of-band remote authentication | |
Buhren et al. | Insecure until proven updated: analyzing AMD SEV's remote attestation | |
US9509692B2 (en) | Secured access to resources using a proxy | |
JP6222592B2 (ja) | モバイルアプリケーション管理のためのモバイルアプリケーションのアイデンティティの検証 | |
EP3061027B1 (en) | Verifying the security of a remote server | |
US8171295B2 (en) | Information processing apparatus, a server apparatus, a method of an information processing apparatus, a method of a server apparatus, and an apparatus executable process | |
US9413538B2 (en) | Cryptographic certification of secure hosted execution environments | |
CN112765637A (zh) | 数据处理方法、密码服务装置和电子设备 | |
CN117453343A (zh) | 虚拟机度量、机密计算认证方法、设备、系统及存储介质 | |
Galanou et al. | Matee: Multimodal attestation for trusted execution environments | |
CN111245600B (zh) | 基于区块链技术的鉴权认证方法和系统 | |
Bravi | Use of Trusted Computing techniques to counteract Cybersecurity attacks in Critical Infrastructures | |
Pedone et al. | Trusted computing technology and proposals for resolving cloud computing security problems | |
Sharma | Onboard credentials: Hardware assisted secure storage of credentials | |
Uzunay et al. | Trust-in-the-middle: towards establishing trustworthiness of authentication proxies using trusted computing | |
St Clair | Shamon-establishing Trust in Distributed Virtualized Environments |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
A977 | Report on retrieval |
Free format text: JAPANESE INTERMEDIATE CODE: A971007 Effective date: 20130904 |
|
A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20130917 |
|
A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20131216 |
|
TRDD | Decision of grant or rejection written | ||
A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 Effective date: 20140204 |
|
A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20140305 |
|
R150 | Certificate of patent or registration of utility model |
Ref document number: 5497171 Country of ref document: JP Free format text: JAPANESE INTERMEDIATE CODE: R150 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |