WO2019112971A1 - Procédé et appareil d'amorçage sécurisé de système - Google Patents

Procédé et appareil d'amorçage sécurisé de système Download PDF

Info

Publication number
WO2019112971A1
WO2019112971A1 PCT/US2018/063685 US2018063685W WO2019112971A1 WO 2019112971 A1 WO2019112971 A1 WO 2019112971A1 US 2018063685 W US2018063685 W US 2018063685W WO 2019112971 A1 WO2019112971 A1 WO 2019112971A1
Authority
WO
WIPO (PCT)
Prior art keywords
processor
boot code
boot
computer system
main processor
Prior art date
Application number
PCT/US2018/063685
Other languages
English (en)
Inventor
Joshua P. De Cesare
Timothy R. Paaske
Xeno S. KOVAH
Nikolaj SCHLEJ
Jeffrey R. Wilcox
Ezekiel T. RUNYON
Hardik K. Doshi
Kevin H. ALDERFER
Corey T. KALLENBERG
Original Assignee
Apple Inc.
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from US16/205,838 external-priority patent/US20190102558A1/en
Application filed by Apple Inc. filed Critical Apple Inc.
Publication of WO2019112971A1 publication Critical patent/WO2019112971A1/fr

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/575Secure boot
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Stored Programmes (AREA)

Abstract

L'invention concerne un procédé et un appareil permettant d'effectuer un amorçage sécurisé d'un système informatique. Un système informatique selon l'invention comprend un processeur auxiliaire et un processeur principal. Le processus d'amorçage consiste à amorcer initialement le processeur auxiliaire. Le processeur auxiliaire est associé à une mémoire non volatile contenant un code d'amorçage destiné au processeur principal. Le processeur auxiliaire peut effectuer une vérification du code d'amorçage. Suite à la vérification du code d'amorçage, le processeur principal peut être sorti d'un état de réinitialisation. Dès la sortie du processeur principal de l'état de réinitialisation, le code d'amorçage peut lui être fourni. Ensuite, la procédure d'amorçage peut continuer avec l'exécution du code d'amorçage par le processeur principal.
PCT/US2018/063685 2017-12-07 2018-12-03 Procédé et appareil d'amorçage sécurisé de système WO2019112971A1 (fr)

Applications Claiming Priority (6)

Application Number Priority Date Filing Date Title
US201762596081P 2017-12-07 2017-12-07
US201762596099P 2017-12-07 2017-12-07
US62/596,099 2017-12-07
US62/596,081 2017-12-07
US16/205,838 US20190102558A1 (en) 2017-06-02 2018-11-30 Method and Apparatus for Secure System Boot
US16/205,838 2018-11-30

Publications (1)

Publication Number Publication Date
WO2019112971A1 true WO2019112971A1 (fr) 2019-06-13

Family

ID=64734249

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2018/063685 WO2019112971A1 (fr) 2017-12-07 2018-12-03 Procédé et appareil d'amorçage sécurisé de système

Country Status (1)

Country Link
WO (1) WO2019112971A1 (fr)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI738135B (zh) * 2019-04-07 2021-09-01 新唐科技股份有限公司 監控系統開機之安全裝置及其方法
WO2024050184A1 (fr) * 2022-08-28 2024-03-07 Qualcomm Incorporated Prise en charge d'algorithmes cryptographiques supplémentaires faisant appel à un composant matériel cryptographique en ligne

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2014175866A1 (fr) * 2013-04-23 2014-10-30 Hewlett-Packard Development Company, L.P. Récupération de code de démarrage de système à partir d'une mémoire non volatile
US20150199520A1 (en) * 2014-01-13 2015-07-16 Raytheon Company Mediated secure boot for single or multicore processors
US20160125187A1 (en) * 2014-11-03 2016-05-05 Rubicon Labs, Inc. System and Method for a Renewable Secure Boot

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2014175866A1 (fr) * 2013-04-23 2014-10-30 Hewlett-Packard Development Company, L.P. Récupération de code de démarrage de système à partir d'une mémoire non volatile
US20150199520A1 (en) * 2014-01-13 2015-07-16 Raytheon Company Mediated secure boot for single or multicore processors
US20160125187A1 (en) * 2014-11-03 2016-05-05 Rubicon Labs, Inc. System and Method for a Renewable Secure Boot

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI738135B (zh) * 2019-04-07 2021-09-01 新唐科技股份有限公司 監控系統開機之安全裝置及其方法
TWI791244B (zh) * 2019-04-07 2023-02-01 新唐科技股份有限公司 監控系統開機之安全裝置及其方法
WO2024050184A1 (fr) * 2022-08-28 2024-03-07 Qualcomm Incorporated Prise en charge d'algorithmes cryptographiques supplémentaires faisant appel à un composant matériel cryptographique en ligne

Similar Documents

Publication Publication Date Title
US11263326B2 (en) Method and apparatus for secure system boot
US8909940B2 (en) Extensible pre-boot authentication
KR100855803B1 (ko) 협동적 임베디드 에이전트
US20190102558A1 (en) Method and Apparatus for Secure System Boot
US8201239B2 (en) Extensible pre-boot authentication
WO2018052625A1 (fr) Technologies de fourniture et de gestion d'amorçage sécurisé d'images de réseau prédiffusé programmable par l'utilisateur
US10430589B2 (en) Dynamic firmware module loader in a trusted execution environment container
US10592661B2 (en) Package processing
KR20130058058A (ko) 서비스 프로세서 컴플렉스 내의 데이터 저장을 위한 요구 기반 usb 프록시
US20210232691A1 (en) Automatically replacing versions of a key database for secure boots
US10853086B2 (en) Information handling systems and related methods for establishing trust between boot firmware and applications based on user physical presence verification
TWI754219B (zh) 更新信號技術
US20190114433A1 (en) Method and Apparatus for Boot Variable Protection
US10019577B2 (en) Hardware hardened advanced threat protection
CN114035842A (zh) 固件配置方法、计算系统配置方法、计算装置以及设备
US10417429B2 (en) Method and apparatus for boot variable protection
WO2019112971A1 (fr) Procédé et appareil d'amorçage sécurisé de système
US20070162733A1 (en) Secure CMOS
US20230342472A1 (en) Computer System, Trusted Function Component, and Running Method
CN113268447A (zh) 计算机架构及其内的访问控制、数据交互及安全启动方法
WO2019112972A1 (fr) Procédé et appareil de protection de variable de démarrage
US20230359741A1 (en) Trusted boot method and apparatus, electronic device, and readable storage medium
US20240160431A1 (en) Technologies to update firmware and microcode
US20230078058A1 (en) Computing systems employing a secure boot processing system that disallows inbound access when performing immutable boot-up tasks for enhanced security, and related methods
WO2022155973A1 (fr) Puce de terminal et son procédé de mesure

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18821931

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18821931

Country of ref document: EP

Kind code of ref document: A1