Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

17 results about "Trusted components" patented technology

Extending a security perimeter into a tenant-specific public cloud partition

ActiveUS12413409B2User identity/authority verificationHard codingTrusted components
Methods, systems, and computer program products for executing trusted software components in public computing clouds. Verifiably authentic software components are installed into a tenant partition of a multi-tenant public cloud-based environment. To do so, a software component installer is configured to install registered software components into the tenant partition. Installer processing includes (1) obtaining a component-specific token for a software component wherein the component-specific token is specific to both the software component to be installed and a particular tenant, and (2) installing the software component on behalf of the given tenant in the multi-tenant public cloud-based environment. Prior to executing the underlying code of the tenant-specific software component, the software component is authenticated with a component registry using the component-specific token. Additional trusted components are installed based on demand from within the tenant partition. No user or administrator intervention is needed and no credentials are hard-coded into the software components.
Owner:NUTANIX INC

Component verification method, device and readable storage medium of internet of things equipment

ActiveCN119675893BUser identity/authority verificationTrusted componentsDigital signature
The application provides a component verification method and device of an Internet of Things equipment and a readable storage medium, and the specific implementation scheme is as follows: reading the equipment component information of an OTP storage area after the equipment component is powered on and completed, performing self-checking based on the equipment component information to obtain a component self-checking result; sending the corresponding equipment component start state to a verification platform according to the component self-checking result; receiving a discrimination random number generated by the verification platform in response to the normal start state of the equipment component, calling an internal private key to digitally sign the discrimination random number to obtain a signature value; and sending the signature value and the built-in digital certificate to the verification platform to verify whether the component of the Internet of Things equipment is a trusted component. The application scheme provides a component trusted verification mechanism of the Internet of Things equipment, improves the component trustworthiness of the Internet of Things equipment, and in addition, the component self-checking by the Internet of Things equipment and the second re-verification by the verification platform improve the security strength of the equipment component verification.
Owner:SHENZHEN TECH UNIV

A method for trusted component partitioning and automated deployment of a trusted DCS controller

The application provides a method for dividing and automatically deploying trusted components of a trusted DCS controller, comprising: dividing components in the trusted DCS controller into trust_module bottom management trusted security components and agent proxy management communication trusted security components according to the functional characteristics and security requirements of the components in the trusted DCS controller; and simultaneously or separately installing the trust_module bottom management trusted security components and the agent proxy management communication trusted security components by using a trust_module trusted security component automatic deployment tool and an agent proxy trusted security component automatic deployment tool. The application realizes modular design of trusted components, and the required trusted security components can be separately installed and configured, so that the deployment process of the trusted components is greatly simplified and the deployment efficiency is improved.
Owner:XIAN THERMAL POWER RES INST CO LTD +1

Trusted starting method and system for credential mobile terminal

PendingCN121808786AImprove startup reliabilityImprove controllabilityPlatform integrity maintainanceTrusted componentsOperational system
The invention relates to the technical field of creative mobile terminals, in particular to a trusted startup method and system for a creative mobile terminal, and the method comprises the steps: carrying out hierarchical verification and state monitoring on a hardware trust root module, security startup firmware and an operating system kernel, extracting multi-dimensional security features, and constructing a system security feature vector; secondly, establishing a trust chain component dependency graph, and generating a trusted startup sequence with the minimum security risk through constraint optimization; in combination with the trusted startup sequence and the feature vector, intelligently identifying startup threats and dividing risk levels to form a layered security protection strategy; and dynamically adjusting a protection strategy and allocating a resource weight, loading and dividing the trusted component into a high-security verification area and a basic verification area for block verification, and outputting a trusted startup execution result. According to the method, full-link trusted measurement, intelligent risk management and control and resource optimization scheduling in the starting process are realized, and the safety and starting efficiency of the credential terminal are remarkably improved.
Owner:HANGZHOU BYTE INFORMATION TECH CO LTD

Method for starting a computing unit

The invention relates to a method for starting a computing unit comprising a microcontroller and a trusted component, wherein, during the startup of the computing unit, the trusted component verifies the hardware configuration of the microcontroller. The invention further relates to a device and a computer program.
Owner:ROBERT BOSCH GMBH

binding a security object of a security module to a security guest

At least one secure object of the security module is bound to the security guest. The trusted component determines whether metadata of the security guest includes a secret binding attribute of the security module. Based on determining that the metadata includes the secret binding attribute, the trusted component configures the security module for the security guest in a select mode. The select mode prevents certain operations from being intercepted by a hypervisor associated with the security guest. The trusted component intercepts security module communications and performs cryptographic operations on one or more secure objects of the security module communications using the secret binding attribute to provide cryptographic results. Results of the security module communications including the cryptographic results are provided to a receiver.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Trusted boot method, trusted component and chip of multiprocessor system

PendingCN122413433ATrusted componentsMulti processor
The application discloses a trusted starting method of a multi-processor system, a trusted component and a chip, and relates to the chip field.In the method, when starting, the multi-processor system performs identity authentication and key negotiation between a processor and a trusted component through a main processor, and after the identity authentication is passed and the key is negotiated, the measurement result of the slave processor encrypted based on the key is forwarded to the trusted component through the main processor, so that the slave processor and the trusted component are guaranteed to perform channel encryption on the basis of mutual trust of identities, the measurement result of the slave processor cannot be viewed or tampered with in the transmission process, and the security of the trusted starting of the system is improved.
Owner:HUAWEI TECH CO LTD

Hands free access management and credential protection

ActiveUS12463951B2Security arrangementSecuring communicationTrusted componentsOff the shelf
A trusted component is suggested to be added to off the shelf computing systems such as PCs or smartphone providing secure functions for access management and credential protection—safe authentication, maintaining session integrity and validation of content modification. An additional advantage of the solution that it detects malware / hacking attempts on first try allowing of taking action while oblivious to the malware / hacker to avoid retaliation.
Owner:BARKAN MORDECAI

Automated evidence collection within a cloud service

A trusted component can be deployed to a computing cluster that collects audit evidence inside the cluster continuously. Performing the evidence collection within the cloud service avoids extending access to cloud resources, since the cloud service already has access to the cloud resources being audited. Additionally, since the evidence collection component is deployed to production servers, existing processes for testing and verifying standards compliance will be applied to the evidence collection component, increasing the quality of the component as compared to less thoroughly vetted external solutions. The evidence collection component may run on a regular schedule and collect evidence regularly (e.g., daily). The relevant information is retrieved from logs generated by the services being audited. The retrieved data is stored in an object store. Thus, only the information published by the evidence collection component is made accessible to external tools, enhancing the security of the services.
Owner:SAP SE

BIND SECURE OBJECTS OF A SECURITY MODULE TO A SECURE GUEST

A computer program product for enabling processing within a data processing environment, wherein the computer program product comprises: comprising at least one computer-readable storage medium that is readable by at least one processing circuit and stores instructions for carrying out a procedure: Binding at least one secure object of a security module (150) of the data processing environment to a secure guest (180) of the data processing environment, wherein the secure guest is configured to use the security module (150), and wherein the binding has: Determine (300) through a trusted component (160) of the data processing environment whether metadata of the secure guest (180) contains a confidential binding attribute for the security module (150), wherein the confidential binding attribute is to be used to bind the one or more secure objects generated by the security module (150) to the secure guest (180), wherein the security module (150) is separate from the trusted component and is assigned to the secure guest (180) via a hypervisor (170); Configure (304) by the trusted component (160) based on the finding that the metadata contains the confidential binding attribute, the security module (150) for the secure guest (180) in a selected mode, wherein the selected mode prevents certain operations from being intercepted by a hypervisor (170); Interception (306) of a security module data transmission by the trusted component (160); Performing a cryptographic operation on one or more secure objects of the security module data transmission using the confidential binding attribute to provide a cryptographic result; and Providing a result of the security module data transmission to a receiver, wherein the result contains the cryptographic result.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Electronic gaming terminal with trusted component system

PendingUS20260087876A1Apparatus for meter-controlled dispensingTrusted componentsData set
Systems and methods to enhance validation of trusted components of an electronic gaming terminal are described. The system includes a platform controller, and one or more component controllers. The platform controller generates and shares an encryption key with the component controllers. The platform controller validates the component controller by transmitting encrypted first data set, receiving encrypted second data set, and validating the component controller based on decrypting the second data set. In response to the component controller being deemed invalid, the platform controller prevents launching of a gaming application.
Owner:SAVVY DOG SYST LLC

Extending a security perimeter into a tenant-specific public cloud partition

PendingUS20260128890A1User identity/authority verificationHard codingTrusted components
Methods, systems, and computer program products for executing trusted software components in public computing clouds. Verifiably authentic software components are installed into a tenant partition of a multi-tenant public cloud-based environment. To do so, a software component installer is configured to install registered software components into the tenant partition. Installer processing includes (1) obtaining a component-specific token for a software component wherein the component-specific token is specific to both the software component to be installed and a particular tenant, and (2) installing the software component on behalf of the given tenant in the multi-tenant public cloud-based environment. Prior to executing the underlying code of the tenant-specific software component, the software component is authenticated with a component registry using the component-specific token. Additional trusted components are installed based on demand from within the tenant partition. No user or administrator intervention is needed and no credentials are hard-coded into the software components.
Owner:NUTANIX INC

Identity authentication method and device, equipment and medium

The invention relates to an identity authentication method and device, equipment and a medium. The method comprises the following steps: sending a service request to a service platform to indicate the service platform to query an identity authentication result representing that a user has a third-party platform permission from a block chain; if not, encrypting identity plaintext information of the user on the third-party platform by using a public key provided by the trusted component; sending the encrypted identity ciphertext information to the trusted component to indicate the trusted component to generate first verification information, decrypting the identity ciphertext information by using a private key matched with the public key in a trusted domain provided by the trusted component, and sending the first verification information to a third-party platform based on the decrypted identity plaintext information; and sending second verification information to the trusted component to instruct the trusted component to generate an identity authentication result and store the identity authentication result to the block chain after comparing that the second verification information is consistent with the first verification information, the identity authentication result being used for instructing the service platform to provide services for the user. By adopting the method, the privacy data of the user can be protected.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Establishment of trust for disconnected edge-based deployments

ActiveUS12676859B2Trusted componentsEdge computing
A computing network comprising a computing service provider and an edge computing network is managed. A trusted device establishes a root of trust at the edge computing network via a trusted component on the trusted device. In response to receiving a first indication of a disconnection or degradation of communications between the computing service provider and the edge computing network, the edge computing network initiates an autonomous mode at the edge computing network. While the edge computing network is operating in the autonomous mode, the trusted device detects new devices that are attempting to access computing resources in the edge computing network. The trusted device stores data pertaining to new devices that were not authorized to access the computing resources in the edge computing network.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Rollback protection with ephemeral identities for tee-based consensus protocols

ActiveUS12470396B2User identity/authority verificationTrusted componentsParallel computing
A rollback protection method for preventing message equivocation in a consensus system is provided. The consensus system includes distributed computational nodes connected by a network and configured to run a TEE-based consensus protocol. The method includes: executing, within a trusted execution environment of a node of distributed computational nodes, a trusted component instance, that includes volatile protected memory with protected data stored therein and a protected piece of code implementing at least a part of a consensus algorithm, generating identity data comprising a unique ephemeral identity, and storing the identity data in the volatile protected memory of the trusted component instance, and certifying a message of the consensus algorithm, wherein a certified consensus algorithm message is generated by cryptographically binding parts of the consensus algorithm message to the unique ephemeral identity of the trusted component instance and at least parts of the protected data of the trusted component instance.
Owner:NEC CORP

Access object authentication method and apparatus, and system

ActiveUS12683801B2Trusted componentsEngineering
An access object authentication method includes a trusted component that is in a computing device and that completes an access object authentication process. When a client requests to access a target object, the trusted component receives an object identifier (ID) and an authentication ID of the target object from the client to perform, based on the authentication ID, tenant authentication on a tenant to which the client belongs. When the authentication on the tenant to which the client belongs succeeds, the trusted component accesses a storage device based on the object ID of the target object.
Owner:HUAWEI TECH CO LTD