Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

11 results about "Trusted computing base" patented technology

The trusted computing base (TCB) of a computer system is the set of all hardware, firmware, and/or software components that are critical to its security, in the sense that bugs or vulnerabilities occurring inside the TCB might jeopardize the security properties of the entire system. By contrast, parts of a computer system outside the TCB must not be able to misbehave in a way that would leak any more privileges than are granted to them in accordance to the security policy.

Method and device for constructing network security operating system, electronic equipment and storage medium

ActiveCN121887549AArtificial lifeSecuring communicationOperational systemTrusted computing base
The invention belongs to the field of network security, and relates to a method and a device for constructing a network security operating system, electronic equipment and a storage medium, and the method comprises the following steps: constructing an autonomously controllable improved microkernel infrastructure; based on the microkernel infrastructure, constructing a full-stack layered security control computing architecture base; constructing intelligent agent components, and deploying a multi-intelligent agent collaborative protection component system; integrating trusted computing and an integrity measurement verification system; performing dynamic adaptation and execution of multiple security policies; and a standardized safety evaluation and adaptive optimization closed loop is established. A trusted computing base is cut from a design source, so that the probability of occurrence of high-risk vulnerabilities is reduced; the real-time defense that the threat is changed and the strategy is changed is realized, and the blind area of the static strategy in resisting the unknown threat is made up; the malicious codes can be blocked before running, and the post passive situation that traditional security software only depends on a feature library for searching and killing is broken; and the contradiction between security capability solidification and threat dynamic evolution is fundamentally solved.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

A power industrial control security protection system and method based on microkernel active defense

PendingCN122179216ASecuring communicationScheduling (computing)Trusted computing base
The application discloses a power industrial control safety protection system and method based on a microkernel active defense, wherein the system takes a microkernel isolation base as a minimum trusted computing base, allocates revocable communication endpoints and controlled mapping permissions to each protection domain, and provides base support for the isolation domain boundary and permission recovery in the active defense; in the method, the system is uniformly formatted by an input module to process field data and service requests and generate a request identifier, a request distribution service distributes the same request to an odd number of online executors for parallel processing, a single decision output available externally is generated, an executor scheduling service selects a candidate executor from a candidate protection domain pool and reconstructs an online user mode service cluster according to a feedback index by adopting a periodic rotation and event triggering strategy, and if the request distribution service, the consistency arbitration service or the executor scheduling service fails, a minimum bottom-up cleaning is performed by an active defense kernel state support module and a reestablishable state is entered.
Owner:NARI INFORMATION & COMM TECH

Paging support for encrypted GPU buffers

Described herein is a paging technique that can be implemented in any accelerator with attached memory and support for operating on encrypted data when the CPU is not within the trusted compute base (TCB). Memory storing data that is encrypted using hardware physical address (HPA)-based encrypted can be paged out of accelerator device memory by decoupling encryption from the hardware physical address and re-encrypting the data for page-out. Upon page-in, the data is decrypted, the integrity and authenticity of the data is verified, then the data is re-encrypted using HPA-based encryption.
Owner:INTEL CORP

Selective Cryptographic Processing and Trust Elevation for Collective Operations in a UALink Network

PendingUS20260254662A1Trusted ComputingTransaction data
Implementations for selective cryptographic processing of collective and unicast traffic at a switch in an accelerator network. As AI training and inference workloads increasingly rely on in-network collective operations to accelerate gradient synchronization, broadcast, and reduction across large-scale accelerator pods, some implementations include a switch comprising a circuit that determines, for each encrypted transaction, whether it is a collective transaction or a unicast transaction. For collective transactions, the circuit decrypts transaction data for processing such as arithmetic reduction at the switch. For unicast transactions, the circuit bypasses decryption and forwards the transaction with data remaining encrypted between source and destination accelerators. Some implementations further include selective trust elevation of the switch into a trusted computing base for collective operations via a security manager, secure session establishment, attestation verification, and encryption key programming, while maintaining the switch outside the trusted computing base for unicast operations.
Owner:UNIFABRIX LTD

Laboratory digital safety workspace management method, system and equipment based on trusted computing and medium

The invention discloses a laboratory digital safety workspace management method, system and device based on trusted computing and a medium, and belongs to the technical field of laboratory information safety management, and the method comprises the steps: measuring a starting chain through trusted hardware, uploading a measurement value after verification, completing multi-factor authentication and encryption channel establishment, and carrying out strategy conformity check; creating a resource isolated working space, loading a security policy in real time, and monitoring user behaviors and peripheral access; carrying out enhanced authentication and encryption verification transmission; and generating a tamper-proof chained auditing log, and automatically starting hierarchical response and joint treatment based on the log and a monitoring result to form a traceable responsibility judgment link. According to the invention, the operation environment of the terminal system is ensured to be credible based on the trusted computing root, multi-task isolation and data leakage prevention are realized by adopting a containerized digital workspace, authority control is implemented through an identity and task adaptive security policy, and the security event response capability and operation traceability are improved by means of real-time monitoring and auditing a log library.
Owner:YUNNAN ELECTRIC POWER TESTING & RES INST (GRP) CO LTD +1

A method and system for building a virtual machine monitor secure execution environment

The application discloses a virtual machine monitor security execution environment construction method and system. The method is as follows: removing the host OS and virtual machine monitor runtime code from the trusted computing base TCB, and constructing a simple security monitor on the CPU privilege level of the host; removing the privilege permission of the host OS to obtain a reduced-privilege host OS; using the simple security monitor to instantiate a Bid-Enclave instance for each virtual machine on the host to carry the virtual machine monitor runtime; and executing a bidirectional isolation strategy between the reduced-privilege host OS and the instance and between different instances; dividing I / O processing into a control plane and a data plane; using the reduced-privilege host OS to process the control plane and auditing by the simple security monitor; and under the supervision of the simple security monitor, establishing a protected direct memory access channel between the instance and a PCIe SR-IOV virtual function or an analog device queue to access the data plane.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Industrial control network security analysis method and system based on knowledge graph, and medium

The application discloses a knowledge graph-based industrial control network security analysis method and system and a medium, and relates to the technical field of industrial control network security.The method comprises the following steps: for an industrial control scene, an industrial control component-component industrial control element is used to mine security invariants and perform control logic modeling, and a trusted computing base is built; an industrial control knowledge graph is determined; a first industrial control threshold is deployed based on the trusted computing base, a second industrial control threshold is established based on the industrial control knowledge graph, an industrial control security threshold is embedded in a peripheral interface in front of a controller, and with the interaction of a first industrial control task instruction, an industrial control security threshold is added to perform two-level threshold decision and industrial control security threshold management.The technical problem that the existing industrial control network security risks are difficult to identify in a timely manner and lack effective protection decision mechanisms is solved, the technical effect of improving the comprehensiveness and credibility of industrial control network security analysis and enhancing the protection capability of an industrial control system against potential attack behaviors is achieved.
Owner:北京珞安科技有限责任公司

Sensitive data auditing method based on trusted computing

The invention discloses a sensitive data auditing method based on trusted computing, which belongs to the technical field of sensitive data security auditing, and comprises the following steps: acquiring a framework topological graph of a target system, determining a plurality of specified sensitive data processing areas, and deploying trusted computing base components for each area to establish a trusted execution environment; based on the historical access record, performing access behavior analysis on the plurality of specified sensitive data processing areas, and generating a corresponding normal access behavior baseline; constructing an access behavior judgment model according to the normal access behavior baseline, and performing access behavior judgment on the current access record to obtain a judgment result; and obtaining a corresponding access record based on the abnormal access behavior, performing analysis, obtaining reference audit data corresponding to the access subject, performing abnormal risk analysis, calculating a risk coefficient value of the reference audit data, obtaining a risk level corresponding to the abnormal access behavior, and triggering a graded early warning response mechanism.
Owner:BEIJING ZHONGAN NEBULA SOFTWARE TECH CO LTD

Method for auditing sensitive data based on trusted computing

ActiveCN121435229BSolve the problem of weak protection in processing linksavoid risk of leakageBehavioral analyticsTrusted Computing
The application discloses a sensitive data auditing method based on trusted computing and belongs to the technical field of sensitive data security auditing, which comprises the following steps: collecting the architecture topology of a target system, determining a plurality of specified sensitive data processing areas, deploying a trusted computing base component for each area to establish a trusted execution environment; based on historical access records, performing access behavior analysis on the plurality of specified sensitive data processing areas to generate corresponding normal access behavior baselines; then, constructing an access behavior judgment model according to the normal access behavior baselines to perform access behavior judgment on current access records to obtain a judgment result; based on abnormal access behavior, obtaining corresponding access records and performing analysis, obtaining baseline auditing data of corresponding access subjects and performing abnormal risk analysis, calculating a risk coefficient value of the baseline auditing data, obtaining a risk level of the corresponding abnormal access behavior and triggering a hierarchical early warning response mechanism.
Owner:BEIJING ZHONGAN NEBULA SOFTWARE TECH CO LTD

Industrial computing device and method for performing attestation

An industrial computing device for controlling a technical system comprises: a measurement unit for installing therein measurement agents each configured to obtain a respective measurement result by performing a measurement of a device attribute of a component of the industrial computing device and / or the technical system; a measurement binding unit that receives the measurement result from each of the measurement agents and to generate a bound measurement result by binding the measurement result of each measurement agent to the respective measurement agent; and an attestation unit that provides a cryptographically secured attestation of the bound measurement result, The measurement binding unit and the attestation unit are part of a trusted computing base of the industrial computing device, whereas the measurement unit is formed outside of the trusted computing base. Flexibility of an OEM to perform custom measurements is increased.
Owner:SIEMENS AG

Cloud computing security control system for credential and credential cloud platform

The invention relates to a cloud computing security control system for a credential cloud platform, and belongs to the field of cloud computing security, and the system comprises a credential trusted computing base construction module which constructs a trusted start chain and performs dynamic measurement verification on a virtualization monitor and a key system component; the calculation behavior fingerprint monitoring and analysis module collects operation data and extracts calculation behavior fingerprints representing a normal behavior mode; calculating the similarity with the reference fingerprint, and outputting a dynamic security confidence score; the security function service gridding management module disassembles a plurality of security capabilities into SFV micro-service instances; the cross-layer heterogeneous security knitting engine receives the multi-source security information and matches the multi-source security information with a predefined linkage response strategy; and the data security situation label management module automatically attaches and updates a security situation label to the data key node. The system can be deeply integrated into a credential cloud bottom layer, and has active immunity and elastic defense capability.
Owner:E-SURFING DIGITAL LIFE TECH CO LTD