Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8 results about "Trusted operating system" patented technology

Trusted Operating System (TOS) generally refers to an operating system that provides sufficient support for multilevel security and evidence of correctness to meet a particular set of government requirements.

Distributed TEE system, communication method based on distributed TEE system

This application relates to a distributed TEE system and a communication method based on the distributed TEE system. The system includes multiple TEEs, each TEE's secure world includes a key management module and a communication invocation module, and the TEE's trusted operating system includes an encryption / decryption module. Each module is invoked by a security monitor within the TEE or runs in a first memory location of the secure world that can be accessed by the ordinary world. The key management module is used to generate keys; the encryption / decryption module is used to encrypt specified data according to the key when the TEE generates specified data in response to a memory access instruction, verify the integrity of the first data packet received from another TEE, and decrypt the first data packet according to the key; the communication invocation module is used to encapsulate the encrypted specified data and / or the decrypted first data packet into a second data packet. This method can improve the security of data communication when deploying a TEE system in a distributed system.
Owner:ZHEJIANG UNIV +1

Authority management method and system for equipment flash, chip and intelligent terminal

The invention discloses an authority management method and system for equipment flashing, a chip and an intelligent terminal.The method comprises the steps that when an authorization mode for equipment flashing is a quick start authorization mode, a boot loader is started; the client application initiates a first authorization authentication request via the first trusted execution environment client interface; the trusted execution environment core driver receives the first authorization authentication request and switches the operating environment of the processor from a common world to a secure world; the trusted operating system receives and analyzes the first authorization authentication request, and schedules an early trusted application to obtain equipment fingerprint information from the first storage partition; when the equipment fingerprint information passes verification, modifying the first authorization mark, and correspondingly modifying the second authorization mark stored in the second storage partition; and the intelligent terminal is switched into the factory mode. According to the method and the device, the original flashing port can be controllably opened, so that the risk of illegal flashing is avoided, and meanwhile, legal flashing operation is guaranteed.
Owner:SHANGHAI SUMI TECH CO LTD +1

Method to secure data processing in computer, computer program and computer device

The description relates to a method to secure data processing in a computer arranged according to a hybrid software architecture. The aid hybrid architecture relies on a dual operating system comprising a General-Purpose Operating System “GPOS” and a Trusted Operating System “TOS” running critical functions. The execution of a current application by the GPOS implying an access of at least one primitive to the TOS. The method comprises implementing by the GPOS an authentication procedure requiring an authentication validation granted by the TOS, and upon at least a validation of the authentication by the TOS, authorizing said at least one primitive to access to the TOS.
Owner:MITSUBISHI ELECTRIC CORP

Resource adjustment method and device, electronic equipment and storage medium

The embodiment of the invention provides a resource adjustment method and device, electronic equipment and a storage medium. The resource adjustment method comprises the steps that a resource adjustment request of any trusted operating system instance is responded, the adjustment request comprises the type of a to-be-adjusted resource and the size of the to-be-adjusted resource, and the adjustment request is combined with the operation requirement of the trusted operating system instance; further, a resource occupation relationship matched with the to-be-adjusted resource type is determined, the resource occupation relationship comprises use conditions of the plurality of operating system instances on the resource of the to-be-adjusted resource type, the resource use conditions of the plurality of operating system instances can be determined according to the resource occupation relationship, and then the to-be-adjusted resource type can be adjusted according to the resource occupation relationship. The resource corresponding to the size of the to-be-adjusted resource can be adjusted to the trusted operating system instance, so that the resource dynamic adjustment for the trusted operating system instance is realized, the efficient operation of the application program in the trusted operating system instance is ensured, and the resource utilization rate in the management system is improved.
Owner:ALIBABA CLOUD COMPUTING CO LTD

A trusted storage system and method based on a distributed storage mechanism

The application relates to the technical field of data storage and trusted computing, and provides a trusted storage system and method based on a distributed storage mechanism. The system comprises a storage resource pool, a virtualization layer, a storage engine, a function layer, interface management and trusted enhancement verification; the distributed intelligent storage system is used for realizing multi-type storage of data; a high-speed communication interconnection network is used for realizing high-speed access of data; and the fusion of trusted hardware and a trusted operating system is used for realizing safe control and whole-process trust of a data access process.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Method, electronic device and storage medium for upgrading signed firmware

The application discloses a method for upgrading signed firmware, an electronic device and a storage medium, wherein public key parameter information and a digital signature algorithm type are saved to a secure storage by a trusted operating system, a message digest corresponding to the public key parameter information is calculated by the trusted operating system, the message digest is encrypted, and the encrypted message digest is written into a command line parameter, and the signed firmware to be upgraded is verified based on the public key parameter information and the digital signature algorithm type in the secure storage and the encrypted message digest in the command line parameter, and the upgrading is performed only when the verification is successful, so that the security of the public key information is improved, and the encrypted message digest in the command line parameter is used as a communication credential between the trusted operating system, thereby effectively improving the security of the signed firmware upgrading.
Owner:FUZHOU ROCKCHIP SEMICON

Remote operation and maintenance method, device and system based on relay protection

The invention discloses a remote operation and maintenance method, device and system based on relay protection. The method comprises the steps that when a remote operation and maintenance operation instruction is obtained, the remote operation and maintenance operation instruction is packaged into a safe operation and maintenance file, a remote operation and maintenance master station adopts a first trusted hardware module, a first trusted operation system runs on the remote operation and maintenance master station, and a data analysis processing platform is arranged in the remote operation and maintenance master station and used for recording the operation process to a first auditing log which cannot be tampered; the operation and maintenance file is sent to the intelligent oscillograph in a file mode, the intelligent oscillograph interacts with the protection device through a safe controllable protocol, the intelligent oscillograph adopts a second trusted hardware module, a second trusted operation system runs on the second trusted hardware module, and a service processing module in the system analyzes a trusted remote operation and maintenance operation instruction from the operation and maintenance file and sends the remote operation and maintenance operation instruction to the intelligent oscillograph. And controlling the protection device according to the credible remote operation and maintenance operation instruction, and recording the operation process to a second auditing log which cannot be tampered. According to the invention, the technical problem of low security of intelligent power grid relay protection is solved.
Owner:BEIJING CREDIBLE HUATAI TECHNICAL SERVICE CO LTD +1

Commands communications

In an example, a hypervisor measuring the state of a protected virtual machine using a Trusted Platform Module (TPM) filter. Using the TPM filter, the system ensures an untrusted operating system attempting to access the TPM is secure, without having to trust the security of the operating system or the operating system's built in hypervisor.
Owner:HEWLETT PACKARD DEVELOPMENT COMPANY LP