Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

61 results about "Trusted Platform Module" patented technology

Trusted Platform Module (TPM, also known as ISO/IEC 11889) is an international standard for a secure cryptoprocessor, a dedicated microcontroller designed to secure hardware through integrated cryptographic keys.

Method and device for verifying physical consistency of trusted supply chain and command of energy storage station

The invention provides an energy storage station trusted supply chain and command physical consistency verification method and device. The method comprises the following steps: setting a trusted platform module or a security element in a key device of the energy storage station, and generating a device trusted state identifier; adding a time quality identifier and a source signature to the measurement and state data; identity authentication, protocol analysis, object address and parameter range verification and rate constraint verification are carried out on the remote control instruction; generating a feasible region according to state estimation and equipment constraint, and performing executable judgment on the instruction; when any link does not meet the preset condition, switching to a verifiable security state and blocking a remote write-in path; and when the command firewall and the physical consistency check are both passed, a control instruction is issued to the converter control device and the battery management system, and power, reactive power and grid-connected and off-grid control of the energy storage station is executed. According to the application, supply chain credible closed loop, metering linkage access and double-loop instruction verification can be realized, and failure safety and verifiable evidence obtaining are supported.
Owner:BEIJING GOLDWIND CARBON NEUTRAL ENERGY CO LTD

Virtualizing discrete and migratable trusted platform modules (TPMS)

Systems and methods are provided for implementing virtualization of discrete and migratable cryptographic processors (e.g., trusted platform modules (“TPMs”)). In examples, an orchestrator in a control plane causes migration of a first cryptographic processor emulator (e.g., a TPM emulator) that has been instantiated on a first platform root of trust (“PROT”) to a second PROT, by requesting secret data (e.g., an endorsement seed associated with the cryptographic processor emulator, sealed secrets, etc.) stored in a first memory in the first PROT. The orchestrator receives the secret data, instantiates a second cryptographic processor emulator on the second PROT based on the secret data, and transfers the secret data to a second memory in the second PROT. The orchestrator instructs the cryptographic processor emulator on the first PROT to delete the secret data from the first memory, and sends a status of the migration to a requesting device that requested the migration.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

External field equipment trusted access method based on non-addressable stealth gateway

The invention discloses an external field equipment trusted access method based on a non-addressable stealth gateway, which relates to the technical field of network security access, and comprises the following four steps: in a manufacturing period and first access, a certificate authorization machine binds equipment identity and trusted platform module measurement, policy decision point decision, policy execution point implementation and policy subset loading; initiating from the outside of the equipment, establishing an end-to-end trusted channel with the center, and performing inward isolation and transparent bearing on rear-end real services; updating strategies, algorithms and secret keys on line under the control of a unified strategy library; according to the method, the attack surface is reduced, the transformation cost is reduced, non-stop treatment is ensured, the encrypted traffic can be observed and audited, only trusted equipment can reach the center through a trusted channel, and event linkage right descending and certificate state linkage treatment are supported.
Owner:HANGZHOU XENON TECHNOLOGY CO LTD

Method and device for installing certificate on basis of encryption and decryption of contract certificate private key

Disclosed are a method and device for installing a certificate on the basis of encryption and decryption of a contract certificate private key for an electric vehicle communication controller. The method for installing the certificate comprises: a step in which the electric vehicle communication controller transmits, to a secondary actor, a certificate installation request message signed with a private key associated with a manufacturer's provisioning certificate; and a step of receiving, from the secondary actor, a certificate installation response message signed with a private key associated with a leaf certificate of a certificate provisioning service, wherein an encrypted private key element of the certificate installation response message stores a private key belonging to a new contract certificate which is encrypted for the electric vehicle communication controller without a trust platform module, the private key belonging to the new contract certificate is encrypted with AES-GCM-256 on the basis of an encryption key which is entered from a public key of the manufacturer's provisioning certificate and generated through an ECDH protocol, and the private key encrypted with the AES-GCM-256 is included in a ciphertext at 528-bits or 448-bits after an initial initialization vector of a contract certificate data packet.
Owner:HYUNDAI MOTOR CO LTD +2

Systems and methods for passwordless logon

In one embodiment, a method receives a secret and a passwordless login request using a credential provider of the client device. The method pairs the credential provider of the client device with a trusted platform module (TPM) associated with a computing device. The method encrypts, using the TPM of the computing device, the secret with a hardware-bound key associated with the computing device. The method receives, from the client device, a push notification associated with the passwordless login request. The method obtains, from the client device, biometric authentication data and a nonce encrypted with a public key. The method validates a proximity of the biometric authentication data and determine a decrypted nonce by decrypting the nonce using a private key associated with the client device. The method validates the decrypted nonce with the secret. In response to determining the decrypted nonce is valid, the method approves the passwordless login request.
Owner:CISCO TECHNOLOGY INC

Virtualizing secure vault of data processing unit for secure hardware security module for hosts

A system and method of securing and virtualizing firmware trusted platform modules (TPMs) for virtualizing a hardware security module (HSM) for a host within a network fabric is provided. The system and method include operably coupling a set of components associated with a host comprising a data processing unit (DPU) secure vault and a firmware trusted platform module (TPM). The firmware TPM is configured as a virtual firmware TPM. The DPU secure vault secures the virtual firmware TPM into one or more virtual firmware TPMs based on one or more partitions configured with the DPU secure vault. A virtual TPM manager communicatively coupled to the DPU secure vault manages one or more virtual TPMs for hosting a set of Virtual Machines (VMs) or Containers.
Owner:CISCO TECHNOLOGY INC

Methods and systems for using smart network interface cards to secure data transmission between an initiator host running an object and a target host equipped with a disaggregated hardware device that satisfies hardware specifications of the object

This disclosure is directed to methods and systems that establish a secure data channel between a host and a disaggregated hardware device (“DHD”) of a data center. The system comprises an initiator host that runs objects, such as virtual machines and containers. The host includes an initiator smart network interface card (“SNIC”). The initiator SNIC includes a virtual device, a trust platform module (“TPM”) and a security engine. The system also comprises a target host equipped with a DHD and a target SNIC. The target SNIC includes a TPM and a security engine. The TPM and the security engine of the initiator SNIC and the TPM and the security engine of the target SNIC establish a secure data channel between an object running on the host and the DHD.
Owner:VMWARE INC

A device control method, device, storage medium, and computer program product

The application discloses a device control method, device, storage medium and computer program product, relates to the computer technical field, and the method comprises the following steps: when receiving a hibernation instruction, a trusted execution environment is created, and a dynamic session state plaintext is exported from a trusted platform module to the trusted execution environment; the dynamic session state plaintext is encrypted by using a pre-generated hibernate binding key in the trusted execution environment to obtain dynamic session state ciphertext, and a check value corresponding to the dynamic session state ciphertext is calculated; a hibernate image is created based on the dynamic session state ciphertext and the corresponding check value in the trusted execution environment, and the hibernate image is stored in a nonvolatile storage medium; and a hibernate operation is triggered. The application improves the wake-up efficiency of the device from the hibernate state.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Verifying the rendering of video content at client devices using trusted platform modules

Systems and methods for verifying the rendering of video content on information resources are provided herein. A server can receive, from a target client device, a tracking message purporting to relate to delivery of a target content item; determine whether the tracking message contains an identifier of a sending device that sent the tracking message; determine whether the sending device and the target client device are the same device; if the sending client device and the target client device are the same device: recover, from the tracking message, information about at least a portion of a frame of a content item processed by a trusted platform module of the client device; and compare the at least a portion of the frame of the content item processed by a trusted platform module of the client device with a target content item.
Owner:GOOGLE LLC

Full-link data security protection system and method based on trusted root

The invention discloses a full-link data security protection system and method based on a trusted root, and belongs to the technical field of information security. The link data transmission structure comprises a plurality of substructures, each substructure comprises an operating system, an application program, internal hardware and a transmission channel which are used as encryption objects, the encryption objects are encrypted, and the encryption content is as follows: setting a trusted platform module as a trusted root encryption tool; the operating system comprises an identity authentication password and authority management; the application program encryption comprises a login password and a hierarchical application lock; the internal hardware comprises data encryption of a BIOS, a hard disk and a memory; communication encryption measurement modules are arranged at the two ends of the transmission channel; by the adoption of the system and method, the trusted platform module (TPM) serves as a hardware trusted root, and the processes of operating system identity authentication and authority management, a system application program hierarchical encryption mechanism, a hardware layer data encryption module and transmission channel double-end encryption are achieved.
Owner:SHANGHAI SHIYUE COMPUTER TECH CO LTD

Construction method of trusted confidential channel based on AMD SEV trusted confidential virtual machine

The invention discloses a method for constructing a trusted confidential channel based on an AMD SEV trusted confidential virtual machine, which relates to the field of computer technology and information security, and consists of a unique confidential virtual machine starting scheme, an extended TLS protocol and support components thereof. Specifically, the invention designs a method for constructing a trusted confidential channel based on an AMD SEV trusted confidential virtual machine. According to the method, by means of a virtual trusted platform module vTPM, the running state of an AMD SEV trusted confidential virtual machine is obtained to serve as a trusted credential, and a TLS protocol is expanded to support establishment of a confidential channel and verify the trusted credentials of two communication parties at the same time. Meanwhile, in order to support the method, a corresponding support component is expanded in the confidential virtual machine, so that a user load running in the confidential virtual machine can be seamlessly integrated with the method, and a method for safely and reliably establishing a trusted confidential channel with an application running in the remote confidential virtual machine is provided for the user load.
Owner:BEIJING JIAOTONG UNIV

Scalable trusted platform module in programmable network interface devices

An apparatus includes a host interface, a network interface, and a programmable circuitry communicably coupled to the host interface and the network interface. The programmable circuitry can include one or more processors to implement network interface functionality, and a discrete trusted platform module (dTPM) to enable the one or more processors to establish a secure boot mechanism for the apparatus, wherein the one or more processors are to instantiate a virtual TPM (vTPM) manager that is associated with the dTPM, the vTPM manager to host vTPM instances corresponding to one or more virtualized environments hosted on at least one of the programmable circuitry or a host device communicable coupled to the apparatus.
Owner:INTEL CORP

Secure communication method and device for dynamic mode encryption, medium and product

The invention discloses a secure communication method and device for dynamic mode encryption, a medium and a product, and relates to the field of data communication. According to the method, the transmitting end and the receiving end can generate the elliptic curve key pair through the trusted platform module and execute ECDH key negotiation; the sending end sends a detection packet, and the receiving end returns a response packet so as to dynamically adjust the size of the optimal transmission unit according to the network condition; a sending end flexibly selects a single round of AES-GCM encryption or AES-Twoish-Serpent triple chain encryption according to a security level score of a data block, so that the protection strength of sensitive data is ensured, and resource waste caused by excessive encryption of common data is avoided; a sending end generates independent session keys for different data blocks through a key derivation function, the forward security of a communication system is enhanced, an encryption mode and message authentication information are recorded at the frame head of the encrypted data block and encryption protection is carried out, and integrity verification of the transmission process is ensured.
Owner:BEIJING YOU TECHNOLOGY CO LTD

Secure enclave system-in-package

A Secure Enclave SiP (SE-SiP) is disclosed, which is an improvement to Trusted Platform Module (TPM) concepts, and in certain aspects, is a general-purpose next-generation security building block that provides all the security benefits of a system designed using a TPM, replaces the need to trust a general-purpose CPU chip vendor with the need to trust a much simpler more trustworthy configurable device, and replaces the need to trust the entire system motherboard manufacturer with the much more limited need to trust the SE-SiP manufacturer. It can provide privacy for the software and data sent to the system, resident on it, or retrieved from it, with respect to all parties—including the person / party in physical possession of the device.
Owner:OCTAVO SYSTEMS LLC

Method of backing up a key and method of restoring a key

This specification provides a method for backing up a key, comprising: deriving a hardware key based on a system state metric stored in the Platform Configuration Register (PCR) of a Trusted Platform Module (TPM); performing a first encryption and a second encryption on the target key to obtain a first ciphertext; performing the first encryption using the hardware key in the TPM, and performing the second encryption using a white-box encryption software module; and exporting the first ciphertext to obtain backup data of the target key.
Owner:ZHEJIANG ANT SECRET TECH CO LTD

Verification method, electronic device, storage medium and computer program product

The invention provides a verification method, electronic equipment, a storage medium and a computer program product. The method comprises one of the following steps that a server side sends first information containing identification information of a remote certificate (RA) agent and related information of a trusted platform module (TPM) device to a certificate authority (CA), and the first information is provided for the CA to a client side; the binding relation is used for verifying the RA agency and the TPM equipment corresponding to the server side. The RA agency and the TPM equipment are used for verifying the RA agency and the TPM equipment corresponding to the server side. And the server receives a remote attestation request which is sent by the client and at least comprises the random number, and sends a remote attestation report which is generated based on the random number and the identification information of the RA agent corresponding to the server to the client, so that the client verifies the RA agent corresponding to the server and the TPM equipment based on the remote attestation report. According to the invention, the client can accurately verify the credible state of the server.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Method, device, and computer program product for secure calling

The present disclosure relates to a method, a device, and a computer program product. The method includes: in response to receiving a calling command from a client, determining whether the calling command includes a security identifier. The method further includes, in response to determining that the calling command includes a security identifier, determining a security service corresponding to the security identifier in a firmware trusted platform module (FTPM). The method further includes performing security isolation and encryption processing on data related to the calling command by using the security service in the FTPM. In this way, the real intention of the calling command is concealed by the security identifier, which can reduce the possibility of attackers attacking or tampering with the calling command. Therefore, embodiments of the present disclosure enhance the security of the system, protect the device from potential attacks and damage, and prevent unauthorized accesses and malicious operations.
Owner:DELL PROD LP

Communications System with Remote Security for Host Devices

A communications system may include a server in a trusted environment and a host device in an untrusted environment. The host device may include storage and a trusted platform module (TPM). The server, a client binary, and the TPM may be used to secure data that is stored at, transmitted by, and / or received by the host device despite the host device being in an untrusted environment. As one example, the server may perform both a challenge-based identity verification and a state verification on the host device prior to transmitting a sensitive data payload to the host device. As another example, the host device may encrypt its storage using a storage key, may discard the storage key, and may interface with the host to provide the storage key to the host device to decrypt the storage after the server has verified the host device.
Owner:APPLE INC

Trusted platform module generated in an isolated region of a computing system

Systems, methods, and computer readable storage media described herein provide techniques for generating a virtual trusted platform module (vTPM) in an isolated region of a computing system. In an aspect, guest firmware of a virtual machine (VM) executing on device determines a state based on a configuration of the guest firmware. The guest firmware generates a vTPM based on the state and causes the vTPM to perform a cryptographic operation. In an aspect, the state is determined independent of state information external to the VM. In another aspect, the cryptographic operation includes unsealing a state of an operating system of the VM. The unsealed state is utilized to securely boot the operating system. In another aspect, the cryptographic operation includes sealing a state of an application hosted by the operating system. In another aspect, the VM is a confidential VM that isolates the vTPM from other services of the VM.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Renewal of a signed attestation artifact with limited usage of a trusted platform module

Techniques are described herein that are capable of renewing a signed attestation artifact with limited usage of a trusted platform module (TPM). Based on initiation of a cold boot of a host, attestation artifacts are received from the host. The attestation artifacts prove trust in a trusted execution environment (TEE) that runs on the host. The attestation artifacts include a public portion of an ephemeral cryptographic key (ECKeyPub), a public portion of a signing key (SKeyPub), and a signed key claim. The attestation artifacts are validated, and a signed attestation artifact, which includes the ECKeyPub and the SKeyPub, is generated and provided to the host. Based on a request to renew the signed attestation artifact including the signed attestation artifact, which includes the ECKeyPub and the SKeyPub, and further based on the TEE possessing the ephemeral cryptographic key, the signed attestation artifact is renewed during the cold boot session.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

TPM / VTPM-based cluster node remote authentication method and system

The invention relates to a cluster node remote authentication method and system based on TPM / VTPM. The problems that in the prior art, remote authentication service verification steps are complex, credible authentication support is insufficient, and dynamic authorization communication according to credibility is difficult to achieve are solved. The method comprises the following steps: S1, loading a TPM (Trusted Platform Module) or a VTPM (Virtual Trusted Platform Module) by a node in a starting process, measuring a kernel component in the starting process and generating a starting measurement report; s2, the node submits the starting measurement report to a remote certification service, and the remote certification service performs signature verification and structural integrity verification and extracts strategy information; s3, the remote attestation service inputs the strategy information into a strategy engine, and node credibility is judged; and S4, the node initiates a registration request to the cluster control plane by virtue of the communication credential. The method has the advantages that the node credibility verification based on the starting metric chain is realized, and the safety of the node adding process is improved; manual intervention is reduced; dynamic security authorization is realized, and the method can adapt to a multi-cloud and hybrid deployment scene.
Owner:SHANGHAI JIAOTONG UNIV +1

Initialization information storage virtualization system

An initialization information storage virtualization system includes a resource system that is coupled to a resource management system and that includes a processing system coupled to a System Control Processor (SCP) device. The SCP device creates a virtual initialization information storage and a virtual Trusted Platform Module (vTPM) in its secure memory subsystem. The SCP device then receives resource system initialization information and resource system initialization authentication information for the resource system from the resource management system, populates the virtual initialization information storage with the resource system initialization information, and populates the vTPM with the resource system initialization authentication information. When the SCP device receives an initialization information request from the processing system, the SCP device provides the resource system initialization information and the resource system initialization authentication information to the processing system.
Owner:DELL PROD LP

Enterprise authentication with virtualized TPM

Disclosed is a system and method for enterprise authentication. An enterprise cluster includes one or more enterprise appliances employing virtual machines managed by at least one hypervisor. Each virtual machine is associated with a respective virtual Trusted Platform Module (vTPM) secured by the hypervisor. An enterprise key (EK) is provided to the appliances of the enterprise cluster and imported into a vTPM associated with each appliance. When a user authentication request is received by a first appliance, the first appliance obtains a user encrypted key which was previously encrypted by a different vTPM on a different appliance with the same EK. The vTPM then signs a challenge based on decrypting the user encrypted key with the EK, completing the user authentication request.
Owner:IMPRIVATA

System and method for providing secure communication using ephemeral keys with a lifetime associated with a type of data being secured

A system for providing ephemeral keys for a cryptographic system includes a secure enclave configured to generate one or more ephemeral keys (EKs), where each EK of the one or more EKs has a lifetime associated with the respective EK, and one or more secured devices connected to the secure enclave, where each secured device of the one or more secured devices has a trusted platform module (TPM) configured to acquire at least one of the one or more EKs, where the TPM of each secured device further is configured to generate secured data in response to validating the lifetime of an associated EK by encrypting sensitive data with the associated EK, and where each secured device of the one or more secured devices is further configured to transmit the secured data to an entity external to the secured device.
Owner:TEXTRON INNOVATIONS INC

Communication method of TPM, TPM, board, and device

The trusted platform module (TPM) includes a TPM logic circuit, a receive buffer, a TPM register, and one or more processors. The TPM register is a storage space obtained by dividing a memory of the TPM. The TPM logic circuit receives a TPM register write command from a host and stores a payload of the write command into the receive buffer. The payload of the TPM register write command is a part or all of content forming TPM command data. When data in the receive buffer reaches a first data amount threshold, the processor dumps the data in the receive buffer into the TPM register. When all the content of the TPM command data is stored in the TPM register, the one or more processors execute the TPM command data.
Owner:HUAWEI TECH CO LTD

Data processing system for trusted computing

A data processing system (1) comprises a processor unit (2), at least two selectively connectable mass storage devices (6i), and a trusted platform module (8) with at least two switchable register banks (PCRi) or at least two switchable physical or virtual trusted platform modules (8i). One of the at least two register banks (PCRi) or one of the individual trusted platform modules (8i) is activated according to the connected mass storage device (6i), or one of the individual trusted platform modules (8i) is connected together with the respective mass storage device (6i).
Owner:MUSE ELECTRONICS GMBH

Integrated trust platform modules, device attestation, and device management for live zero trust network access

Systems, apparatus, and methods for device attestation are disclosed. An example apparatus includes communication circuitry to obtain a request to access an organization resource and a client certificate including a device identifier and a certificate authority issuer, at least one memory storing machine readable instructions, and programmable circuitry to execute the machine readable instructions to determine that the certificate authority issuer is a trusted issuer, compare the device identifier against device identifiers in a database storing trusted device identifiers of an organization protecting the organization resource, in response to determining that an instance of the device identifier exists in the database, determine that a client device associated with the device identifier is authorized to access the organization resource based on checking a policy of the organization, and grant the client device access to the organization resource.
Owner:JAMF SOFTWARE LLC

Staged measured boot sequence of a computer

In a computer or other electronic device that uses a boot process, it is desirable to allow updating of boot images without impacting objects sealed using trusted keys. In one embodiment, multiple platform configuration registers (PCRs) within a Trusted Platform Module (TPM) are used in association with the booting process. A first PCR can be associated with a first boot image and a second PCR can be associated with a second boot image. A change in the first boot image results in a change of the first PCR value, but the second PCR value can remain unchanged. Accordingly, any objects that are sealed using a trusted key as the second PCR value need not be resealed. Addition PCRs can be added for additional boot images.
Owner:AMAZON TECH INC

Shared secret key based on system components

Systems and methods for establishing a shared secret (or pre-shared key (PSK)) between a Chipset and a trusted platform module (TPM) of a computing device that can be used to encrypt all communication between those two components. The PSK may include two (or more) factors that must both be available to the Chipset in order to communicate with the TPM. The first factor may originate from an Endpoint Security Controller (EpSC) and the second factor may originate from within the Chipset. The PSK may only be regenerated by combining multiple segments of a key, referred to as “factors,” that may be separately assigned to different components of a computing device. If all factors are not provided to a TPM upon boot-up, communication between the Chipset and the TPM may be disabled.
Owner:HEWLETT PACKARD DEVELOPMENT COMPANY LP

A trusted root-based full-link data security protection system and method

The application discloses a kind of whole-link data security protection system and method based on trusted root, belong to the technical field of information security;Link data transmission structure includes several substructures, substructure includes operating system, application program, internal hardware and transmission channel as encryption object, encrypt encryption object, and encryption content is as follows: set trusted platform module as trusted root encryption tool;Operating system includes identity authentication password and authority management;Application program encryption includes login password and hierarchical application lock;Internal hardware includes BIOS, hard disk and memory data encryption;Communication encryption determination module is arranged at both ends of transmission channel;The application adopts the above system and method, and based on trusted platform module (TPM) as hardware trusted root realizes operating system identity authentication and authority management, system application program hierarchical encryption mechanism, hardware layer data encryption module and transmission channel double-end encryption process.
Owner:SHANGHAI SHIYUE COMPUTER TECH CO LTD