Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

138 results about "Trusted Platform Module" patented technology

Trusted Platform Module (TPM, also known as ISO/IEC 11889) is an international standard for a secure cryptoprocessor, a dedicated microcontroller designed to secure hardware through integrated cryptographic keys.

Secure cryptographic secret bootstrapping in a provider network

Techniques for secure cryptographic secret bootstrapping balance the need to quickly and conveniently restore cryptographic secrets to server computers in the event of an outage with the need for security. Before the outage, a server computer uses a trusted platform module of the server computer to seal an encryption key used to encrypt a secret stored at the server computer. In response to the outage, the server computer restores the secret by using the trusted platform module to unseal the encryption key and then using the unsealed encryption key to decrypt the encrypted secret. The techniques can be used to restore cryptographic secrets rapidly and securely to a cluster of server computers used for cryptographic operations in a provider network without the overhead of safe room procedures.
Owner:AMAZON TECH INC

Dual authentication key negotiation method for vehicle networking commuting

The invention belongs to the field of identity authentication in the Internet of Vehicles, and particularly relates to an Internet of Vehicles commuting-oriented dual authentication key negotiation method, which specifically comprises the following steps of: constructing an Internet of Vehicles system which comprises a trusted center, a roadside unit and a vehicle, and publishing initial system parameters by the trusted center; a vehicle, a user and a roadside unit respectively complete identity registration and verification to a credible center, the credible center respectively distributes corresponding identity verification key parameters to the vehicle and the roadside unit, and a driver logs in through a biological key; the credible platform module integrity evaluation report of the vehicle is verified, the behavior score of the vehicle is calculated according to the historical behavior information of the vehicle, and the behavior score is composed of a travel score and an interaction score; after the session key negotiation process between the roadside unit and the vehicles is completed, the roadside unit acts as a main authentication node to realize authentication between the vehicles by using the key information generated by the vehicles, and only after the authentication is completed, an authentication result is uploaded to a trusted center for recording. According to the invention, each entity in the Internet of Vehicles system can be ensured to communicate safely, and the calculation overhead and the communication overhead are reduced, so that the authentication efficiency is improved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Management controller registration using a trusted platform module

Methods and systems for registering a management controller of a data processing system with a server are disclosed. To register a management controller, an identifier for the management controller may be cryptographically signed using a private key of a public private key pair kept secret by a trusted platform module (TPM). The signed identifier may be provided to the server and the sever may utilize a public key of the public private key pair to verify the signed identifier was signed by a trusted entity. If the signed identifier is verified by the server, the server may register the management controller as associated with the data processing system and as a trusted entity to manage operation of hardware resources of the data processing system. The management controller may subsequently utilize an out of band communication channel to interact with the server to manage the operation of the data processing system.
Owner:DELL PROD LP

Method and device for installing certificate on basis of encryption and decryption of contract certificate private key

Disclosed are a method and device for installing a certificate on the basis of encryption and decryption of a contract certificate private key for an electric vehicle communication controller. The method for installing the certificate comprises: a step in which the electric vehicle communication controller transmits, to a secondary actor, a certificate installation request message signed with a private key associated with a manufacturer's provisioning certificate; and a step of receiving, from the secondary actor, a certificate installation response message signed with a private key associated with a leaf certificate of a certificate provisioning service, wherein an encrypted private key element of the certificate installation response message stores a private key belonging to a new contract certificate which is encrypted for the electric vehicle communication controller without a trust platform module, the private key belonging to the new contract certificate is encrypted with AES-GCM-256 on the basis of an encryption key which is entered from a public key of the manufacturer's provisioning certificate and generated through an ECDH protocol, and the private key encrypted with the AES-GCM-256 is included in a ciphertext at 528-bits or 448-bits after an initial initialization vector of a contract certificate data packet.
Owner:HYUNDAI MOTOR CO LTD +2

Renewal of a signed attestation artifact with limited usage of a trusted platform module

Techniques are described herein that are capable of renewing a signed attestation artifact with limited usage of a trusted platform module (TPM). Based on initiation of a cold boot of a host, attestation artifacts are received from the host. The attestation artifacts prove trust in a trusted execution environment (TEE) that runs on the host. The attestation artifacts include a public portion of an ephemeral cryptographic key (ECKeyPub), a public portion of a signing key (SKeyPub), and a signed key claim. The attestation artifacts are validated, and a signed attestation artifact, which includes the ECKeyPub and the SKeyPub, is generated and provided to the host. Based on a request to renew the signed attestation artifact including the signed attestation artifact, which includes the ECKeyPub and the SKeyPub, and further based on the TEE possessing the ephemeral cryptographic key, the signed attestation artifact is renewed during the cold boot session.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Data encryption system and method based on 5G communication module

The invention relates to the technical field of 5G communication modules, in particular to a data encryption system based on a 5G communication module and a method thereof.The data encryption system comprises a terminal device module, a power private network eSIM, an X.509 digital certificate issued by a CA and a private key are pre-installed in a terminal device and stored in a trusted execution environment or a trusted platform module, firmware integrity verification can be completed after power-on, and the terminal device module is connected with the terminal device module. TLS bidirectional handshake with an identity authentication gateway is initiated through the eSIM and the digital certificate so as to establish an encryption channel with a session identifier; and the identity authentication gateway is used for receiving and verifying eSIM authentication information and an equipment certificate from the terminal equipment, and generating a unique session identifier after finishing TLS bidirectional authentication. In the invention, through combining the eSIM network authentication of the electric power private network and the X.509 certificate issued by the CA, TLS bidirectional handshake between the equipment and the identity gateway is realized, and dual authentication between a physical link layer and an application link layer is realized; and risks of equipment counterfeiting, malicious man-in-the-middle access and the like are completely eradicated.
Owner:JIANGSU FULIAN COMM TECH CO LTD

Method and equipment for realizing firmware trusted platform module on RISC-V platform

The invention provides a method and equipment for realizing a firmware trusted platform module on an RISC-V platform, the functions of the trusted platform module are realized without extra hardware extension through cooperation of software and firmware in combination with a PMP mechanism, a PUF and a hardware timer of the RISC-V platform, and the realization mode comprises an isolation execution process, a hardware execution process and a hardware execution process. An fTPM isolation memory area is configured in the starting stage through a PMP mechanism, and access to fTPM codes and data is limited; a static data protection process: generating a device key by using a PUF (Physical Unclonable Function), and carrying out encryption and integrity protection on fTPM persistent data in combination with a Flash locking mechanism; the trusted starting process comprises the steps of adopting a DME mechanism, ensuring and maintaining the integrity of a starting metric chain and supporting a PCR register function; the efficient communication process comprises the steps of dynamically adjusting the PMP permission of a shared memory area through a dynamic permission exchange page mechanism, and realizing zero-copy communication between the fTPM and an operating system or an application program; and the secure clock process comprises the step of constructing an independent trusted clock source based on a hardware timer of the RISC-V platform.
Owner:WUHAN UNIV

Method and device for verifying physical consistency of trusted supply chain and command of energy storage station

The invention provides an energy storage station trusted supply chain and command physical consistency verification method and device. The method comprises the following steps: setting a trusted platform module or a security element in a key device of the energy storage station, and generating a device trusted state identifier; adding a time quality identifier and a source signature to the measurement and state data; identity authentication, protocol analysis, object address and parameter range verification and rate constraint verification are carried out on the remote control instruction; generating a feasible region according to state estimation and equipment constraint, and performing executable judgment on the instruction; when any link does not meet the preset condition, switching to a verifiable security state and blocking a remote write-in path; and when the command firewall and the physical consistency check are both passed, a control instruction is issued to the converter control device and the battery management system, and power, reactive power and grid-connected and off-grid control of the energy storage station is executed. According to the application, supply chain credible closed loop, metering linkage access and double-loop instruction verification can be realized, and failure safety and verifiable evidence obtaining are supported.
Owner:BEIJING GOLDWIND CARBON NEUTRAL ENERGY CO LTD

Virtualizing discrete and migratable trusted platform modules (TPMS)

Systems and methods are provided for implementing virtualization of discrete and migratable cryptographic processors (e.g., trusted platform modules (“TPMs”)). In examples, an orchestrator in a control plane causes migration of a first cryptographic processor emulator (e.g., a TPM emulator) that has been instantiated on a first platform root of trust (“PROT”) to a second PROT, by requesting secret data (e.g., an endorsement seed associated with the cryptographic processor emulator, sealed secrets, etc.) stored in a first memory in the first PROT. The orchestrator receives the secret data, instantiates a second cryptographic processor emulator on the second PROT based on the secret data, and transfers the secret data to a second memory in the second PROT. The orchestrator instructs the cryptographic processor emulator on the first PROT to delete the secret data from the first memory, and sends a status of the migration to a requesting device that requested the migration.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Device control method, device, storage medium and computer program product

The invention discloses an equipment control method, equipment, a storage medium and a computer program product, and relates to the technical field of computers, the method comprises the following steps: when a sleep instruction is received, creating a trusted execution environment, and exporting a dynamic session state plaintext from a trusted platform module into the trusted execution environment; encrypting the dynamic session state plaintext by using a pre-generated dormancy binding key in the trusted execution environment to obtain a dynamic session state ciphertext, and calculating a verification value corresponding to the dynamic session state ciphertext; creating a dormant mirror image based on the dynamic session state ciphertext and the corresponding check value in the trusted execution environment, and storing the dormant mirror image in a nonvolatile storage medium; and triggering a sleep operation. The awakening efficiency of the device from the dormant state is improved.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Clustered virtual trusted platform module domain services with a redirector / router service system

An information handling system may validate a connection request received from a trusted platform module (TPM)-virtual (vTPM) module according to a policy, wherein the connection request originated from a virtual machine associated with the TPM-vTPM module which consumes services from a clustered vTPM domain service. In response to determining that the connection request is valid based on the policy, the system may determine the vTPM domain service associated to the TPM-vTPM module, and determine whether to route or redirect the connection request according to policy. In response to determining that the connection request is to be redirected, the system may transmit a response to the TPM-vTPM module, wherein the response includes redirect information to the vTPM domain service. In response to determining that the connection request is to be routed, the system may route the connection request to the vTPM domain service.
Owner:DELL PROD LP

External field equipment trusted access method based on non-addressable stealth gateway

The invention discloses an external field equipment trusted access method based on a non-addressable stealth gateway, which relates to the technical field of network security access, and comprises the following four steps: in a manufacturing period and first access, a certificate authorization machine binds equipment identity and trusted platform module measurement, policy decision point decision, policy execution point implementation and policy subset loading; initiating from the outside of the equipment, establishing an end-to-end trusted channel with the center, and performing inward isolation and transparent bearing on rear-end real services; updating strategies, algorithms and secret keys on line under the control of a unified strategy library; according to the method, the attack surface is reduced, the transformation cost is reduced, non-stop treatment is ensured, the encrypted traffic can be observed and audited, only trusted equipment can reach the center through a trusted channel, and event linkage right descending and certificate state linkage treatment are supported.
Owner:HANGZHOU XENON TECHNOLOGY CO LTD

Container operation environment credible control method and device, equipment and medium

The invention relates to a trusted control method and device for a container operation environment, equipment and a medium, and belongs to the technical field of computer security. A lightweight virtual machine is created on a host, a virtual trusted platform module is integrated in the lightweight virtual machine, a trusted startup process is executed in a startup process, and a trusted measurement result is calculated; submitting a trusted measurement result to a remote attestation server so as to verify the trusted state of the lightweight virtual machine; after the verification is passed, receiving an authorization response issued by the remote certification server; requesting to download the target encryption container mirror image from the container mirror image warehouse by using the download token, and downloading the target encryption container mirror image after the verification is passed; and decrypting the target encryption container mirror image by using the decryption key, and loading the decrypted target encryption container mirror image to the container operation environment to start the corresponding target container. A trusted closed loop is formed, and it is ensured that the container operation environment has safety and credibility in the initialization stage.
Owner:JINGYI ZHIYUAN (WUHAN) INFORMATION TECH CO LTD

Security communication platform and method constructed based on security control and trusted network connection

The invention relates to the technical field of network security and communication, in particular to a security communication platform and method constructed based on security control and trusted network connection. The security communication platform comprises a security management and control center platform, a trusted password service platform, a trusted network connection optimization architecture, a distributed network architecture, a security shared memory mechanism, an application cluster system and a trusted VPN function module, the security management and control center platform is deployed in a core network, and a trusted platform module is arranged in the security management and control center platform as a global trusted root. By constructing an integrated platform of the trusted security management and control system and the secure and trusted intelligent VPN, triple security assurance of trusted access terminal, trusted network connection and trusted data transmission can be realized, and the requirements of a key information system on high security, high reliability and high adaptation of network communication are met; the defects of the traditional VPN in the aspects of attack surface control, encryption capability, identity authentication, systematic defense and the like are overcome.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Clustered virtual trusted platform module domain services system

An information handling system includes a virtual trusted platform module (TPM) consumer associated with a virtual machine. The virtual TPM (vTPM) consumer may consume TPM services from a clustered vTPM domain service and determine the connection information of the vTPM domain service. The vTPM consumer transmits a connection request for a TPM operation request to the vTPM domain service, wherein the connection request includes a payload in addition to the connection information. The consumer may also receive a response associated with the TPM operation request from the vTPM domain service.
Owner:DELL PROD LP

Method and device for installing certificate on basis of encryption and decryption of contract certificate private key

Disclosed are a method and device for installing a certificate on the basis of encryption and decryption of a contract certificate private key for an electric vehicle communication controller. The method for installing the certificate comprises: a step in which the electric vehicle communication controller transmits, to a secondary actor, a certificate installation request message signed with a private key associated with a manufacturer's provisioning certificate; and a step of receiving, from the secondary actor, a certificate installation response message signed with a private key associated with a leaf certificate of a certificate provisioning service, wherein an encrypted private key element of the certificate installation response message stores a private key belonging to a new contract certificate which is encrypted for the electric vehicle communication controller without a trust platform module, the private key belonging to the new contract certificate is encrypted with AES-GCM-256 on the basis of an encryption key which is entered from a public key of the manufacturer's provisioning certificate and generated through an ECDH protocol, and the private key encrypted with the AES-GCM-256 is included in a ciphertext at 528-bits or 448-bits after an initial initialization vector of a contract certificate data packet.
Owner:HYUNDAI MOTOR CO LTD +2

Systems and methods for passwordless logon

In one embodiment, a method receives a secret and a passwordless login request using a credential provider of the client device. The method pairs the credential provider of the client device with a trusted platform module (TPM) associated with a computing device. The method encrypts, using the TPM of the computing device, the secret with a hardware-bound key associated with the computing device. The method receives, from the client device, a push notification associated with the passwordless login request. The method obtains, from the client device, biometric authentication data and a nonce encrypted with a public key. The method validates a proximity of the biometric authentication data and determine a decrypted nonce by decrypting the nonce using a private key associated with the client device. The method validates the decrypted nonce with the secret. In response to determining the decrypted nonce is valid, the method approves the passwordless login request.
Owner:CISCO TECHNOLOGY INC

Virtualizing secure vault of data processing unit for secure hardware security module for hosts

A system and method of securing and virtualizing firmware trusted platform modules (TPMs) for virtualizing a hardware security module (HSM) for a host within a network fabric is provided. The system and method include operably coupling a set of components associated with a host comprising a data processing unit (DPU) secure vault and a firmware trusted platform module (TPM). The firmware TPM is configured as a virtual firmware TPM. The DPU secure vault secures the virtual firmware TPM into one or more virtual firmware TPMs based on one or more partitions configured with the DPU secure vault. A virtual TPM manager communicatively coupled to the DPU secure vault manages one or more virtual TPMs for hosting a set of Virtual Machines (VMs) or Containers.
Owner:CISCO TECHNOLOGY INC

Machine learning-based financial behavior prediction and adaptive budget optimization system

A computer-implemented system for predicting financial behavior and adaptive budget optimization based on machine learning, consisting of: a multitude of distributed processing nodes to enable low-latency communication between the nodes; a transaction data ingestion processor configured to establish authenticated connections with a plurality of financial data sources, wherein the ingestion module is further configured to normalize received transaction records into a standardized schema comprising at least a merchant identifier, a transaction category, a timestamp, a transaction amount, and optional geolocation metadata; a preprocessing engine comprising a classification sub-module trained through supervised learning to assign transaction categories based on merchant identifiers and context attributes, and a feature extraction sub-module configured to compute temporal, statistical, and behavioral feature vectors from the normalized transaction data; a prediction control unit comprising a plurality of lightweight neural network architectures, including at least one recurrent neural network (RNN) and at least one attention-based temporal model, the prediction control unit configured to predict short-term and medium-term output trends by sequentially processing the feature vectors; a budget optimization computation unit configured to solve multi-constraint budget allocation problems using a hybrid approach comprising a primary linear programming solver and an additional heuristic optimization technique, wherein the budget optimization computation unit is further configured to dynamically adjust budget allocations based on updated forecasts and user-defined constraints; a security subsystem configured for encryption at rest and in transit, as well as secure key storage in a hardware-based Trusted Platform Module (TPM); and a user interaction interface configured to display budget recommendations and forecasted spending trends through at least one web application, mobile application, or hardware device interface.
Owner:GOGINENI ANILA

Computer system for failing a secure boot in a case tampering event

A computer system for failing a secure boot in a case tampering event comprises a microcontroller unit (MCU); a trusted platform module (TPM), for generating random bytes for a secure boot of the computer system; a bootloader, for storing information comprising the random bytes in the MCU and at least one hardware of the computer system and performing the secure boot, wherein the TPM is comprised in the bootloader; an operating system (OS), for performing the secure boot; and at least one sensor, coupled to the MCU, for detecting a case tampering event, and transmitting a signal for triggering a deletion of the random bytes, if the case tampering event happens. The MCU performs the operation of deleting the random bytes stored in the MCU and the at least one hardware according to a power supply, in response to the signal.
Owner:MOXA INC

Power Internet of Things gateway management method and device, server and storage medium

The invention provides a power Internet of Things gateway management method and device, a server and a storage medium, and relates to the technical field of computers. The method is applied to a container arrangement platform, and the container arrangement platform carries out independent containerization deployment on services and / or applications on power internet of things gateway equipment based on a container technology to obtain a plurality of containers. The container arrangement platform monitors the operation states of a plurality of containers; when it is monitored that the target container in the multiple containers is abnormal, credible restarting and / or credible repairing are / is conducted on the target container based on the credible platform module. By means of containerized deployment, application and / or service isolation is achieved, the safety of the system is improved, system modularization is achieved in a containerized mode, and the expansibility of the system and the utilization rate of hardware resources are improved. On the basis of containerized deployment, hardware-level security protection measures are realized by using the trusted platform module, so that the operating environment in the container is strictly controlled, the security is further improved, and the safe and stable operation of the Internet of Things gateway is ensured.
Owner:GUANGDONG POWER GRID CO LTD CHAOZHOU POWER SUPPLY BUREAU +1

Methods and systems for using smart network interface cards to secure data transmission between an initiator host running an object and a target host equipped with a disaggregated hardware device that satisfies hardware specifications of the object

This disclosure is directed to methods and systems that establish a secure data channel between a host and a disaggregated hardware device (“DHD”) of a data center. The system comprises an initiator host that runs objects, such as virtual machines and containers. The host includes an initiator smart network interface card (“SNIC”). The initiator SNIC includes a virtual device, a trust platform module (“TPM”) and a security engine. The system also comprises a target host equipped with a DHD and a target SNIC. The target SNIC includes a TPM and a security engine. The TPM and the security engine of the initiator SNIC and the TPM and the security engine of the target SNIC establish a secure data channel between an object running on the host and the DHD.
Owner:VMWARE INC

A device control method, device, storage medium, and computer program product

The application discloses a device control method, device, storage medium and computer program product, relates to the computer technical field, and the method comprises the following steps: when receiving a hibernation instruction, a trusted execution environment is created, and a dynamic session state plaintext is exported from a trusted platform module to the trusted execution environment; the dynamic session state plaintext is encrypted by using a pre-generated hibernate binding key in the trusted execution environment to obtain dynamic session state ciphertext, and a check value corresponding to the dynamic session state ciphertext is calculated; a hibernate image is created based on the dynamic session state ciphertext and the corresponding check value in the trusted execution environment, and the hibernate image is stored in a nonvolatile storage medium; and a hibernate operation is triggered. The application improves the wake-up efficiency of the device from the hibernate state.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Verifying the rendering of video content at client devices using trusted platform modules

Systems and methods for verifying the rendering of video content on information resources are provided herein. A server can receive, from a target client device, a tracking message purporting to relate to delivery of a target content item; determine whether the tracking message contains an identifier of a sending device that sent the tracking message; determine whether the sending device and the target client device are the same device; if the sending client device and the target client device are the same device: recover, from the tracking message, information about at least a portion of a frame of a content item processed by a trusted platform module of the client device; and compare the at least a portion of the frame of the content item processed by a trusted platform module of the client device with a target content item.
Owner:GOOGLE LLC

Full-link data security protection system and method based on trusted root

The invention discloses a full-link data security protection system and method based on a trusted root, and belongs to the technical field of information security. The link data transmission structure comprises a plurality of substructures, each substructure comprises an operating system, an application program, internal hardware and a transmission channel which are used as encryption objects, the encryption objects are encrypted, and the encryption content is as follows: setting a trusted platform module as a trusted root encryption tool; the operating system comprises an identity authentication password and authority management; the application program encryption comprises a login password and a hierarchical application lock; the internal hardware comprises data encryption of a BIOS, a hard disk and a memory; communication encryption measurement modules are arranged at the two ends of the transmission channel; by the adoption of the system and method, the trusted platform module (TPM) serves as a hardware trusted root, and the processes of operating system identity authentication and authority management, a system application program hierarchical encryption mechanism, a hardware layer data encryption module and transmission channel double-end encryption are achieved.
Owner:SHANGHAI SHIYUE COMPUTER TECH CO LTD

Key updating method and device, storage medium, terminal and system

The invention discloses a secret key updating method and device, a storage medium, a terminal and a system, relates to the technical field of data encryption transmission, and mainly aims to solve the problem of low timeliness and safety of existing secret key updating. The method mainly comprises the steps of determining key use state parameters according to key associated data; under the condition that the key use state parameter is greater than a preset use state parameter threshold, generating a quantum key updating request according to the key associated data, and generating an encryption key through a physical unclonable security component; encrypting the quantum key updating request according to the encryption key, and sending the encrypted quantum key updating request to the server, so that the server generates and returns a newly added key according to the quantum key updating request; and receiving a key update reply sent by the server in an encrypted manner, decrypting the key update reply through the physical unclonable security component, and storing the newly-added key obtained by decryption to the trusted platform module. The method is mainly used for key updating.
Owner:BEIJING XUEDIRUANJIAN DEVELOPMENT CO LTD

Methods and computing devices for accessing TPM in a computing device

Methods and apparatuses for accessing a trusted platform module (TPM) are disclosed. In an implementation, a method comprises receiving, by a virtual machine monitor from a first virtual machine in at least one virtual machine, a first notification message for requesting to access the TPM. In response to determining that the TPM is unlocked, locking, by the virtual machine monitor, the TPM to allow the TPM to be accessed only by the first virtual machine, and sending a first decision message to the first virtual machine indicating the first virtual machine to start performing a first access operation on the TPM. Receiving, by the virtual machine monitor, a second notification message from the first virtual machine, and unlocking, by the virtual machine monitor, the TPM in response to the second notification message.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Construction method of trusted confidential channel based on AMD SEV trusted confidential virtual machine

The invention discloses a method for constructing a trusted confidential channel based on an AMD SEV trusted confidential virtual machine, which relates to the field of computer technology and information security, and consists of a unique confidential virtual machine starting scheme, an extended TLS protocol and support components thereof. Specifically, the invention designs a method for constructing a trusted confidential channel based on an AMD SEV trusted confidential virtual machine. According to the method, by means of a virtual trusted platform module vTPM, the running state of an AMD SEV trusted confidential virtual machine is obtained to serve as a trusted credential, and a TLS protocol is expanded to support establishment of a confidential channel and verify the trusted credentials of two communication parties at the same time. Meanwhile, in order to support the method, a corresponding support component is expanded in the confidential virtual machine, so that a user load running in the confidential virtual machine can be seamlessly integrated with the method, and a method for safely and reliably establishing a trusted confidential channel with an application running in the remote confidential virtual machine is provided for the user load.
Owner:BEIJING JIAOTONG UNIV

Methods, devices, and computer program products for verifying IoT device

Embodiments of the present disclosure include a method, a device, and a computer program product for verifying an Internet of Things (IoT) device. The method includes, in response to boot of a trusted platform module (TPM) simulator, establishing an environment similar to the TPM in a trusted execution environment (TEE) of the IoT device. The method further includes sending, by a direct anonymous attestation (DAA) simulator in the TEE, an access request to an application in the IoT device. In addition, the method further includes, in response to receiving a response received by the application from a cloud platform, executing, by the TPM simulator, verification for the IoT device. In some embodiments, required TPM security services are simulated in the TEE of IoT devices, thereby minimizing the exposure of user privacy information while completing the verification and ensuring the security of verification.
Owner:DELL PROD LP

Scalable trusted platform module in programmable network interface devices

An apparatus includes a host interface, a network interface, and a programmable circuitry communicably coupled to the host interface and the network interface. The programmable circuitry can include one or more processors to implement network interface functionality, and a discrete trusted platform module (dTPM) to enable the one or more processors to establish a secure boot mechanism for the apparatus, wherein the one or more processors are to instantiate a virtual TPM (vTPM) manager that is associated with the dTPM, the vTPM manager to host vTPM instances corresponding to one or more virtualized environments hosted on at least one of the programmable circuitry or a host device communicable coupled to the apparatus.
Owner:INTEL CORP