Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

104 results about "Trusted Platform Module" patented technology

Trusted Platform Module (TPM, also known as ISO/IEC 11889) is an international standard for a secure cryptoprocessor, a dedicated microcontroller designed to secure hardware through integrated cryptographic keys.

Management controller registration using a trusted platform module

Methods and systems for registering a management controller of a data processing system with a server are disclosed. To register a management controller, an identifier for the management controller may be cryptographically signed using a private key of a public private key pair kept secret by a trusted platform module (TPM). The signed identifier may be provided to the server and the sever may utilize a public key of the public private key pair to verify the signed identifier was signed by a trusted entity. If the signed identifier is verified by the server, the server may register the management controller as associated with the data processing system and as a trusted entity to manage operation of hardware resources of the data processing system. The management controller may subsequently utilize an out of band communication channel to interact with the server to manage the operation of the data processing system.
Owner:DELL PROD LP

Method and device for installing certificate on basis of encryption and decryption of contract certificate private key

Disclosed are a method and device for installing a certificate on the basis of encryption and decryption of a contract certificate private key for an electric vehicle communication controller. The method for installing the certificate comprises: a step in which the electric vehicle communication controller transmits, to a secondary actor, a certificate installation request message signed with a private key associated with a manufacturer's provisioning certificate; and a step of receiving, from the secondary actor, a certificate installation response message signed with a private key associated with a leaf certificate of a certificate provisioning service, wherein an encrypted private key element of the certificate installation response message stores a private key belonging to a new contract certificate which is encrypted for the electric vehicle communication controller without a trust platform module, the private key belonging to the new contract certificate is encrypted with AES-GCM-256 on the basis of an encryption key which is entered from a public key of the manufacturer's provisioning certificate and generated through an ECDH protocol, and the private key encrypted with the AES-GCM-256 is included in a ciphertext at 528-bits or 448-bits after an initial initialization vector of a contract certificate data packet.
Owner:HYUNDAI MOTOR CO LTD +2

Method and equipment for realizing firmware trusted platform module on RISC-V platform

The invention provides a method and equipment for realizing a firmware trusted platform module on an RISC-V platform, the functions of the trusted platform module are realized without extra hardware extension through cooperation of software and firmware in combination with a PMP mechanism, a PUF and a hardware timer of the RISC-V platform, and the realization mode comprises an isolation execution process, a hardware execution process and a hardware execution process. An fTPM isolation memory area is configured in the starting stage through a PMP mechanism, and access to fTPM codes and data is limited; a static data protection process: generating a device key by using a PUF (Physical Unclonable Function), and carrying out encryption and integrity protection on fTPM persistent data in combination with a Flash locking mechanism; the trusted starting process comprises the steps of adopting a DME mechanism, ensuring and maintaining the integrity of a starting metric chain and supporting a PCR register function; the efficient communication process comprises the steps of dynamically adjusting the PMP permission of a shared memory area through a dynamic permission exchange page mechanism, and realizing zero-copy communication between the fTPM and an operating system or an application program; and the secure clock process comprises the step of constructing an independent trusted clock source based on a hardware timer of the RISC-V platform.
Owner:WUHAN UNIV

Method and device for verifying physical consistency of trusted supply chain and command of energy storage station

The invention provides an energy storage station trusted supply chain and command physical consistency verification method and device. The method comprises the following steps: setting a trusted platform module or a security element in a key device of the energy storage station, and generating a device trusted state identifier; adding a time quality identifier and a source signature to the measurement and state data; identity authentication, protocol analysis, object address and parameter range verification and rate constraint verification are carried out on the remote control instruction; generating a feasible region according to state estimation and equipment constraint, and performing executable judgment on the instruction; when any link does not meet the preset condition, switching to a verifiable security state and blocking a remote write-in path; and when the command firewall and the physical consistency check are both passed, a control instruction is issued to the converter control device and the battery management system, and power, reactive power and grid-connected and off-grid control of the energy storage station is executed. According to the application, supply chain credible closed loop, metering linkage access and double-loop instruction verification can be realized, and failure safety and verifiable evidence obtaining are supported.
Owner:BEIJING GOLDWIND CARBON NEUTRAL ENERGY CO LTD

Virtualizing discrete and migratable trusted platform modules (TPMS)

Systems and methods are provided for implementing virtualization of discrete and migratable cryptographic processors (e.g., trusted platform modules (“TPMs”)). In examples, an orchestrator in a control plane causes migration of a first cryptographic processor emulator (e.g., a TPM emulator) that has been instantiated on a first platform root of trust (“PROT”) to a second PROT, by requesting secret data (e.g., an endorsement seed associated with the cryptographic processor emulator, sealed secrets, etc.) stored in a first memory in the first PROT. The orchestrator receives the secret data, instantiates a second cryptographic processor emulator on the second PROT based on the secret data, and transfers the secret data to a second memory in the second PROT. The orchestrator instructs the cryptographic processor emulator on the first PROT to delete the secret data from the first memory, and sends a status of the migration to a requesting device that requested the migration.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Device control method, device, storage medium and computer program product

The invention discloses an equipment control method, equipment, a storage medium and a computer program product, and relates to the technical field of computers, the method comprises the following steps: when a sleep instruction is received, creating a trusted execution environment, and exporting a dynamic session state plaintext from a trusted platform module into the trusted execution environment; encrypting the dynamic session state plaintext by using a pre-generated dormancy binding key in the trusted execution environment to obtain a dynamic session state ciphertext, and calculating a verification value corresponding to the dynamic session state ciphertext; creating a dormant mirror image based on the dynamic session state ciphertext and the corresponding check value in the trusted execution environment, and storing the dormant mirror image in a nonvolatile storage medium; and triggering a sleep operation. The awakening efficiency of the device from the dormant state is improved.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

External field equipment trusted access method based on non-addressable stealth gateway

The invention discloses an external field equipment trusted access method based on a non-addressable stealth gateway, which relates to the technical field of network security access, and comprises the following four steps: in a manufacturing period and first access, a certificate authorization machine binds equipment identity and trusted platform module measurement, policy decision point decision, policy execution point implementation and policy subset loading; initiating from the outside of the equipment, establishing an end-to-end trusted channel with the center, and performing inward isolation and transparent bearing on rear-end real services; updating strategies, algorithms and secret keys on line under the control of a unified strategy library; according to the method, the attack surface is reduced, the transformation cost is reduced, non-stop treatment is ensured, the encrypted traffic can be observed and audited, only trusted equipment can reach the center through a trusted channel, and event linkage right descending and certificate state linkage treatment are supported.
Owner:HANGZHOU XENON TECHNOLOGY CO LTD

Container operation environment credible control method and device, equipment and medium

The invention relates to a trusted control method and device for a container operation environment, equipment and a medium, and belongs to the technical field of computer security. A lightweight virtual machine is created on a host, a virtual trusted platform module is integrated in the lightweight virtual machine, a trusted startup process is executed in a startup process, and a trusted measurement result is calculated; submitting a trusted measurement result to a remote attestation server so as to verify the trusted state of the lightweight virtual machine; after the verification is passed, receiving an authorization response issued by the remote certification server; requesting to download the target encryption container mirror image from the container mirror image warehouse by using the download token, and downloading the target encryption container mirror image after the verification is passed; and decrypting the target encryption container mirror image by using the decryption key, and loading the decrypted target encryption container mirror image to the container operation environment to start the corresponding target container. A trusted closed loop is formed, and it is ensured that the container operation environment has safety and credibility in the initialization stage.
Owner:JINGYI ZHIYUAN (WUHAN) INFORMATION TECH CO LTD

Security communication platform and method constructed based on security control and trusted network connection

The invention relates to the technical field of network security and communication, in particular to a security communication platform and method constructed based on security control and trusted network connection. The security communication platform comprises a security management and control center platform, a trusted password service platform, a trusted network connection optimization architecture, a distributed network architecture, a security shared memory mechanism, an application cluster system and a trusted VPN function module, the security management and control center platform is deployed in a core network, and a trusted platform module is arranged in the security management and control center platform as a global trusted root. By constructing an integrated platform of the trusted security management and control system and the secure and trusted intelligent VPN, triple security assurance of trusted access terminal, trusted network connection and trusted data transmission can be realized, and the requirements of a key information system on high security, high reliability and high adaptation of network communication are met; the defects of the traditional VPN in the aspects of attack surface control, encryption capability, identity authentication, systematic defense and the like are overcome.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Method and device for installing certificate on basis of encryption and decryption of contract certificate private key

Disclosed are a method and device for installing a certificate on the basis of encryption and decryption of a contract certificate private key for an electric vehicle communication controller. The method for installing the certificate comprises: a step in which the electric vehicle communication controller transmits, to a secondary actor, a certificate installation request message signed with a private key associated with a manufacturer's provisioning certificate; and a step of receiving, from the secondary actor, a certificate installation response message signed with a private key associated with a leaf certificate of a certificate provisioning service, wherein an encrypted private key element of the certificate installation response message stores a private key belonging to a new contract certificate which is encrypted for the electric vehicle communication controller without a trust platform module, the private key belonging to the new contract certificate is encrypted with AES-GCM-256 on the basis of an encryption key which is entered from a public key of the manufacturer's provisioning certificate and generated through an ECDH protocol, and the private key encrypted with the AES-GCM-256 is included in a ciphertext at 528-bits or 448-bits after an initial initialization vector of a contract certificate data packet.
Owner:HYUNDAI MOTOR CO LTD +2

Systems and methods for passwordless logon

In one embodiment, a method receives a secret and a passwordless login request using a credential provider of the client device. The method pairs the credential provider of the client device with a trusted platform module (TPM) associated with a computing device. The method encrypts, using the TPM of the computing device, the secret with a hardware-bound key associated with the computing device. The method receives, from the client device, a push notification associated with the passwordless login request. The method obtains, from the client device, biometric authentication data and a nonce encrypted with a public key. The method validates a proximity of the biometric authentication data and determine a decrypted nonce by decrypting the nonce using a private key associated with the client device. The method validates the decrypted nonce with the secret. In response to determining the decrypted nonce is valid, the method approves the passwordless login request.
Owner:CISCO TECHNOLOGY INC

Virtualizing secure vault of data processing unit for secure hardware security module for hosts

A system and method of securing and virtualizing firmware trusted platform modules (TPMs) for virtualizing a hardware security module (HSM) for a host within a network fabric is provided. The system and method include operably coupling a set of components associated with a host comprising a data processing unit (DPU) secure vault and a firmware trusted platform module (TPM). The firmware TPM is configured as a virtual firmware TPM. The DPU secure vault secures the virtual firmware TPM into one or more virtual firmware TPMs based on one or more partitions configured with the DPU secure vault. A virtual TPM manager communicatively coupled to the DPU secure vault manages one or more virtual TPMs for hosting a set of Virtual Machines (VMs) or Containers.
Owner:CISCO TECHNOLOGY INC

Machine learning-based financial behavior prediction and adaptive budget optimization system

A computer-implemented system for predicting financial behavior and adaptive budget optimization based on machine learning, consisting of: a multitude of distributed processing nodes to enable low-latency communication between the nodes; a transaction data ingestion processor configured to establish authenticated connections with a plurality of financial data sources, wherein the ingestion module is further configured to normalize received transaction records into a standardized schema comprising at least a merchant identifier, a transaction category, a timestamp, a transaction amount, and optional geolocation metadata; a preprocessing engine comprising a classification sub-module trained through supervised learning to assign transaction categories based on merchant identifiers and context attributes, and a feature extraction sub-module configured to compute temporal, statistical, and behavioral feature vectors from the normalized transaction data; a prediction control unit comprising a plurality of lightweight neural network architectures, including at least one recurrent neural network (RNN) and at least one attention-based temporal model, the prediction control unit configured to predict short-term and medium-term output trends by sequentially processing the feature vectors; a budget optimization computation unit configured to solve multi-constraint budget allocation problems using a hybrid approach comprising a primary linear programming solver and an additional heuristic optimization technique, wherein the budget optimization computation unit is further configured to dynamically adjust budget allocations based on updated forecasts and user-defined constraints; a security subsystem configured for encryption at rest and in transit, as well as secure key storage in a hardware-based Trusted Platform Module (TPM); and a user interaction interface configured to display budget recommendations and forecasted spending trends through at least one web application, mobile application, or hardware device interface.
Owner:GOGINENI ANILA

Methods and systems for using smart network interface cards to secure data transmission between an initiator host running an object and a target host equipped with a disaggregated hardware device that satisfies hardware specifications of the object

This disclosure is directed to methods and systems that establish a secure data channel between a host and a disaggregated hardware device (“DHD”) of a data center. The system comprises an initiator host that runs objects, such as virtual machines and containers. The host includes an initiator smart network interface card (“SNIC”). The initiator SNIC includes a virtual device, a trust platform module (“TPM”) and a security engine. The system also comprises a target host equipped with a DHD and a target SNIC. The target SNIC includes a TPM and a security engine. The TPM and the security engine of the initiator SNIC and the TPM and the security engine of the target SNIC establish a secure data channel between an object running on the host and the DHD.
Owner:VMWARE INC

A device control method, device, storage medium, and computer program product

The application discloses a device control method, device, storage medium and computer program product, relates to the computer technical field, and the method comprises the following steps: when receiving a hibernation instruction, a trusted execution environment is created, and a dynamic session state plaintext is exported from a trusted platform module to the trusted execution environment; the dynamic session state plaintext is encrypted by using a pre-generated hibernate binding key in the trusted execution environment to obtain dynamic session state ciphertext, and a check value corresponding to the dynamic session state ciphertext is calculated; a hibernate image is created based on the dynamic session state ciphertext and the corresponding check value in the trusted execution environment, and the hibernate image is stored in a nonvolatile storage medium; and a hibernate operation is triggered. The application improves the wake-up efficiency of the device from the hibernate state.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Verifying the rendering of video content at client devices using trusted platform modules

Systems and methods for verifying the rendering of video content on information resources are provided herein. A server can receive, from a target client device, a tracking message purporting to relate to delivery of a target content item; determine whether the tracking message contains an identifier of a sending device that sent the tracking message; determine whether the sending device and the target client device are the same device; if the sending client device and the target client device are the same device: recover, from the tracking message, information about at least a portion of a frame of a content item processed by a trusted platform module of the client device; and compare the at least a portion of the frame of the content item processed by a trusted platform module of the client device with a target content item.
Owner:GOOGLE LLC

Full-link data security protection system and method based on trusted root

The invention discloses a full-link data security protection system and method based on a trusted root, and belongs to the technical field of information security. The link data transmission structure comprises a plurality of substructures, each substructure comprises an operating system, an application program, internal hardware and a transmission channel which are used as encryption objects, the encryption objects are encrypted, and the encryption content is as follows: setting a trusted platform module as a trusted root encryption tool; the operating system comprises an identity authentication password and authority management; the application program encryption comprises a login password and a hierarchical application lock; the internal hardware comprises data encryption of a BIOS, a hard disk and a memory; communication encryption measurement modules are arranged at the two ends of the transmission channel; by the adoption of the system and method, the trusted platform module (TPM) serves as a hardware trusted root, and the processes of operating system identity authentication and authority management, a system application program hierarchical encryption mechanism, a hardware layer data encryption module and transmission channel double-end encryption are achieved.
Owner:SHANGHAI SHIYUE COMPUTER TECH CO LTD

Methods and computing devices for accessing TPM in a computing device

Methods and apparatuses for accessing a trusted platform module (TPM) are disclosed. In an implementation, a method comprises receiving, by a virtual machine monitor from a first virtual machine in at least one virtual machine, a first notification message for requesting to access the TPM. In response to determining that the TPM is unlocked, locking, by the virtual machine monitor, the TPM to allow the TPM to be accessed only by the first virtual machine, and sending a first decision message to the first virtual machine indicating the first virtual machine to start performing a first access operation on the TPM. Receiving, by the virtual machine monitor, a second notification message from the first virtual machine, and unlocking, by the virtual machine monitor, the TPM in response to the second notification message.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Construction method of trusted confidential channel based on AMD SEV trusted confidential virtual machine

The invention discloses a method for constructing a trusted confidential channel based on an AMD SEV trusted confidential virtual machine, which relates to the field of computer technology and information security, and consists of a unique confidential virtual machine starting scheme, an extended TLS protocol and support components thereof. Specifically, the invention designs a method for constructing a trusted confidential channel based on an AMD SEV trusted confidential virtual machine. According to the method, by means of a virtual trusted platform module vTPM, the running state of an AMD SEV trusted confidential virtual machine is obtained to serve as a trusted credential, and a TLS protocol is expanded to support establishment of a confidential channel and verify the trusted credentials of two communication parties at the same time. Meanwhile, in order to support the method, a corresponding support component is expanded in the confidential virtual machine, so that a user load running in the confidential virtual machine can be seamlessly integrated with the method, and a method for safely and reliably establishing a trusted confidential channel with an application running in the remote confidential virtual machine is provided for the user load.
Owner:BEIJING JIAOTONG UNIV

Methods, devices, and computer program products for verifying IoT device

Embodiments of the present disclosure include a method, a device, and a computer program product for verifying an Internet of Things (IoT) device. The method includes, in response to boot of a trusted platform module (TPM) simulator, establishing an environment similar to the TPM in a trusted execution environment (TEE) of the IoT device. The method further includes sending, by a direct anonymous attestation (DAA) simulator in the TEE, an access request to an application in the IoT device. In addition, the method further includes, in response to receiving a response received by the application from a cloud platform, executing, by the TPM simulator, verification for the IoT device. In some embodiments, required TPM security services are simulated in the TEE of IoT devices, thereby minimizing the exposure of user privacy information while completing the verification and ensuring the security of verification.
Owner:DELL PROD LP

Scalable trusted platform module in programmable network interface devices

An apparatus includes a host interface, a network interface, and a programmable circuitry communicably coupled to the host interface and the network interface. The programmable circuitry can include one or more processors to implement network interface functionality, and a discrete trusted platform module (dTPM) to enable the one or more processors to establish a secure boot mechanism for the apparatus, wherein the one or more processors are to instantiate a virtual TPM (vTPM) manager that is associated with the dTPM, the vTPM manager to host vTPM instances corresponding to one or more virtualized environments hosted on at least one of the programmable circuitry or a host device communicable coupled to the apparatus.
Owner:INTEL CORP

Immutable execution stream

A novel approach to computer system security integrates one-way hashing of computer system state with Active Root of Trust (ARoT) and Active Trusted Platform Module (ATPM) technologies. The hashed output is interpreted by the ARoT and ATPM to observe and verify CPU and associated software stack integrity.
Owner:SOLID SILICON CORP

Secure communication method and device for dynamic mode encryption, medium and product

The invention discloses a secure communication method and device for dynamic mode encryption, a medium and a product, and relates to the field of data communication. According to the method, the transmitting end and the receiving end can generate the elliptic curve key pair through the trusted platform module and execute ECDH key negotiation; the sending end sends a detection packet, and the receiving end returns a response packet so as to dynamically adjust the size of the optimal transmission unit according to the network condition; a sending end flexibly selects a single round of AES-GCM encryption or AES-Twoish-Serpent triple chain encryption according to a security level score of a data block, so that the protection strength of sensitive data is ensured, and resource waste caused by excessive encryption of common data is avoided; a sending end generates independent session keys for different data blocks through a key derivation function, the forward security of a communication system is enhanced, an encryption mode and message authentication information are recorded at the frame head of the encrypted data block and encryption protection is carried out, and integrity verification of the transmission process is ensured.
Owner:BEIJING YOU TECHNOLOGY CO LTD

Secure enclave system-in-package

A Secure Enclave SiP (SE-SiP) is disclosed, which is an improvement to Trusted Platform Module (TPM) concepts, and in certain aspects, is a general-purpose next-generation security building block that provides all the security benefits of a system designed using a TPM, replaces the need to trust a general-purpose CPU chip vendor with the need to trust a much simpler more trustworthy configurable device, and replaces the need to trust the entire system motherboard manufacturer with the much more limited need to trust the SE-SiP manufacturer. It can provide privacy for the software and data sent to the system, resident on it, or retrieved from it, with respect to all parties—including the person / party in physical possession of the device.
Owner:OCTAVO SYSTEMS LLC

Implementation method, device, module and system of firmware trusted platform module based on RISC-V architecture

The present invention utilizes a firmware trusted platform module implemented by the PMP memory protection mechanism in the architecture to solve the problems of implementation complexity and the need for additional hardware support in the current firmware TPM solution under the RISC-V architecture. The method includes the following modules: (1) NVRAM secure memory module using the PMP mechanism: Based on the RISC-V instruction set, its privileged architecture and physical memory protection (PMP) technology are used to implement memory isolation, divide multiple memory areas and configure different access rights. In this way, the security of the memory is guaranteed from the hardware perspective, and at the same time, DRAM latency PUF is used to generate reversible keys, avoiding the security risks of key storage. PMP technology is further used to control access to Flash devices, so that NVRAM data can be securely encrypted and stored and effectively protected. (2) RISC-V architecture rollback attack defense module: Modify some TPM command semantics and use NVRAM to maintain the number of error attempts to deal with the problems that TPM may face, such as rollback attacks and lack of a secure clock.
Owner:WUHAN UNIV

Method of backing up a key and method of restoring a key

This specification provides a method for backing up a key, comprising: deriving a hardware key based on a system state metric stored in the Platform Configuration Register (PCR) of a Trusted Platform Module (TPM); performing a first encryption and a second encryption on the target key to obtain a first ciphertext; performing the first encryption using the hardware key in the TPM, and performing the second encryption using a white-box encryption software module; and exporting the first ciphertext to obtain backup data of the target key.
Owner:ZHEJIANG ANT SECRET TECH CO LTD

Methods and means for attestation of a platform

A method for enabling attestation of a platform comprising a Trusted Execution Environment, TEE, and a Trusted Platform Module, TPM is disclosed. The method is performed by the TEE and comprises: receiving, from an Application of the platform, a request for generation of an attestation quote, the request comprising a nonce, information on which PCR(s) to be used and information about Attestation Keys; establishing a connection to the TPM and obtaining from it at least one PCR value; generating an attestation quote based on the received nonce and the at least one PCR value; signing the attestation, and rendering the attestation quote available for the Application.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Verification method, electronic device, storage medium and computer program product

The invention provides a verification method, electronic equipment, a storage medium and a computer program product. The method comprises one of the following steps that a server side sends first information containing identification information of a remote certificate (RA) agent and related information of a trusted platform module (TPM) device to a certificate authority (CA), and the first information is provided for the CA to a client side; the binding relation is used for verifying the RA agency and the TPM equipment corresponding to the server side. The RA agency and the TPM equipment are used for verifying the RA agency and the TPM equipment corresponding to the server side. And the server receives a remote attestation request which is sent by the client and at least comprises the random number, and sends a remote attestation report which is generated based on the random number and the identification information of the RA agent corresponding to the server to the client, so that the client verifies the RA agent corresponding to the server and the TPM equipment based on the remote attestation report. According to the invention, the client can accurately verify the credible state of the server.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Method, device, and computer program product for secure calling

The present disclosure relates to a method, a device, and a computer program product. The method includes: in response to receiving a calling command from a client, determining whether the calling command includes a security identifier. The method further includes, in response to determining that the calling command includes a security identifier, determining a security service corresponding to the security identifier in a firmware trusted platform module (FTPM). The method further includes performing security isolation and encryption processing on data related to the calling command by using the security service in the FTPM. In this way, the real intention of the calling command is concealed by the security identifier, which can reduce the possibility of attackers attacking or tampering with the calling command. Therefore, embodiments of the present disclosure enhance the security of the system, protect the device from potential attacks and damage, and prevent unauthorized accesses and malicious operations.
Owner:DELL PROD LP