- 专利标题: Systems and methods for evaluating security risks using a manufacturer-signed software identification manifest
-
申请号: US17111253申请日: 2020-12-03
-
公开(公告)号: US11586738B2公开(公告)日: 2023-02-21
- 发明人: Charles D. Robison , Nicholas D. Grobelny
- 申请人: Dell Products, L.P.
- 申请人地址: US TX Round Rock
- 专利权人: Dell Products, L.P.
- 当前专利权人: Dell Products, L.P.
- 当前专利权人地址: US TX Round Rock
- 代理机构: Fogarty LLP
- 主分类号: G06F21/57
- IPC分类号: G06F21/57 ; G06F21/60 ; G06F21/74 ; G06F21/73 ; G06F21/64
摘要:
Systems and methods for evaluating security risks using a manufacturer-signed software identification manifest are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to: receive a request to perform attestation of a client device; retrieve, from an agent executed by the client device, a manifest comprising: (i) a signature portion encrypted with a first key, and (ii) a software identification (SWID) portion encrypted with a second key; retrieve the first key from a manufacturer database; retrieve the second key from a customer database; decrypt the signature and the manifest with the first and second keys; and perform the attestation using the decrypted manifest.
公开/授权文献
信息查询