-
公开(公告)号:US11146400B2
公开(公告)日:2021-10-12
申请号:US16820233
申请日:2020-03-16
Applicant: ARM IP Limited , ARM Ltd
Inventor: Geraint David Luff , Brendan James Moran , Milosch Meriac , Manuel Pegourie-Gonnard
IPC: H04L9/32 , H04W4/70 , H04L29/06 , H04W12/10 , H04W12/12 , H04W12/102 , H04W12/106 , H04W12/122 , H04W4/80 , H04W4/06
Abstract: A method for verifying the integrity of data in a message by a data processing device, the message comprising a plurality of packets, the method comprising: receiving, at the device from a first resource, a manifest associated with the message, the manifest comprising a plurality of group check values for the plurality of packets; receiving, at the device, from the first or a different resource, the message; generating a first progression of rolling hashes for the plurality of packets; deriving group check values from the first progression of rolling hashes for groups of the plurality of packets along one or more paths; verifying the integrity of the data in the message based on or in response to a determination that the derived group check values correspond to the plurality of group check values in the manifest.
-
公开(公告)号:US20200288322A1
公开(公告)日:2020-09-10
申请号:US16820233
申请日:2020-03-16
Applicant: ARM IP Limited , ARM Ltd
Inventor: Geraint David Luff , Brendan James Moran , Milosch Meriac , Manuel Pegourie-Gonnard
Abstract: A method for verifying the integrity of data in a message by a data processing device, the message comprising a plurality of packets, the method comprising: receiving, at the device from a first resource, a manifest associated with the message, the manifest comprising a plurality of group check values for the plurality of packets; receiving, at the device, from the first or a different resource, the message; generating a first progression of rolling hashes for the plurality of packets; deriving group check values from the first progression of rolling hashes for groups of the plurality of packets along one or more paths; verifying the integrity of the data in the message based on or in response to a determination that the derived group check values correspond to the plurality of group check values in the manifest.
-
公开(公告)号:US10595207B2
公开(公告)日:2020-03-17
申请号:US15258117
申请日:2016-09-07
Applicant: ARM IP Limited , ARM Ltd
Inventor: Geraint Luff , Brendan Moran , Milosch Meriac , Manuel Pegourie-Gonnard
Abstract: A method for verifying the integrity of data in a message by a data processing device, the message comprising a plurality of packets, the method comprising: receiving, at the device from a first resource, a manifest associated with the message, the manifest comprising a plurality of group check values for the plurality of packets; receiving, at the device, from the first or a different resource, the message; generating a first progression of rolling hashes for the plurality of packets; deriving group check values from the first progression of rolling hashes for groups of the plurality of packets along one or more paths; verifying the integrity of the data in the message based on or in response to a determination that the derived group check values correspond to the plurality of group check values in the manifest.
-
公开(公告)号:US20160212137A1
公开(公告)日:2016-07-21
申请号:US15001750
申请日:2016-01-20
Applicant: ARM IP Limited , ARM Ltd.
Inventor: Remy Pottier , Hugo John Martin Vincent , Amyas Edward Wykes Phillips , Christopher Mark Paola , Milosch Meriac
IPC: H04L29/06
CPC classification number: H04L63/101 , H04L63/0823 , H04L63/104
Abstract: A method of creating, at a permissions management resource, access permissions relating to a subject device for at least one data processing device, the method comprising: obtaining, at the permissions management resource, input data; generating, at the permissions management resource, at least one permission relating to accessing the subject device in response to the input data; transmitting, from the permissions management resource to the subject device and/or the at least one processing device, a communication comprising the at least one permission.
Abstract translation: 在权限管理资源上创建与至少一个数据处理设备的主题设备相关的访问许可的方法,所述方法包括:在所述许可管理资源处获取输入数据; 在所述许可管理资源处产生响应于所述输入数据访问所述主题设备的至少一个许可; 从所述许可管理资源向所述主体设备和/或所述至少一个处理设备发送包括所述至少一个许可的通信。
-
公开(公告)号:US20170070890A1
公开(公告)日:2017-03-09
申请号:US15258117
申请日:2016-09-07
Applicant: ARM IP Limited , ARM Ltd
Inventor: Geraint Luff , Brendan Moran , Milosch Meriac , Manuel Pegourie-Gonnard
Abstract: A method for verifying the integrity of data in a message by a data processing device, the message comprising a plurality of packets, the method comprising: receiving, at the device from a first resource, a manifest associated with the message, the manifest comprising a plurality of group check values for the plurality of packets; receiving, at the device, from the first or a different resource, the message; generating a first progression of rolling hashes for the plurality of packets; deriving group check values from the first progression of rolling hashes for groups of the plurality of packets along one or more paths; verifying the integrity of the data in the message based on or in response to a determination that the derived group check values correspond to the plurality of group check values in the manifest.
Abstract translation: 一种用于由数据处理设备验证消息中的数据的完整性的方法,所述消息包括多个分组,所述方法包括:在所述设备处从所述设备从第一资源接收与所述消息相关联的清单,所述清单包括 多个分组的多个组检查值; 在所述设备处从所述第一或不同资源接收所述消息; 产生用于所述多个分组的滚动哈希的第一进程; 从沿着一个或多个路径的多个分组的组的滚动哈希的第一进程中导出组检查值; 基于或响应于导出的组检查值对应于清单中的多个组检查值的确定来验证消息中的数据的完整性。
-
公开(公告)号:US11366904B2
公开(公告)日:2022-06-21
申请号:US15748788
申请日:2016-08-01
Applicant: ARM IP LIMITED
Inventor: Geraint Luff , Thomas Grocutt , Milosch Meriac , Jonathan Austin
IPC: G06F21/57 , G06F21/64 , G06F21/74 , G06F21/78 , H04L41/0859
Abstract: A machine-implemented method for controlling a configuration data item in a storage-equipped device having at least two security domains, comprising receiving, by one of the security domains, a configuration data item; storing the configuration data item; providing a security indication for the configuration data item; and when an event indicates untrustworthiness of the data item, invalidating a configuration effect of the stored configuration data item. Further provided is a machine-implemented method for controlling a storage-equipped device as a node in a network of devices, comprising receiving information that a data source or type of a configuration data item is untrusted; analysing metadata for the data source and the configuration data item; populating a knowledge base with analysed metadata; and responsive to the analysed metadata, transmitting security information to the network of devices. A corresponding device and computer program product are also described.
-
公开(公告)号:US20210203489A1
公开(公告)日:2021-07-01
申请号:US17057373
申请日:2019-05-01
Applicant: Arm IP Limited
Inventor: Brendan James Moran , Milosch Meriac
IPC: H04L9/08
Abstract: A method for securely distributing content from a distributor to a plurality of receiving devices, each recipient creating recipient trusted ephemeral public private key pair and making the recipient trusted ephemeral public key available, the method comprising: generating a content encryption key for encrypting content to be distributed and encrypting content using the content encryption key; generating, for each recipient trusted ephemeral public key, a shared secret using the recipient trusted ephemeral public key and the distributor ephemeral private key; generating a plurality of encrypted per-recipient key slots, each encrypted per-recipient key slot generated by encrypting the content encryption key using a different shared secret of the plurality of shared secrets; creating a data structure comprising the distributor ephemeral public key, the encrypted content, and one or more encrypted per-recipient key slots; and transmitting the data structure to deliver the content to recipients associated with the device public keys from which the one or more encrypted per-recipient key slots are derived.
-
公开(公告)号:US11003508B2
公开(公告)日:2021-05-11
申请号:US15572692
申请日:2016-04-21
Applicant: ARM IP LIMITED , ARM LIMITED
Inventor: Christopher Mark Paola , Milosch Meriac , Remy Pottier
IPC: G06F15/173 , G06F9/50 , H04L29/08 , G06F11/34
Abstract: A system provided at nodes within a network of nodes enabling the nodes to migrate activities to other nodes within its communication range to provide load balancing across the network. The other nodes having power and processing capabilities and capacity enabling them to undertake the migrated activities.
-
公开(公告)号:US10924934B2
公开(公告)日:2021-02-16
申请号:US16191024
申请日:2018-11-14
Applicant: Arm IP Limited
Inventor: Samuel Marc Town , Milosch Meriac
Abstract: A method, electronic apparatus and computer program for device obfuscation in electronic networks, comprising determining at least one device type of at least one physical device operable to be at least intermittently attached to a wireless network; generating a pattern of wireless network activity associated with the at least one device type; exposing over the wireless network a plurality of non-functional messages conforming to the pattern; and operating a purported sender and receiver of each of the plurality of messages to obscure at least one of an exploitable characteristic and an exploitable state of the at least one device type with respect to the wireless network.
-
公开(公告)号:US10917243B2
公开(公告)日:2021-02-09
申请号:US16025142
申请日:2018-07-02
Applicant: Arm IP Limited
Inventor: Milosch Meriac
Abstract: Apparatus and methods are described to provision a compute node in a plurality of compute nodes to a requestor, comprising receiving an anonymised access token from a provider of the compute nodes, requesting identities of a subset of compute nodes in the plurality of compute nodes, selecting at least one compute node in the subset of compute notes, providing the anonymised access token to a secure enclave of the selected at least one compute node, providing an anonymised identity of the requestor to the secure enclave and validating use of the anonymised identity with the access token.
-
-
-
-
-
-
-
-
-