ATTESTING UPDATE OF A FIRMWARE LAYER

    公开(公告)号:US20220222348A1

    公开(公告)日:2022-07-14

    申请号:US17148548

    申请日:2021-01-13

    Abstract: In various examples there is a method of enabling an attestable update of a firmware layer that provides a unique identity of a computing device. The method comprises using an immutable firmware layer to access a unique device secret. The immutable layer is used to derive a hardware device identity (HDI) from the unique device secret. The immutable layer is used to derive a compound device identity (CDI) from a measurement of the firmware layer and the unique device secret. The CDI and HDI are made available to the firmware layer. The firmware layer is used to issue a local certificate to endorse a device identity key, derived from the CDI, the local certificate signed by a key derived from the HDI.

    EXECUTION ENVIRONMENT AND GATEKEEPER ARRANGEMENT

    公开(公告)号:US20210004469A1

    公开(公告)日:2021-01-07

    申请号:US16503455

    申请日:2019-07-03

    Abstract: A computer system has a separation mechanism which enforces separation between at least two execution environments such that one execution environment is a gatekeeper which interposes on all communications of the other execution environment. The computer system has an attestation mechanism which enables the gatekeeper to attest to properties of the at least two execution environments. A first one of the execution environments runs application specific code which may contain security vulnerabilities. The gatekeeper is configured to enforce an input output policy on the first execution environment by interposing on all communication to and from the first execution environment by forwarding, modifying or dropping individual ones of the communications according to the policy. The gatekeeper provides evidence of attestation both for the application specific code and the policy.

Patent Agency Ranking