Invention Grant
- Patent Title: Identifying security boundaries on computing devices
- Patent Title (中): 识别计算设备的安全边界
-
Application No.: US14614132Application Date: 2015-02-04
-
Publication No.: US09584317B2Publication Date: 2017-02-28
- Inventor: Kinshuman Kinshumann , Yevgeniy A. Samsonov , Niels T. Ferguson , Mark Fishel Novak
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agent Timothy Churna; Dan Choi; Micky Minhas
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/00 ; H04L9/08 ; H04L9/32 ; G06F21/57

Abstract:
During booting of a computing device, multiple security boundaries are generated. A security boundary refers to a manner of operation of a computing device or a portion of the computing device, with a program executing in one security boundary being prohibited from accessing data and programs in another security boundary. As part of booting the computing device measurements of (e.g., hash values or other identifications of) various modules loaded and executed as part of booting the computing device are maintained by a boot measurement system of the computing device. Additionally, as part of booting the computing device, a public/private key pair of one of the security boundaries is generated or otherwise obtained. The private key of the public/private key pair is provided to the one security boundary, and the public key of the public/private key pair is provided to the boot measurement system.
Public/Granted literature
- US20160105280A1 Identifying Security Boundaries on Computing Devices Public/Granted day:2016-04-14
Information query