Invention Grant
- Patent Title: System wide root of trust chaining via signed applications
-
Application No.: US13925552Application Date: 2013-06-24
-
Publication No.: US09721101B2Publication Date: 2017-08-01
- Inventor: Peter M. Jones , Adam D. Jackson
- Applicant: Red Hat, Inc.
- Applicant Address: US NC Raleigh
- Assignee: Red Hat, Inc.
- Current Assignee: Red Hat, Inc.
- Current Assignee Address: US NC Raleigh
- Agency: Lowenstein Sandler LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/57

Abstract:
A processing device searches executing at least one of a boot loader or a kernel for the operating system searches for an extensible firmware interface (EFI) binary object. Responsive to finding a first EFI binary object, the processing device verifies that a first signature associated with the first EFI binary object is valid using a platform key. Responsive to verifying that the first signature for the first EFI binary object is valid, the processing device performs the following operations: identifying a first public key encapsulated in the first EFI binary object, wherein the first public key is associated with a non-EFI certificate authority; extracting the first public key from the first EFI binary object; and performing at least one of a) passing the first public key to a kernel of an operating system (OS) or b) exposing the first public key to a user space of the OS.
Public/Granted literature
- US20140380031A1 SYSTEM WIDE ROOT OF TRUST CHAINING VIA SIGNED APPLICATIONS Public/Granted day:2014-12-25
Information query