Invention Grant
- Patent Title: Policies for secrets in trusted execution environments
-
Application No.: US14832446Application Date: 2015-08-21
-
Publication No.: US09830480B2Publication Date: 2017-11-28
- Inventor: Benjamin David Poiesz , Andrew Abramson , Neel Rao , Shawn Edward Willden , Andres Guillermo Morales , James Brooks Miller
- Applicant: Google Inc.
- Applicant Address: US CA Mountain View
- Assignee: Google LLC
- Current Assignee: Google LLC
- Current Assignee Address: US CA Mountain View
- Agency: Shumaker & Sieffert, P.A.
- Main IPC: G06F11/30
- IPC: G06F11/30 ; G06F12/14 ; G06F21/72 ; G06F21/53 ; H04L9/32 ; H04L9/08 ; G06F21/62 ; G06F21/74

Abstract:
A computing device executes one or more trusted execution environment (TEE) processes in a TEE of a processor. The one or more TEE processes cryptographically protect a secret and a policy. The policy specifies a plurality of conditions on usage of the secret. A particular non-TEE process generates a request whose fulfillment involves an action requiring use of the secret. Responsive to the request, one or more non-TEE processes determine whether a first subset of the plurality of conditions is satisfied. Responsive to the first subset of the plurality of conditions being satisfied, the one or more TEE processes determine that a second, different subset of the plurality of conditions is satisfied. Responsive to determining the second subset of the plurality of conditions is satisfied, the one or more TEE processes use the secret to perform the action.
Public/Granted literature
- US20160350561A1 POLICIES FOR SECRETS IN TRUSTED EXECUTION ENVIRONMENTS Public/Granted day:2016-12-01
Information query