Mechanism to update attested firmware on a platform

    公开(公告)号:US12229270B2

    公开(公告)日:2025-02-18

    申请号:US18538787

    申请日:2023-12-13

    Abstract: An apparatus to facilitate permissions at a computing system platform is disclosed. The apparatus includes a plurality of agents, each including a non-volatile memory storing firmware executed to perform a function associated with the agent and attestation hardware to detect an update at the computing system platform, generate a cryptographic key associated with each of the plurality of agents, perform an attestation with a relying party using the generated cryptographic keys and receive a tuple associated with each of the plurality of agents, wherein a tuple includes one or more permissions indicating platform resources an agent is permitted to access.

    MECHANISM TO UPDATE ATTESTED FIRMWARE ON A PLATFORM

    公开(公告)号:US20240152619A1

    公开(公告)日:2024-05-09

    申请号:US18538787

    申请日:2023-12-13

    CPC classification number: G06F21/572 H04L9/0816

    Abstract: An apparatus to facilitate permissions at a computing system platform is disclosed. The apparatus includes a plurality of agents, each including a non-volatile memory storing firmware executed to perform a function associated with the agent and attestation hardware to detect an update at the computing system platform, generate a cryptographic key associated with each of the plurality of agents, perform an attestation with a relying party using the generated cryptographic keys and receive a tuple associated with each of the plurality of agents, wherein a tuple includes one or more permissions indicating platform resources an agent is permitted to access.

    Mechanism to update attested firmware on a platform

    公开(公告)号:US11861009B2

    公开(公告)日:2024-01-02

    申请号:US17131959

    申请日:2020-12-23

    CPC classification number: G06F21/572 H04L9/0816

    Abstract: An apparatus to facilitate permissions at a computing system platform is disclosed. The apparatus includes a plurality of agents, each including a non-volatile memory storing firmware executed to perform a function associated with the agent and attestation hardware to detect an update at the computing system platform, generate a cryptographic key associated with each of the plurality of agents, perform an attestation with a relying party using the generated cryptographic keys and receive a tuple associated with each of the plurality of agents, wherein a tuple includes one or more permissions indicating platform resources an agent is permitted to access.

    ISA accessible physical unclonable function

    公开(公告)号:US11706039B2

    公开(公告)日:2023-07-18

    申请号:US17134364

    申请日:2020-12-26

    CPC classification number: H04L9/3278 G06F9/30098 G06F9/30145 H04L9/0861

    Abstract: Techniques for encrypting data using a key generated by a physical unclonable function (PUF) are described. An apparatus according to the present disclosure may include decoder circuitry to decode an instruction and generate a decoded instruction. The decoded instruction includes operands and an opcode. The opcode indicates that execution circuitry is to encrypt data using a key generated by a PUF. The apparatus may further include execution circuitry to execute the decoded instruction according to the opcode to encrypt the data to generate encrypted data using the key generated by the PUF.

    System, Apparatus And Method For Direct Peripheral Access Of Secure Storage

    公开(公告)号:US20230100106A1

    公开(公告)日:2023-03-30

    申请号:US17483904

    申请日:2021-09-24

    Abstract: In one embodiment, an apparatus includes: an access control circuit to receive a memory transaction directed to a storage, the memory transaction having a requester ID and a key ID; a first memory to store an access control table, the access control table having a plurality of entries each to store a requester ID and at least one key ID; and a cryptographic circuit coupled to the access control circuit, the cryptographic circuit to perform a cryptographic operation on data associated with the memory transaction based at least in part on the key ID. The apparatus may be implemented as an inline engine coupled between the storage and an accelerator, the inline engine to provide decrypted data to the accelerator, the storage to store encrypted data. Other embodiments are described and claimed.

    PLATFORM SEALING SECRETS USING PHYSICALLY UNCLONABLE FUNCTION (PUF) WITH TRUSTED COMPUTING BASE (TCB) RECOVERABILITY

    公开(公告)号:US20220417042A1

    公开(公告)日:2022-12-29

    申请号:US17358238

    申请日:2021-06-25

    Abstract: Methods and apparatus relating to provision of platform sealing secrets using a Physically Unclonable Function (PUF) with Trusted Computing Based (TCB) Recoverability are described. In an embodiment, decode circuitry decodes an instruction to determine data to be cryptographically protected and a challenge for a Physically Unclonable Function (PUF) circuitry. Execution circuitry executes the decoded instruction to cryptographically protect the data in accordance with a key, wherein the PUF circuitry is to generate the key in response to the challenge. Other embodiments are also disclosed and claimed.

Patent Agency Ranking