-
公开(公告)号:WO2013095387A1
公开(公告)日:2013-06-27
申请号:PCT/US2011/066188
申请日:2011-12-20
Applicant: INTEL CORPORATION , SARANGDHAR, Nitin V. , STEVENS, William A. , VRANICH, John J.
Inventor: SARANGDHAR, Nitin V. , STEVENS, William A. , VRANICH, John J.
CPC classification number: G06F12/1408 , G06F13/14 , G06F21/44 , G06F21/79 , G06F2212/1052
Abstract: Embodiments of the invention create an underlying infrastructure in a flash memory device (e.g., a serial peripheral interface (SPI) flash memory device) such that it may be protected against user attacks - e.g., replacing the SPI flash memory device or a man-in-the-middle (MITM) attack to modify the SPI flash memory contents on the fly. In the prior art, monotonic counters cannot be stored in SPI flash memory devices because said devices do not provide replay protection for the counters. A user may also remove the flash memory device and reprogram it. Host platforms alone cannot protect against such hardware attacks. Embodiments of the invention enable secure standard storage flash memory devices such as SPI flash memory devices to achieve replay protection for securely stored data. Embodiments of the invention utilize flash memory controllers, flash memory devices, unique device keys and HMAC key logic to create secure execution environments for various components.
Abstract translation: 本发明的实施例在闪存设备(例如,串行外设接口(SPI)闪存设备)中创建底层基础设施,使得其可以被保护免受用户攻击 - 例如,替换SPI闪存设备或人 - 中间(MITM)攻击,即时修改SPI闪存内容。 在现有技术中,单调计数器不能存储在SPI闪存设备中,因为所述设备不为计数器提供重放保护。 用户也可以移除闪存设备并对其进行重新编程。 主机平台本身不能防止这种硬件攻击。 本发明的实施例使诸如SPI闪存设备之类的安全标准存储闪存设备能够实现安全存储的数据的重放保护。 本发明的实施例利用闪存控制器,闪存设备,唯一设备密钥和HMAC密钥逻辑来为各种组件创建安全的执行环境。
-
公开(公告)号:WO2011081890A2
公开(公告)日:2011-07-07
申请号:PCT/US2010/060115
申请日:2010-12-13
Applicant: INTEL CORPORATION , MARTINEZ, Alberto, J. , STEVENS, William, A. , GOEL, Purushottam , BRICKELL, Ernie
Inventor: MARTINEZ, Alberto, J. , STEVENS, William, A. , GOEL, Purushottam , BRICKELL, Ernie
CPC classification number: H04L63/08 , G06F21/57 , H04L9/3249 , H04L63/06 , H04L2209/56
Abstract: In some embodiments a secure permit request to change a hardware configuration is created. The secure permit request is sent to a remote location, and a permit sent from the remote location in response to the permit request is received. The hardware configuration is changed in response to the received permit. Other embodiments are described and claimed.
Abstract translation: 在一些实施例中,创建了用于改变硬件配置的安全许可证请求。 安全许可请求被发送到远程位置,并且接收到响应于许可请求从远程位置发送的许可证。 硬件配置根据接收到的许可证而改变。 描述和要求保护其他实施例。
-
公开(公告)号:WO2011081890A3
公开(公告)日:2011-11-03
申请号:PCT/US2010060115
申请日:2010-12-13
Applicant: INTEL CORP , MARTINEZ ALBERTO J , STEVENS WILLIAM A , GOEL PURUSHOTTAM , BRICKELL ERNIE
Inventor: MARTINEZ ALBERTO J , STEVENS WILLIAM A , GOEL PURUSHOTTAM , BRICKELL ERNIE
CPC classification number: H04L63/08 , G06F21/57 , H04L9/3249 , H04L63/06 , H04L2209/56
Abstract: In some embodiments a secure permit request to change a hardware configuration is created. The secure permit request is sent to a remote location, and a permit sent from the remote location in response to the permit request is received. The hardware configuration is changed in response to the received permit. Other embodiments are described and claimed.
Abstract translation: 在一些实施例中,创建用于改变硬件配置的安全许可请求。 安全许可请求被发送到远程位置,并且接收响应于许可请求从远程位置发送的许可。 响应收到的许可证,硬件配置发生变化。 描述并要求保护其他实施例。
-
公开(公告)号:WO0159564A3
公开(公告)日:2002-05-02
申请号:PCT/US0100467
申请日:2001-01-04
Applicant: INTEL CORP , SPIEGEL CHRISTOPHER J , GAFKEN ANDREW H , HALE ROBERT P , STEVENS WILLIAM A JR
Inventor: SPIEGEL CHRISTOPHER J , GAFKEN ANDREW H , HALE ROBERT P , STEVENS WILLIAM A JR
CPC classification number: G06F21/575 , G06F9/4401
Abstract: A protected boot sequence in a computer system. A reset vector directs the system to a boot program including a protected program. This protected program verifies the integrity of the BIOS contents before branching to the BIOS for execution of normal bootstrap functions. The protected program can also lock down various blocks of bootstrap code to prevent them from being changed after a certain point in the boot sequence.
Abstract translation: 计算机系统中的受保护引导序列。 复位向量将系统引导到包括受保护程序的引导程序。 此受保护的程序在分支到BIOS以执行正常引导功能之前验证BIOS内容的完整性。 受保护的程序还可以锁定引导代码的各种块,以防止在引导顺序中的某一点之后它们被更改。
-
公开(公告)号:CA5314A
公开(公告)日:1875-10-30
申请号:CA5314D
Applicant: STEVENS WILLIAM A , CROSS RICHARD E
Inventor: STEVENS WILLIAM A , CROSS RICHARD E
-
6.
公开(公告)号:US2634502A
公开(公告)日:1953-04-14
申请号:US30684652
申请日:1952-08-28
Applicant: STEVENS WILLIAM A , WILSON KARL T
Inventor: STEVENS WILLIAM A , WILSON KARL T
IPC: A41H9/02
CPC classification number: A41H9/02
-
-
-
-
-