SYSTEM AND METHOD FOR SAFELY BOOTING COMPUTER HAVING RELIABLE PROCESSING MODULE

    公开(公告)号:JP2006323814A

    公开(公告)日:2006-11-30

    申请号:JP2005353934

    申请日:2005-12-07

    Applicant: MICROSOFT CORP

    Abstract: PROBLEM TO BE SOLVED: To prevent unauthorized correction on data used during booting and access after booting for reinforcing security of a computer. SOLUTION: In the computer having a reliable platform module TPM, an expected hash value for a boot component can be placed inside a platform configuration register PCR, and consequently, the TPM can disclose a secret. Then, the boot component is decoded by using the secret, and its hash value is calculated to be placed inside the PCR. Subsequently, the comparison of PCRs can be carried out. When the comparison between the PCRs is not carried out, the access to an important secret for system operation can be disabled. The access to a first secret is allowed only when a plurality of first PCR values exist, while the access to a second secret is allowed only after one or a plurality of PCR values are replaced by new values. COPYRIGHT: (C)2007,JPO&INPIT

    System and method for protected operating system boot using state validation
    3.
    发明专利
    System and method for protected operating system boot using state validation 有权
    使用状态验证保护操作系统引导的系统和方法

    公开(公告)号:JP2006018825A

    公开(公告)日:2006-01-19

    申请号:JP2005179527

    申请日:2005-06-20

    CPC classification number: G06F21/575 G06F9/4401

    Abstract: PROBLEM TO BE SOLVED: To prevent rogue components from being loaded together with an operating system, to prevent divulgence of a system key under inappropriate circumstances. SOLUTION: After a portion of a machine startup procedure has occurred, an operating system loader is run, and the loader is validated, and a correct machine state is either verified to exist and/or to be created. Once the loader has been verified to be a legitimate loader and the machine state under which the loader is running is verified to be correct, a loader's future behavior is known to protect against the loading of rogue components that can cause divulgence of the system key. When the loader's behavior is known to be safe for the system key, a validator unseals the system key and provides it to the loader. COPYRIGHT: (C)2006,JPO&NCIPI

    Abstract translation: 要解决的问题:为了防止流氓组件与操作系统一起加载,以防止在不适当情况下泄露系统密钥。

    解决方案:在机器启动过程的一部分发生之后,运行操作系统加载程序,验证加载程序,并验证是否存在和/或创建正确的机器状态。 一旦加载程序被验证为合法的加载程序,并且加载程序正在运行的机器状态被验证为正确的,装载器的未来行为是已知的,以防止可能导致系统密钥泄露的流氓组件的加载。 当装载机的行为已知对于系统密钥是安全的时,验证器将打开系统密钥并将其提供给加载程序。 版权所有(C)2006,JPO&NCIPI

    Coexistence driver
    4.
    发明专利
    Coexistence driver 有权
    共同驱动程序

    公开(公告)号:JP2005251204A

    公开(公告)日:2005-09-15

    申请号:JP2005057356

    申请日:2005-03-02

    CPC classification number: G06F8/61 G06F9/4411 G06F9/44536 Y10S707/99931

    Abstract: PROBLEM TO BE SOLVED: To provide a method and a system for preventing a driver from being overwritten by another driver having a subsequent version or a common name. SOLUTION: This method and this system for preventing a driver from being overwritten by another driver having a subsequent version or a common name includes generation of unique identification in all targeted driver packages. Driver files included in the driver packages or all the driver packages themselves are installed in a sub-directory position of a common storage based on the unique identification. The driver files can be loaded to a memory from the sub-directory position. Accordingly, a plurality of the driver packages and the driver files having the same name can be installed and loaded by making them coexist. COPYRIGHT: (C)2005,JPO&NCIPI

    Abstract translation: 要解决的问题:提供一种防止驾驶员被具有后续版本或公用名称的另一驾驶员重写的方法和系统。 解决方案:用于防止驱动程序被具有后续版本或公用名称的另一驱动程序覆盖的该方法和该系统包括在所有目标驱动程序包中产生唯一标识。 驱动程序包中包含的驱动程序文件或所有驱动程序包本身都将基于唯一标识安装在公用存储的子目录位置。 驱动程序文件可以从子目录位置加载到内存中。 因此,可以通过使它们共存来安装和加载具有相同名称的多个驱动程序包和驱动程序文件。 版权所有(C)2005,JPO&NCIPI

Patent Agency Ranking