US2006026417A1PendingUtilityA1
High-assurance secure boot content protection
Assignee: INFORMATION ASSURANCE SYSTEMSPriority: Jul 30, 2004Filed: Jul 28, 2005Published: Feb 2, 2006
Est. expiryJul 30, 2024(expired)· nominal 20-yr term from priority
G06F 21/575
40
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method and apparatus for high assurance boot processing is disclosed. A trusted processor is used to authenticate a trusted boot program and in conjunction with a selector, to provide the authenticated boot program to a boot memory where it can be accessed by a main processor to execute the bootup sequence. The trusted processor also provides a command for the main processor to write a data sequence to a hard drive or similar device, and monitors the data written by the main processor to verify that the data has not been tampered with or otherwise compromised.
Claims
exact text as granted — not AI-modified1 . A method of verifying the encryption of data provided between a main processor and a storage device, comprising the steps of:
transmitting a request from a trusted processor to the main processor to write a data pattern to the storage device; providing an encrypted data pattern to the storage device for storage in the storage device; providing the encrypted data pattern provided to the storage device to the trusted processor; and verifying the data encryption operations in the trusted processor from a comparison between the data pattern and the encrypted data pattern provided to the trusted processor.
2 . The method of claim 1 , wherein the storage device is coupled to the main processor via a storage device bus, and the step of providing an encrypted data pattern generated by the main processor to the trusted processor comprises the steps of:
monitoring data provided to the storage device; and providing the monitored data to the trusted processor.
3 . The method of claim 2 , wherein:
the step of monitoring data provided to the storage device comprises the step of storing data provided to the storage device in a monitor register; and the step of providing the monitored data to the trusted processor comprises the step of converting the monitored data from a storage device bus format to a format readable by the trusted processor.
4 . The method of claim 3 , wherein the monitor register is a solid state memory in the storage device.
5 . The method of claim 4 , wherein the monitored data is stored in the storage device media.
6 . The method of claim 1 , wherein the encrypted data pattern is generated by the main processor.
7 . The method of claim 1 , wherein the encrypted data pattern is generated by a hardware data encryptor disposed between the main processor and the storage device.
8 . The method of claim 1 , further comprising the step of:
converting the request from the trusted processor to the main processor to write a data pattern to the storage device to a main processor readable format.
9 . An apparatus for verifying encryption of data provided between a main processor and a storage device, comprising:
a data monitor, communicatively coupled to monitor data written to the storage device; and a trusted processor, communicatively coupled to the main processor and the data monitor, the trusted processor for generating a command for the main processor to write a data pattern to the storage device, and for verifying the encryption of data provided between the main processor and the storage device using a comparison between the data pattern and an encrypted version of the data pattern read from the monitor register.
10 . The apparatus of claim 9 , wherein the data monitor comprises a monitor register.
11 . The apparatus of claim 10 , wherein the monitor register is a memory register in the storage device.
12 . The apparatus of claim 9 , wherein the data monitor comprises data written to a media of the storage device;
13 . The apparatus of claim 9 , wherein the main processor generates the encrypted version of the data pattern.
14 . The apparatus of claim 9 , wherein a hardware encryptor generates the encrypted version of the data pattern.
15 . A method of securely booting a computer having a main processor, comprising the steps of:
(a) receiving a trusted boot program in a trusted processor; (b) authenticating the trusted boot program in the trusted processor; and (c) providing the trusted boot program to the main processor.
16 . The method of claim 15 , further comprising the steps of:
providing a reset mode command from the trusted processor to the main processor before performing steps (a)-(c); releasing the reset mode command provided from the trusted processor to the main processor; and providing a boot command to the main processor.
17 . The method of claim 15 , wherein the step of providing the trusted boot program to the main processor comprises the step of providing the trusted boot program to a boot memory accessible by the main processor.
18 . The method of claim 17 , wherein the step of providing the trusted boot program to a boot memory accessible by the processor comprises the steps of:
controlling a selector coupled to the boot memory to communicatively couple the trusted processor to the boot memory and communicatively decouple the main processor from the boot memory; providing the trusted boot program to the boot memory via the selector; and controlling the selector to communicatively couple the main processor to the boot memory and to communicatively decouple the trusted processor from the boot memory.
19 . The method of claim 17 , further comprising the step of converting the trusted boot program to a format compatible with the main processor.
20 . The method of claim 15 , wherein the trusted boot program is stored in a trusted memory inaccessible to the main processor.
21 . The method of claim 15 , wherein the trusted boot program is stored in a trusted memory accessible to only the trusted processor.
22 . The method of claim 15 , wherein the trusted boot program is encrypted and the encrypted trusted boot program is decrypted in the trusted processor before being authenticated.
23 . An apparatus for securely booting a computer having a main processor, comprising:
a trusted processor, for reading and authenticating a trusted boot program; and a selector, selectably coupling the trusted processor or the main processor to a boot memory according to a selector signal from the trusted processor.
24 . The apparatus of claim 23 , wherein the trusted boot program is read from a trusted memory coupled to the trusted processor.
25 . The apparatus of claim 23 , wherein the selector selectably couples the trusted processor to a boot memory to store the authenticated boot program in the boot memory and selectably couples the main processor to the boot memory to provide the authenticated boot program to the processor.
26 . The apparatus of claim 25 , wherein the trusted processor is coupled to the main processor to provide a reset command to the main processor until the authenticated boot program is executed by the main processor and to provide a boot command to command the main processor to execute the authenticated boot program.
27 . The apparatus of claim 25 , further comprising:
a first converter, for converting the authenticated boot program stored in the boot memory to a format readable by the main processor.
28 . The apparatus of claim 24 , further comprising:
a second converter, coupled between the main processor and the trusted processor, for converting commands from the trusted processor into a format readable by the main processor.Join the waitlist — get patent alerts
Track US2006026417A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.