Movatterモバイル変換


[0]ホーム

URL:


US20120131334A1 - Method for Attesting a Plurality of Data Processing Systems - Google Patents

Method for Attesting a Plurality of Data Processing Systems
Download PDF

Info

Publication number
US20120131334A1
US20120131334A1US13/289,044US201113289044AUS2012131334A1US 20120131334 A1US20120131334 A1US 20120131334A1US 201113289044 AUS201113289044 AUS 201113289044AUS 2012131334 A1US2012131334 A1US 2012131334A1
Authority
US
United States
Prior art keywords
data processing
processing system
attestation
data
processing systems
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Abandoned
Application number
US13/289,044
Inventor
David Haikney
David N. Mackintosh
Jose J.P. Perez
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
International Business Machines Corp
Original Assignee
International Business Machines Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by International Business Machines CorpfiledCriticalInternational Business Machines Corp
Assigned to INTERNATIONAL BUSINESS MACHINES CORPORATIONreassignmentINTERNATIONAL BUSINESS MACHINES CORPORATIONASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS).Assignors: MACKINTOSH, DAVID N., HAIKNEY, DAVID, PEREZ, JOSE J.P.
Priority to US13/460,080priorityCriticalpatent/US9075994B2/en
Publication of US20120131334A1publicationCriticalpatent/US20120131334A1/en
Abandonedlegal-statusCriticalCurrent

Links

Images

Classifications

Definitions

Landscapes

Abstract

A technique for attesting a plurality of data processing systems. The method includes: configuring a chain of data processing systems wherein a first data processing system is responsible for retrieving attestation data associated with a second data processing system; sending a request for attestation of the first data processing system; in response to receiving the request, retrieving a list of associated one or more children, wherein the one or more children comprise the second data processing system; retrieving and storing attestation data associated with each child; retrieving and storing attestation data associated with the first data processing system; and sending to the requester a concatenated response containing the attestation data associated with the first and second data processing systems, such that the attestation data associated with the first and second data processing systems can be used to attest the first and second data processing systems, respectively.

Description

Claims (25)

1. A method for attesting a plurality of data processing systems, comprising the steps of:
configuring a chain of the plurality of data processing systems, wherein a first data processing system of the plurality of data processing systems is responsible for retrieving attestation data associated with a second data processing system of the plurality of data processing systems;
sending a request for attestation of the first data processing system;
in response to receiving the request, retrieving, by the first data processing system, a list of associated one or more children, wherein the one or more children comprise the second data processing system;
retrieving and storing, by the first data processing system, attestation data associated with each child of the one or more children;
retrieving and storing, by the first data processing system, attestation data associated with the first data processing system; and
sending to the requester, by the first data processing system, a concatenated response containing the attestation data associated with the first and second data processing systems, such that the attestation data associated with the first and second data processing systems is usable to attest the first and second data processing systems, respectively.
13. An apparatus for attesting a plurality of data processing systems, the apparatus comprising a data processor coupled to a memory that includes instructions that are operable when executed by the data processor for performing steps of:
configuring a chain of the plurality of data processing systems, wherein a first data processing system of the plurality of data processing systems is configurable to be responsible for retrieving attestation data associated with a second data processing system of the plurality of data processing systems;
sending a request for attestation of the first data processing system;
retrieving, by the first data processing system, in response to receipt of the request, a list of associated one or more children, wherein the one or more children comprise the second data processing system;
retrieving and storing, by the first data processing system, attestation data associated with each child of the one or more children;
retrieving and storing, by the first data processing system, attestation data associated with the first data processing system; and
sending to the requester, by the first data processing system, a concatenated response containing the attestation data associated with the first and second data processing systems, such that the attestation data associated with the first and second data processing systems is usable to attest the first and second data processing systems, respectively.
US13/289,0442010-11-182011-11-04Method for Attesting a Plurality of Data Processing SystemsAbandonedUS20120131334A1 (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
US13/460,080US9075994B2 (en)2010-11-182012-04-30Processing attestation data associated with a plurality of data processing systems

Applications Claiming Priority (2)

Application NumberPriority DateFiling DateTitle
EP101916692010-11-18
GB10191669.02010-11-18

Related Child Applications (1)

Application NumberTitlePriority DateFiling Date
US13/460,080ContinuationUS9075994B2 (en)2010-11-182012-04-30Processing attestation data associated with a plurality of data processing systems

Publications (1)

Publication NumberPublication Date
US20120131334A1true US20120131334A1 (en)2012-05-24

Family

ID=46065508

Family Applications (2)

Application NumberTitlePriority DateFiling Date
US13/289,044AbandonedUS20120131334A1 (en)2010-11-182011-11-04Method for Attesting a Plurality of Data Processing Systems
US13/460,080Expired - Fee RelatedUS9075994B2 (en)2010-11-182012-04-30Processing attestation data associated with a plurality of data processing systems

Family Applications After (1)

Application NumberTitlePriority DateFiling Date
US13/460,080Expired - Fee RelatedUS9075994B2 (en)2010-11-182012-04-30Processing attestation data associated with a plurality of data processing systems

Country Status (1)

CountryLink
US (2)US20120131334A1 (en)

Cited By (12)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20120166795A1 (en)*2010-12-242012-06-28Wood Matthew DSecure application attestation using dynamic measurement kernels
US20120216244A1 (en)*2011-02-172012-08-23Taasera, Inc.System and method for application attestation
US20140025961A1 (en)*2010-12-212014-01-23David N. MackintoshVirtual machine validation
US8776180B2 (en)2012-05-012014-07-08Taasera, Inc.Systems and methods for using reputation scores in network services and transactions to calculate security risks to computer systems and platforms
US8869264B2 (en)2010-10-012014-10-21International Business Machines CorporationAttesting a component of a system during a boot process
US9075994B2 (en)2010-11-182015-07-07International Business Machines CorporationProcessing attestation data associated with a plurality of data processing systems
US9250951B2 (en)2010-11-182016-02-02International Business Machines CorporationTechniques for attesting data processing systems
US9342696B2 (en)2010-09-222016-05-17International Business Machines CorporationAttesting use of an interactive component during a boot process
US20160162285A1 (en)*2011-01-192016-06-09International Business Machines CorporationUpdating software
CN112688782A (en)*2019-10-172021-04-20华为技术有限公司Remote certification method and equipment for combined equipment
WO2021229084A1 (en)*2020-05-142021-11-18Wibu-Systems AgMethod and secure element for detecting a trusted electronic assembly
US11431752B2 (en)*2018-06-222022-08-30Microsoft Technology Licensing, LlcEx post facto platform configuration attestation

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20230328092A1 (en)*2022-04-122023-10-12Visa International Service AssociationSystem and method for performing device attestation

Citations (3)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US8433924B2 (en)*2006-12-182013-04-30Lenovo (Singapore) Pte. Ltd.Apparatus, system, and method for authentication of a core root of trust measurement chain
US8522018B2 (en)*2006-08-182013-08-27Fujitsu LimitedMethod and system for implementing a mobile trusted platform module
US8549288B2 (en)*2005-10-032013-10-01International Business Machines CorporationDynamic creation and hierarchical organization of trusted platform modules

Family Cites Families (32)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US6539480B1 (en)1998-12-312003-03-25Intel CorporationSecure transfer of trust in a computing system
US6546392B1 (en)1999-06-252003-04-08Mediaone Group, Inc.Self service gateway
GB2376765B (en)2001-06-192004-12-29Hewlett Packard CoMultiple trusted computing environments with verifiable environment identities
US7191464B2 (en)2001-10-162007-03-13Lenovo Pte. Ltd.Method and system for tracking a secure boot in a trusted computing environment
US6928526B1 (en)2002-12-202005-08-09Datadomain, Inc.Efficient data storage system
US7275263B2 (en)2003-08-112007-09-25Intel CorporationMethod and system and authenticating a user of a computer system that has a trusted platform module (TPM)
US7313679B2 (en)*2003-10-172007-12-25Intel CorporationExtended trusted computing base
US8161197B2 (en)2003-12-192012-04-17Broadcom CorporationMethod and system for efficient buffer management for layer 2 (L2) through layer 5 (L5) network interface controller applications
US7222062B2 (en)*2003-12-232007-05-22Intel CorporationMethod and system to support a trusted set of operational environments using emulated trusted hardware
US7480804B2 (en)*2004-04-292009-01-20International Business Machines CorporationMethod and system for hierarchical platform boot measurements in a trusted computing environment
US7380119B2 (en)*2004-04-292008-05-27International Business Machines CorporationMethod and system for virtualization of trusted platform modules
JP4433401B2 (en)2004-12-202010-03-17レノボ シンガポール プライヴェート リミテッド Information processing system, program, and information processing method
WO2006100522A1 (en)2005-03-222006-09-28Hewlett-Packard Development Company, L.P.Methods, devices and data structures for trusted data
US7613921B2 (en)2005-05-132009-11-03Intel CorporationMethod and apparatus for remotely provisioning software-based security coprocessors
US8201216B2 (en)2006-09-112012-06-12Interdigital Technology CorporationTechniques for database structure and management
US7840801B2 (en)*2007-01-192010-11-23International Business Machines CorporationArchitecture for supporting attestation of a virtual machine in a single step
US20080235754A1 (en)2007-03-192008-09-25Wiseman Willard MMethods and apparatus for enforcing launch policies in processing systems
US8151262B2 (en)*2007-03-302012-04-03Lenovo (Singapore) Pte. Ltd.System and method for reporting the trusted state of a virtual machine
GB0707150D0 (en)2007-04-132007-05-23Hewlett Packard Development CoDynamic trust management
US20080281654A1 (en)2007-05-092008-11-13Novell, Inc.Data center life cycle management
US20090204964A1 (en)2007-10-122009-08-13Foley Peter FDistributed trusted virtualization platform
US8620708B2 (en)2007-11-092013-12-31Hitachi-Ge Nuclear Energy, Ltd.Progress status management method, program, and progress status management device
US7921286B2 (en)2007-11-142011-04-05Microsoft CorporationComputer initialization for secure kernel
US8042190B2 (en)*2007-12-312011-10-18Intel CorporationPre-boot protected memory channel
KR101709456B1 (en)*2008-02-192017-02-22인터디지탈 패튼 홀딩스, 인크A method and apparatus for secure trusted time techniques
US7953778B2 (en)2008-05-202011-05-31International Business Machines CorporationEfficient support of consistent cyclic search with read-copy update and parallel updates
US8943491B2 (en)2008-06-262015-01-27Lenovo Enterprise Solutions (Singapore) Pte. Ltd.Systems and methods for maintaining CRTM code
US20100083002A1 (en)2008-09-302010-04-01Liang CuiMethod and System for Secure Booting Unified Extensible Firmware Interface Executables
US8738932B2 (en)2009-01-162014-05-27Teleputers, LlcSystem and method for processor-based security
EP2619701B1 (en)2010-09-222015-04-22International Business Machines CorporationAttesting use of an interactive component during a boot process
US8869264B2 (en)2010-10-012014-10-21International Business Machines CorporationAttesting a component of a system during a boot process
US20120131334A1 (en)2010-11-182012-05-24International Business Machines CorporationMethod for Attesting a Plurality of Data Processing Systems

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US8549288B2 (en)*2005-10-032013-10-01International Business Machines CorporationDynamic creation and hierarchical organization of trusted platform modules
US8522018B2 (en)*2006-08-182013-08-27Fujitsu LimitedMethod and system for implementing a mobile trusted platform module
US8433924B2 (en)*2006-12-182013-04-30Lenovo (Singapore) Pte. Ltd.Apparatus, system, and method for authentication of a core root of trust measurement chain

Cited By (30)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US9342696B2 (en)2010-09-222016-05-17International Business Machines CorporationAttesting use of an interactive component during a boot process
US9436827B2 (en)2010-10-012016-09-06International Business Machines CorporationAttesting a component of a system during a boot process
US8869264B2 (en)2010-10-012014-10-21International Business Machines CorporationAttesting a component of a system during a boot process
US9489232B2 (en)2010-11-182016-11-08International Business Machines CorporationTechniques for attesting data processing systems
US9250951B2 (en)2010-11-182016-02-02International Business Machines CorporationTechniques for attesting data processing systems
US9075994B2 (en)2010-11-182015-07-07International Business Machines CorporationProcessing attestation data associated with a plurality of data processing systems
US9081600B2 (en)*2010-12-212015-07-14International Business Machines CorporationVirtual machine validation
US20140025961A1 (en)*2010-12-212014-01-23David N. MackintoshVirtual machine validation
US20120166795A1 (en)*2010-12-242012-06-28Wood Matthew DSecure application attestation using dynamic measurement kernels
US9087196B2 (en)*2010-12-242015-07-21Intel CorporationSecure application attestation using dynamic measurement kernels
US10620936B2 (en)2011-01-192020-04-14International Business Machines CorporationUpdating software
US10007510B2 (en)*2011-01-192018-06-26International Business Machines CorporationUpdating software
US10108413B2 (en)*2011-01-192018-10-23International Business Machines CorporationUpdating software
US20160162396A1 (en)*2011-01-192016-06-09International Business Machines CorporationUpdating software
US20160162285A1 (en)*2011-01-192016-06-09International Business Machines CorporationUpdating software
US20120216244A1 (en)*2011-02-172012-08-23Taasera, Inc.System and method for application attestation
US8327441B2 (en)*2011-02-172012-12-04Taasera, Inc.System and method for application attestation
US8850588B2 (en)2012-05-012014-09-30Taasera, Inc.Systems and methods for providing mobile security based on dynamic attestation
US8776180B2 (en)2012-05-012014-07-08Taasera, Inc.Systems and methods for using reputation scores in network services and transactions to calculate security risks to computer systems and platforms
US9027125B2 (en)2012-05-012015-05-05Taasera, Inc.Systems and methods for network flow remediation based on risk correlation
US9092616B2 (en)2012-05-012015-07-28Taasera, Inc.Systems and methods for threat identification and remediation
US8990948B2 (en)2012-05-012015-03-24Taasera, Inc.Systems and methods for orchestrating runtime operational integrity
US11431752B2 (en)*2018-06-222022-08-30Microsoft Technology Licensing, LlcEx post facto platform configuration attestation
EP4037279A4 (en)*2019-10-172022-11-16Huawei Technologies Co., Ltd. METHOD FOR NEGOTIATION OF A REMOTE AUTHENTICATION MODE FOR A COMBINED DEVICE AND ASSOCIATED DEVICE
CN112688782A (en)*2019-10-172021-04-20华为技术有限公司Remote certification method and equipment for combined equipment
EP4030681A4 (en)*2019-10-172022-11-16Huawei Technologies Co., Ltd. METHOD AND DEVICE FOR REMOTE ATTESTATION OF A COMBINED DEVICE
US12113823B2 (en)2019-10-172024-10-08Huawei Technologies Co., Ltd.Remote attestation method and device for composite device
US12231452B2 (en)2019-10-172025-02-18Huawei Technologies Co., Ltd.Remote attestation mode negotiation method for combined device and related device
WO2021229084A1 (en)*2020-05-142021-11-18Wibu-Systems AgMethod and secure element for detecting a trusted electronic assembly
US20230185968A1 (en)*2020-05-142023-06-15Wibu-Systems AgMethod and Secure Element for Detecting a Trusted Electronic Assembly

Also Published As

Publication numberPublication date
US20120216255A1 (en)2012-08-23
US9075994B2 (en)2015-07-07

Similar Documents

PublicationPublication DateTitle
US9075994B2 (en)Processing attestation data associated with a plurality of data processing systems
CN112840326B (en)Test engine for automated operation management
CN103201747B (en) Method and apparatus for validating multiple data processing systems
US9436827B2 (en)Attesting a component of a system during a boot process
US9386079B2 (en)Method and system of virtual desktop infrastructure deployment studio
CN103329093B (en)Method and system for updating the code in performing environment
US20190349450A1 (en)Hardware validation
JP5745061B2 (en) Authenticating the use of interactive components during the boot process
US11281768B1 (en)Firmware security vulnerability verification service
CN111079168A (en)Techniques for secure hardware and software attestation of trusted I/O
US11902112B2 (en)Provisioning persistent, dynamic and secure cloud services
US11907375B2 (en)System and method for signing and interlocking a boot information file to a host computing system
US11113186B1 (en)Testing and publishing of resource handlers in a cloud environment
US20200110879A1 (en)Trusted computing attestation of system validation state
WO2020145944A1 (en)Securing node groups
US20250005128A1 (en)Trusted Cloud Device Lifecycle Management
US8140835B2 (en)Updating a basic input/output system (‘BIOS’) boot block security module in compute nodes of a multinode computer
US20190149414A1 (en)Asynchronous imaging of computing nodes
JP2019133220A (en)Integrity verification device, integrity verification system, integrity verification method and integrity verification program
US10782952B1 (en)Generating machine images from software packages
CN113454625A (en)Security state of security slice
US12141295B2 (en)Systems and methods for vulnerability proofing machine learning recommendations
US20250307435A1 (en)Detecting unexpected changes to managed nodes based on remotely-generated verification values derived from node-provided integrity measurements
US12255833B1 (en)Visibility pods for network traffic
CN111258805B (en) Method, device and computer device for monitoring hard disk state of a server

Legal Events

DateCodeTitleDescription
ASAssignment

Owner name:INTERNATIONAL BUSINESS MACHINES CORPORATION, NEW Y

Free format text:ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNORS:HAIKNEY, DAVID;MACKINTOSH, DAVID N.;PEREZ, JOSE J.P.;SIGNING DATES FROM 20111024 TO 20111103;REEL/FRAME:027174/0645

STCBInformation on status: application discontinuation

Free format text:ABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTION


[8]ページ先頭

©2009-2025 Movatter.jp