首页> 外国专利> FIRMWARE-BASED TRUSTED PLATFORM MODULE FOR ARM PROCESSOR ARCHITECTURES AND TRUSTZONE SECURITY EXTENSIONS

FIRMWARE-BASED TRUSTED PLATFORM MODULE FOR ARM PROCESSOR ARCHITECTURES AND TRUSTZONE SECURITY EXTENSIONS

机译:基于固件的基于信任的ARM处理器体系结构和信任区安全扩展平台模块

摘要

A “Firmware-Based TPM” or “fTPM” ensures that secure code execution is isolated to prevent a wide variety of potential security breaches. Unlike a conventional hardware based Trusted Platform Module (TPM), isolation is achieved without the use of dedicated security processor hardware or silicon. In general, the fTPM is first instantiated in a pre-OS boot environment by reading the fTPM from system firmware or firmware accessible memory or storage and placed into read-only protected memory of the device. Once instantiated, the fTPM enables execution isolation for ensuring secure code execution. More specifically, the fTPM is placed into protected read-only memory to enable the device to use hardware such as the ARM® architecture's TrustZone™ extensions and security primitives (or similar processor architectures), and thus the devices based on such architectures, to provide secure execution isolation within a “firmware-based TPM” without requiring hardware modifications to existing devices.
机译:“基于固件的TPM”或“ fTPM”可确保隔离安全的代码执行,以防止各种潜在的安全漏洞。与基于常规硬件的可信平台模块(TPM)不同,无需使用专用安全处理器硬件或芯片即可实现隔离。通常,首先通过从系统固件或固件可访问的内存或存储中读取fTPM并将其放入设备的只读保护内存中,在OS之前的引导环境中实例化fTPM。一旦实例化,fTPM将启用执行隔离以确保安全的代码执行。更具体地说,将fTPM放置在受保护的只读存储器中,以使设备能够使用诸如ARM®体系结构的TrustZone™扩展和安全性原语(或类似的处理器体系结构)之类的硬件,从而使基于此类体系结构的设备能够提供在“基于固件的TPM”中确保执行隔离,而无需对现有设备进行硬件修改。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号