首页> 外国专利> Method and system for bootstrapping a trusted server having redundant trusted platform modules

Method and system for bootstrapping a trusted server having redundant trusted platform modules

机译:用于引导具有冗余可信平台模块的可信服务器的方法和系统

摘要

Multiple trusted platform modules within a data processing system are used in a redundant manner that provides a reliable mechanism for securely storing secret data at rest that is used to bootstrap a system trusted platform module. A hypervisor requests each trusted platform module to encrypt a copy of the secret data, thereby generating multiple versions of encrypted secret data values, which are then stored within a non-volatile memory within the trusted platform. At some later point in time, the encrypted secret data values are retrieved, decrypted by the trusted platform module that performed the previous encryption, and then compared to each other. If any of the decrypted values do not match a quorum of values from the comparison operation, then a corresponding trusted platform module for a non-matching decrypted value is designated as defective because it has not been able to correctly decrypt a value that it previously encrypted.
机译:数据处理系统中的多个可信平台模块以冗余方式使用,该冗余模块提供了一种可靠的机制,用于安全地存储静态数据,以用于引导系统可信平台模块。系统管理程序请求每个可信平台模块对机密数据的副本进行加密,从而生成加密的机密数据值的多个版本,然后将其存储在可信平台内的非易失性内存中。在以后的某个时间点,已加密的机密数据值将被检索,由执行先前加密的受信任平台模块解密,然后相互比较。如果任何解密的值与比较操作的值的定额不匹配,则用于不匹配的解密值的对应受信任平台模块将被指定为有缺陷,因为它无法正确解密先前加密的值。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号