首页> 外国专利> A secure machine platform that interfaces with the operating system and customized control programs

A secure machine platform that interfaces with the operating system and customized control programs

机译:与操作系统和定制控制程序对接的安全机器平台

摘要

A combined-hardware-and-software secure-platform interface to which operating systems and customized control programs interface within a computer system. The combined-hardware-and-software secure-platform interface employs a hardware platform that provides at least four privilege levels, non-privileged instructions, non-privileged registers, privileged instructions, privileged registers, and firmware interfaces. The combined-hardware-and-software secure-platform interface conceals all privileged instructions, privileged registers, and firmware interfaces and privileged registers from direct access by operating systems and custom control programs, providing to the operating systems and custom control programs the non-privileged instructions and non-privileged registers provided by the hardware platform as well as a set of callable software services. The callable services provide a set of secure-platform management services for operational control of hardware resources that neither exposes privileged instructions, privileged registers, nor firmware interfaces of the hardware nor simulates privileged instructions and privileged registers. The callable services also provide a set of security-management services that employ internally generated secret data, each compartmentalized security-management service managing internal secret data without exposing the internal secret data to computational entities other than the security-management service itself.
机译:组合的硬件和软件安全平台接口,操作系统和自定义的控制程序在计算机系统内与之连接。硬件和软件的组合安全平台接口采用了一个硬件平台,该平台至少提供四个特权级别,非特权指令,非特权寄存器,特权指令,特权寄存器和固件接口。硬件和软件的组合安全平台界面隐藏了所有特权指令,特权寄存器以及固件接口和特权寄存器,以防止操作系统和定制控制程序直接访问,从而向操作系统和定制控制程序提供非特权硬件平台提供的指令和非特权寄存器以及一组可调用的软件服务。可调用服务提供了一组用于安全控制硬件资源的安全平台管理服务,这些服务既不公开特权指令,特权寄存器或硬件的固件接口,也不模拟特权指令和特权寄存器。可调用服务还提供了一组使用内部生成的秘密数据的安全管理服务,每个分段的安全管理服务管理内部秘密数据,而不将内部秘密数据暴露给安全管理服务本身以外的计算实体。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号