发明名称 Apparatus for hardware accelerated runtime integrity measurement
摘要 Techniques are described for providing processor-based dedicated fixed function hardware to perform runtime integrity measurements for detecting attacks on system supervisory software, such as a hypervisor or native Operating System (OS). The dedicated fixed function hardware is provided with memory addresses of the system supervisory software for monitoring. After obtaining the memory addresses and other information required to facilitate integrity monitoring, the dedicated fixed function hardware activates a lock-out to prevent reception of any additional information, such as information from a corrupted version of the system supervisory software. The dedicated fixed function hardware then automatically performs periodic integrity measurements of the system supervisory software. Upon detection of an integrity failure, the dedicated fixed function hardware uses out-of-band signaling to report that an integrity failure has occurred.;The dedicated fixed function hardware provides for runtime integrity verification of a platform in a secure manner without impacting the performance of the platform.
申请公布号 US9361244(B2) 申请公布日期 2016.06.07
申请号 US201113993037 申请日期 2011.12.29
申请人 Intel Corporation 发明人 Hiremane Radhakrishna;Keshavamurthy Anil S.
分类号 G06F12/14;G06F21/57 主分类号 G06F12/14
代理机构 Nicholson De Vos Webster & Elliott LLP 代理人 Nicholson De Vos Webster & Elliott LLP
主权项 1. A processor comprising logic to: obtain memory addresses that point to at least a portion of a supervisory software component; activate a lock-out to prevent obtaining further memory addresses; and activate a dedicated timer to periodically trigger a run-time integrity measurement of the supervisory software component.
地址 Santa Clara CA US