发明名称 POLICIES FOR SECRETS IN TRUSTED EXECUTION ENVIRONMENTS
摘要 A computing device executes one or more trusted execution environment (TEE) processes in a TEE of a processor. The one or more TEE processes cryptographically protect a secret and a policy. The policy specifies a plurality of conditions on usage of the secret. A particular non-TEE process generates a request whose fulfillment involves an action requiring use of the secret. Responsive to the request, one or more non-TEE processes determine whether a first subset of the plurality of conditions is satisfied. Responsive to the first subset of the plurality of conditions being satisfied, the one or more TEE processes determine that a second, different subset of the plurality of conditions is satisfied. Responsive to determining the second subset of the plurality of conditions is satisfied, the one or more TEE processes use the secret to perform the action.
申请公布号 WO2016190968(A1) 申请公布日期 2016.12.01
申请号 WO2016US26191 申请日期 2016.04.06
申请人 GOOGLE INC. 发明人 POIESZ, Benjamin David;ABRAMSON, Andrew;RAO, Neel;WILLDEN, Shawn Edward;MORALES, Andres Guillermo;MILLER, James Brooks
分类号 G06F21/74;G06F21/62 主分类号 G06F21/74
代理机构 代理人
主权项
地址