发明名称 Updateable Secure Kernel Extensions
摘要 A method, computer program product, and data processing system for providing an updateable encrypted operating kernel are disclosed. In a preferred embodiment, secure initialization hardware decrypts a minimal secure kernel containing sensitive portions of data and/or code into a portion of the processor-accessible memory space, from which the kernel is executed. Most system software functions are not directly supported by the secure kernel but are provided by dynamically loaded kernel extensions that are encrypted with a public key so that they can only be decrypted with a private key possessed by the secure kernel. The public/private key pair is processor-specific. Before passing control to a kernel extension the secure kernel deletes a subset of its sensitive portions, retaining only those sensitive portions needed to perform the task(s) delegated to the kernel extension. Which sensitive portions are retained is determined by a cryptographic key with which the kernel extension is signed.
申请公布号 US2008301440(A1) 申请公布日期 2008.12.04
申请号 US20070754658 申请日期 2007.05.29
申请人 PLOUFFE JR WILFRED E;SHIMIZU KANNA;ZBARSKY VLADIMIR 发明人 PLOUFFE, JR. WILFRED E.;SHIMIZU KANNA;ZBARSKY VLADIMIR
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址