IP Library Granted Patent US 12694120
Granted Patent B2
US 12694120 · App. 18/699,298 · Granted Jul 28, 2026

First node, second node, third node, computing system and methods performed thereby for handling information indicating one or more features supported by a processor

Inventors: Thomas Nyman (Sollentuna, SE); Merve Turhan (Sollentuna, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
G06F21/575G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12694120
App. No.
18/699,298
Granted
Jul 28, 2026
Kind
B2
Abstract

A method, performed by a first node. The method is for handling information indicating one or more features supported by a processor used by the first node. The first node operates in a computing system. The first node retrieves the information from the processor, before a hypervisor is loaded during a boot sequence. The first node determines a first digest of the information by using an algorithm supported by a hardware-based secure environment, associated to the processor. The first node extends predefined and reserved Platform Control Register (PCR) values at the hardware-based secure environment with the determined first digest. The first node thereby initiates indicating the one or more features supported by the processor to a second node operating in the computing system based on the determined first digest and the extended PCR.

Claims (37)

1 . A method, performed by a first node, the method being for handling information indicating one or more features supported by a processor used by the first node, the first node operating in a computing system, the method comprising:

retrieving the information from the processor, before a hypervisor is loaded during a boot sequence,

determining a first digest of the information by using an algorithm supported by a hardware-based secure environment, associated to the processor, and

extending predefined and reserved Platform Control Register (PCR) values at the hardware-based secure environment with the determined first digest, thereby initiating indicating the one or more features supported by the processor to a second node operating in the computing system based on the determined first digest and the extended PCR.

2 . The method according to claim 1 , wherein

a. the first node manages a shim layer or a bootloader,

b. the hardware-based secure environment is a Trusted Platform Module (TPM) and

c. the information is Central Processor Unit identification (CPUID) information.

3 . A method, performed by a third node, the method being for handling information indicating one or more features supported by a processor used by the third node, the third node operating in a computing system, the method comprising:

establishing an authenticated and integrity protected channel to a hardware-based secure environment, associated to the processor,

retrieving predefined and reserved Platform Control Register (PCR) values from the hardware-based secure environment, the PCR values comprising a first digest of information from the processor,

retrieving the information from the processor,

generating a second digest of the retrieved information, and

validating that the second digest of the retrieved information matches the values stored in the PCR, thereby initiating indicating the information to a second node operating in the computing system based on the validated digest.

4 . The method according to claim 3 , further comprising:

obtaining one of an incremented monotonic count as a first count or a first time stamp from a trusted source, and

generating a first attestation quote comprising the information and the obtained one of the first monotonic count and the first time stamp from the trusted source, wherein the initiating indicating the information to the second node is further based on the generated first attestation quote.

5 . The method according to claim 4 , further comprising:

storing, in a storage the generated first attestation quote, wherein the initiating indicating the information is further based on the stored first attestation quote.

6 . The method according to claim 3 , wherein at least one of:

a. the third node manages a Software Guard Extensions (SGX) Enclave that runs in a Virtual Machine (VM) host,

b. the hardware-based secure environment is a Trusted Platform Module (TPM), and

c. the information is Central Processor Unit identification (CPUID) information.

7 . A method, performed by a second node, the method being for handling information indicating one or more features supported by a processor used by the second node, the second node operating in a computing system, the method comprising:

fetching, from a storage, a first attestation quote comprising the information, one of a first monotonic count and a first time stamp from a trusted source, and a Provisioning Certification Key (PCK) certificate,

obtaining one of a second monotonic count or a second time stamp from the trusted source,

validating the fetched first attestation quote by:

i. generating a second attestation quote,

ii. determining whether or not the PCK certificate is valid, and a signature in the fetched first attestation quote is validated against the PCK Certificate, and

iii. determining whether or not at least one of:

a) the first monotonic count equals the second monotonic count, and

b) a difference between the second time stamp and the first time stamp is within a threshold,

extracting the information from the fetched first attestation quote with the proviso that the fetched first attestation quote is validated, and

initiating providing a virtual machine service based on the extracted information.

8 . The method according to claim 7 , wherein at least one of:

a. the second node manages a Software Guard Extensions (SGX) Enclave that is tasked to process a workload, and

b. the information is Central Processor Unit identification (CPUID) information.