IP Library Granted Patent US 8,756,417
Granted Patent B1
US 8,756,417 · App. 14/172,474 · Granted Jun 17, 2014

Multi-level assurance trusted computing platform

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,756,417
App. No.
14/172,474
Granted
Jun 17, 2014
Kind
B1
Abstract

A multi-mode Trusted Computing Platform (TCP) comprising a Field Programmable Gate Array (FPGA) device that includes a Type-1-compliant root of trust (ROT), a memory containing a Type-1 security boot image and at least one lower-security boot image, and a memory containing a Type-1-associated operating system (OS) image and at least one lower-security-associated OS image. The TCP is configured to execute a multi-stage boot process that, depending on the presence of one or more valid external inputs, selects and initiates either a Type-1 TCP computing mode or a lower-assurance computing mode.

Claims (30)

1. A multi-mode Trusted Computing Platform (TCP), comprising:

a. a Field Programmable Gate Array (FPGA) device that includes a Type-1-compliant root of trust (ROT);

b. memory containing a Type-1 security boot image and at least one lower-security boot image than the Type-1 security boot image; and

c. memory containing a Type-1-associated operating system (OS) image and at least one lower-security-associated OS image than the Type-1-associated OS image;

wherein the TCP is configured to execute a multi-stage boot process that, depending on presence of one or more valid external inputs, selects and initiates either a Type-1 TCP computing mode or a lower-assurance computing mode than the Type-1 TCP computing mode;

wherein the TCP is configured such that a set of input/output (I/O) devices and applications with which the TCP can interact depends upon the computing mode selected and initiated by the TCP; and

wherein the TCP is configured to have functionality and access that, when in Type-1 TCP computing mode, is restricted and controlled by the FPGA-based TCP (FTCP) per Type-1 protocol and is isolated from all non-Type-1 TCP computing mode functionality, applications, files systems, and devices.

2. The TCP of claim 1 , wherein the one or more valid external inputs include a portable device.

3. The TCP of claim 2 , wherein the portable device is a Crypto Ignition Key (CIK) device, Universal Serial Bus (USB) token, or Radio Frequency Identification (RFID) device.

4. The TCP of claim 1 , wherein the TCP is configured to be unable to access Type-1 TCP functionality and areas when in non-Type-1 TCP computing mode.

5. The TCP of claim 1 , wherein the TCP is configured to check for the presence of the one or more valid external inputs.

6. The TCP of claim 5 , wherein the FPGA is configured to boot a Type-1 compliant FPGA-based TCP (FTCP) upon a successful check for the presence of the one or more valid external inputs corresponding to Type-1 TCP computing mode.

7. The TCP of claim 6 , wherein the FPGA is configured to initiate booting of the FTCP with booting of a FPGA-based root of trust (FROT).

8. The TCP of claim 7 , further comprising a main processor, wherein the FTCP is configured to link the FROT to higher-level security means implemented on the main processor.

9. The TCP of claim 8 , wherein the higher-level security means comprise Trusted Platform Module or TrustZone.

10. The TCP of claim 8 , wherein the higher-level security means comprise a trusted kernel.

11. The TCP of claim 8 , wherein the higher-level security means comprise a hypervisor.

12. The TCP of claim 11 , wherein the FTCP is integrated into the hypervisor.

13. The TCP of claim 1 , wherein the FTCP is configured to surround and control all security-sensitive system elements.

14. The TCP of claim 13 , further comprising a main processor, wherein the FTCP is configured to treat the main processor as untrusted and to maintain hardware control over the main processor.

15. The TCP of claim 14 , wherein the FTCP is configured to perform hardware control that includes enable/disable control, power control, and/or data stream processing.

16. The TCP of claim 14 , wherein the FTCP is configured to perform hardware control that includes in-line data stream processing comprising processing, inspection, and encryption.

17. The TCP of claim 14 , wherein the FTCP is configured to process complex protocol stacks and perform authorization and control of data traffic.

18. The TCP of claim 14 , wherein the FTCP is configured to perform hardware control that includes encrypting and decrypting all main processor read/write memory access.

19. The TCP of claim 14 , wherein the FTCP is configured to control the main processor boot process.

20. The TCP of claim 19 , wherein the FTCP is configured to read, validate, decrypt, verify, and load onto the main processor a Type-1-associated OS image.

21. The TCP of claim 14 , wherein the FTCP is configured to read, validate, decrypt, and verify all main processor sub-processes and applications.

22. The TCP of claim 21 , wherein the FTCP is configured to link validation to higher-level security means implemented on the main processor.

23. The TCP of claim 14 , wherein the FTCP is configured to monitor main processor activity for anomalies.

24. The TCP of claim 14 , wherein the main processor includes one or more physically-integrated secure boot protections.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2017
From: SYPRIS ELECTRONICS, LLC
To: ANALOG DEVICES, INC.
Reel/Frame 041079/0878 →
RELEASE OF SECURITY INTEREST Recorded Sep 15, 2016
From: GILL FAMILY CAPITAL MANAGEMENT INC.
To: SYPRIS ELECTRONICS, LLC
Reel/Frame 039759/0201 →
RELEASE OF SECURITY INTEREST Recorded Sep 15, 2016
From: SIENA LENDING GROUP, LLC
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 039759/0348 →
RELEASE OF SECURITY INTEREST Recorded Sep 15, 2016
From: GREAT ROCK CAPITAL PARTNERS MANAGEMENT, LLC
To: SYPRIS SOLUTIONS, INC.; SYPRIS DATA SYSTEMS, INC.; SYPRIS ELECTRONICS, LLC; SYPRIS TECHNOLOGIES, INC.; SYPRIS TECHNOLOGIES INTERNATIONAL, INC.; SYPRIS TECHNOLOGIES KENTON, INC.; SYPRIS TECHNOLOGIES MARION, LLC; SYPRIS TECHNOLOGIES MEXICAN HOLDINGS, LLC; SYPRIS TECHNOLOGIES NORTHERN, INC.; SYPRIS TECHNOLOGIES SOUTHERN, INC.
Reel/Frame 039759/0328 →
SECURITY AGREEMENT Recorded Nov 5, 2015
From: SYPRIS SOLUTIONS, INC.; SYPRIS DATA SYSTEMS, INC.; SYPRIS ELECTRONICS, LLC; SYPRIS TECHNOLOGIES, INC.; SYPRIS TECHNOLOGIES INTERNATIONAL, INC.; SYPRIS TECHNOLOGIES KENTON, INC.; SYPRIS TECHNOLOGIES MARION, LLC; SYPRIS TECHNOLOGIES MEXICAN HOLDINGS, LLC; SYPRIS TECHNOLOGIES NORTHERN, INC.; SYPRIS TECHNOLOGIES SOUTHERN, INC.
To: GREAT ROCK CAPITAL PARTNERS MANAGEMENT, LLC
Reel/Frame 037055/0796 →
SECURITY INTEREST Recorded Sep 10, 2015
From: SYPRIS TECHNOLOGIES, INC.; SYPRIS ELECTRONICS, LLC
To: GILL FAMILY CAPITAL MANAGEMENT, INC.
Reel/Frame 036529/0261 →
SECURITY INTEREST Recorded Jul 20, 2015
From: SYPRIS ELECTRONICS, LLC
To: MERITOR HEAVY VEHICLE SYSTEMS, LLC
Reel/Frame 036134/0194 →
SECURITY INTEREST Recorded Feb 12, 2015
From: SYPRIS TECHNOLOGIES, INC.; SYPRIS ELECTRONICS, LLC
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 034945/0535 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2014
From: GARDNER, DOUGLAS J
To: SYPRIS ELECTRONICS, LLC
Reel/Frame 032331/0504 →