IP Library Granted Patent US 10,042,649
Granted Patent B2
US 10,042,649 · App. 15/402,661 · Granted Aug 7, 2018

System and method for execution of a secured environment initialization instruction

Inventors: James A. Sutton, II (Portland, OR); David W. Grawrock (Aloha, OR)
Assignee: Intel Corporation
G06F9/4403G01N23/223G01N33/502G01N33/6872G06F9/44505G06F12/0802G06F12/145G06F12/1458G06F13/4282G06F21/57G06F21/572H04L9/32H04L9/3247G01N2223/076G06F2212/1052G06F2212/60G06F2213/0026G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,042,649
App. No.
15/402,661
Granted
Aug 7, 2018
Kind
B2
Abstract

A method and apparatus for initiating secure operations in a microprocessor system is described. In one embodiment, one initiating logical processor initiates the process by halting the execution of the other logical processors, and then loading initialization and secure virtual machine monitor software into memory. The initiating processor then loads the initialization software into secure memory for authentication and execution. The initialization software then authenticates and registers the secure virtual machine monitor software prior to secure system operations.

Claims (48)

1. A system comprising:

a plurality of processors;

an interconnect to couple two or more of the processors;

a system memory coupled to the two or more processors;

and an interface to at least one storage device;

at least one of the processors including:

a trusted memory of the processor to support secure initialization operations,

secure initialization logic of the processor to establish a root of trust for a secure execution environment,

execution logic of the processor to execute secure initialization program code within the secure execution environment, at least a portion of the secure initialization program code to be copied into the trusted memory,

the execution logic to validate the secure initialization program code prior to execution,

the execution logic to validate a virtual machine monitor (VMM) and copy the VMM to a trusted system memory area within the secure execution environment.

2. The system of claim 1 , further comprising access logic to permit or deny access to memory pages within the system memory.

3. The system of claim 1 , wherein validation of the VMM by the execution unit is to include cryptographic authentication of the VMM.

4. The system of claim 1 , further comprising a storage device coupled to the interface.

5. The system of claim 1 , wherein the interface is to a Peripheral Component Interconnect (PCI) bus.

6. The system of claim 1 , wherein the interface is a serial interface.

7. The system of claim 1 , wherein the interface is to a Universal Serial Bus (USB).

8. The system of claim 1 , wherein the interface is to a Low Pin Count (LPC) bus.

9. The system of claim 1 , wherein the interface is to an Integrated Drive Electronics (IDE) bus.

10. The system of claim 1 , wherein the interface is to a Small Computer Systems Interconnect (SCSI) bus.

11. A system comprising:

a plurality of processors;

an interconnect to couple two or more of the processors;

a system memory coupled to the two or more processors;

and an interface to at least one storage device;

at least one of the processors including:

a trusted memory of the processor to support secure initialization operations,

execution logic of the processor, the execution logic including secure initialization logic to establish a root of trust for a secure execution environment,

the execution logic to execute secure initialization program code within the secure execution environment, at least a portion of the secure initialization program code to be copied into the trusted memory,

the execution logic to validate the secure initialization program code prior to execution,

the execution logic to validate a virtual machine monitor (VMM) and copy the VMM to a trusted system memory area within the secure execution environment.

12. The system of claim 11 , further comprising access logic to permit or deny access to memory pages within the system memory.

13. The system of claim 11 , wherein validation of the VMM by the execution unit is to include cryptographic authentication of the VMM.

14. A system comprising:

a plurality of processors;

an interconnect to couple two or more of the processors;

a system memory coupled to the two or more processors;

and a serial interface to at least one storage device;

at least one of the processors including:

a trusted memory of the processor to support secure initialization operations,

secure initialization logic of the processor to establish a root of trust for a secure execution environment,

execution logic of the processor to execute secure initialization program code within the secure execution environment, at least a portion of the secure initialization program code to be copied into the trusted memory,

the execution logic to validate the secure initialization program code prior to execution,

the execution logic to validate a virtual machine monitor (VMM) and copy the VMM to a trusted system memory area within the secure execution environment.

15. The system of claim 14 , further comprising access logic to permit or deny access to memory pages within the system memory.

16. The system of claim 14 , wherein validation of the VMM by the execution unit is to include cryptographic authentication of the VMM.

17. The system of claim 14 , wherein the serial interface is to a Peripheral Component Interconnect (PCI) bus.

18. The system of claim 14 , wherein the serial interface is to a Universal Serial Bus (USB).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2022
From: INTEL CORPORATION
To: TAHOE RESEARCH, LTD.
Reel/Frame 061175/0176 →
Continuity (8)
Continuation 14864450 · Sep 24, 2015
Continuation 14222939 · Mar 24, 2014
Continuation 13835997 · Mar 15, 2013
Continuation 13444450 · Apr 11, 2012
Continuation 12455844 · Jun 8, 2009
Continuation 11096618 · Mar 31, 2005
Continuation 10112169 · Mar 29, 2002
Related Publication 20170132014A1 · May 11, 2017