IP Library Granted Patent US 11,157,623
Granted Patent B2
US 11,157,623 · App. 16/280,351 · Granted Oct 26, 2021

Technologies for secure hardware and software attestation for trusted I/O

Inventors: Pradeep M. Pappachan (Hillsboro, OR); Reshma Lal (Hillsboro, OR); Bin Xing (Hillsboro, OR); Siddhartha Chhabra (Portland, OR); Vincent R. Scarlata (Beaverton, OR); Steven B. McGowan (Portland, OR)
Assignee: INTEL CORPORATION
G06F21/57G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,157,623
App. No.
16/280,351
Granted
Oct 26, 2021
Kind
B2
Abstract

Technologies for trusted I/O attestation and verification include a computing device with a cryptographic engine and one or more I/O controllers. The computing device collects hardware attestation information associated with statically attached hardware I/O components that are associated with a trusted I/O usage protected by the cryptographic engine. The computing device verifies the hardware attestation information and securely enumerates one or more dynamically attached hardware components in response to verification. The computing device collects software attestation information for trusted software components loaded during secure enumeration. The computing device verifies the software attestation information. The computing device may collect firmware attestation information for firmware loaded in the I/O controllers and verify the firmware attestation information. The computing device may collect application attestation information for a trusted application that uses the trusted I/O usage and verify the application attestation information. Other embodiments are described and claimed.

Claims (24)

1. An apparatus, comprising:

an application processor;

a memory;

an input/output (I/O) subsystem communicatively coupled to the processor and the memory;

a cryptographic engine to secure one or more direct memory access (DMA) channels;

a secure, fused memory to store persistently a first platform device identifier associated with the apparatus; and

a security subsystem, comprising a secure processing element to:

collect attestation information of one or more hardware or software components of the apparatus;

send the attestation information to a remote verification service;

securely enumerate one or more dynamically attached hardware I/O components in response to a verification of the hardware I/O components by the remote verification service;

load a secure bus enumerator for the one or more dynamically attached hardware I/O components; and

initialize one or more protected direct memory access (DMA) channels associated with a trusted I/O usage of the security subsystem and protected by the cryptographic engine.

2. The apparatus of claim 1 , the secure processing element to:

discover one or more statically attached hardware I/O components.

3. The apparatus of claim 2 , the secure processing element to:

generate one or more secure enclave reports, wherein each secure enclave report is indicative of a cryptographic measurement of a trusted software component.

4. The apparatus of claim 1 , the secure processing element to:

determine one or more hardware I/O devices of the I/O subsystem;

determine, based on the attestation information, that the one or more hardware I/O devices required is reachable via a secure I/O path from a trusted application associated with the I/O subsystem; and

verify an identity of a trusted software component associated with the secure I/O path.

5. The apparatus of claim 1 , the secure processing element to:

verify at least a portion of the attestation information by a trusted application executing on the apparatus.

6. The apparatus of claim 5 , further comprising a firmware attestation module, executed by the secure processing element, to (i) collect firmware attestation information associated with one or more I/O controllers of the apparatus, and (ii) verify the firmware attestation information.

7. The apparatus of claim 1 , further comprising an application attestation module, executed by the secure processing element, to (i) collect application attestation information associated with a trusted application of the apparatus, wherein the trusted application uses a trusted I/O usage, and (ii) verify the application attestation information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2019
From: PAPPACHAN, PRADEEP M.; LAL, RESHMA; XING, BIN; CHHABRA, SIDDHARTHA; SCARLATA, VINCENT R.; MCGOWAN, STEVEN B.
To: INTEL CORPORATION
Reel/Frame 048768/0283 →
Continuity (5)
Continuation 14974960 · Dec 18, 2015
Provisional Application 62194763 · Jul 20, 2015
Provisional Application 62195148 · Jul 21, 2015
Provisional Application 62198779 · Jul 30, 2015
Related Publication 20190278911A1 · Sep 12, 2019
Cited By (2)
US 12,339,977 US 12,499,237