IP Library Patent Application 18387409
Patent Application
App. No. 18/387,409

FLEXIBLE CONTAINER ATTESTATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/387,409
Abstract

Data integrity logic is executable by a processor to generate a data integrity code using a hardware-based secret. A container manager, executable by the processor, creates a secured container including report generation logic that determines measurements of the secured container, generates a report according to a defined report format, and sends a quote request including the report. The defined report format includes a field to include the measurements and a field to include the data integrity code, and the report format is compatible for consumption by any one of a plurality of different quote creator types.

Claims (47)

1 .- 15 . (canceled)

16 . A processor comprising:

first circuitry to receive a report generation instruction, the report generation instruction corresponding to a plurality of parameters, including an identifier of a secured container and a nonce; and

second circuitry to perform operations corresponding to the report generation instruction, including to:

access a hardware-based key;

determine a measurement of contents of the secured container;

generate a report according to a defined report format, wherein the defined report format includes a plurality of fields, including a field to include the measurement; and

store the report in memory.

17 . The processor of claim 16 , wherein the defined report format includes a defined length.

18 . The processor of claim 16 , wherein the report identifies a type of technology used to generate the report.

19 . The processor of claim 16 , wherein the report includes a field to store information specific to the secured container.

20 . The processor of claim 16 , wherein the secured container is a secured virtual machine.

21 . The processor of claim 16 , wherein the report generation instruction is a privileged instruction.

22 . The processor of claim 16 , wherein the report generation instruction is called through an API.

23 . The processor of claim 16 , wherein the defined report format includes a defined length, wherein the report includes a field to store information specific to the secured container, and wherein the secured container is a secured virtual machine.

24 . A processor comprising:

first circuitry to receive binary code and a plurality of parameters associated with the binary code, the plurality of parameters including an identifier of a secured container and a nonce; and

second circuitry to perform operations corresponding to the binary code, including to:

access a hardware-based key;

determine a measurement of contents of the secured container;

generate a report according to a defined report format, wherein the defined report format includes a plurality of fields, including a field to include the measurement; and

store the report in memory.

25 . The processor of claim 24 , wherein the defined report format includes a defined length.

26 . The processor of claim 24 , wherein the report identifies a type of technology used to generate the report.

27 . The processor of claim 24 , wherein the report includes a field to store information specific to the secured container.

28 . The processor of claim 24 , wherein the secured container is a secured virtual machine.

29 . The processor of claim 24 , wherein the binary code corresponds to a privileged level.

30 . The processor of claim 24 , wherein the binary code corresponds to an API.

31 . The processor of claim 24 , wherein the defined report format includes a defined length, wherein the report includes a field to store information specific to the secured container, and wherein the secured container is a secured virtual machine.

32 . At least one machine-readable storage medium storing binary code, the binary code associated with a plurality of parameters, including an identifier of a secured container and a nonce, the binary code executable by a machine to cause the machine to perform operations corresponding to the binary code, including to:

access a hardware-based key;

determine a measurement of contents of the secured container;

generate a report according to a defined report format, wherein the defined report format includes a plurality of fields, including a field to include the measurement; and

store the report in memory.

33 . The at least one machine-readable storage medium of claim 32 , wherein the defined report format includes a defined length, and wherein the secured container is a secured virtual machine.

34 . The at least one machine-readable storage medium of claim 33 , wherein the report identifies a type of technology used to generate the report, and wherein the report includes a field to store information specific to the secured container.

35 . The at least one machine-readable storage medium of claim 33 , wherein the binary code corresponds to an API.

36 . An apparatus comprising:

a processor comprising:

a cache;

a fetch unit to fetch an instruction of an instruction set of the processor;

a decoder coupled with the fetch unit, the decoder to decode the instruction; and

circuitry coupled with the decoder, the circuitry to perform operations corresponding to the instruction, including to:

obtain first measurements of contents and configuration of a trust domain to be launched on a computing platform, wherein the trust domain includes a software container in which software is to be run;

obtain second measurements of the computing platform;

obtain a data integrity code generated from a key accessible only to a particular processor of the computing platform; and

generate an integrity-protected trust domain report structure for the trust domain, wherein the integrity-protected trust domain report structure has a defined report structure and comprises the first measurements, the second measurements, and the data integrity code generated from a hardware-secured key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2026
From: INTEL CORPORATION
To: INTEL PRODUCTS IP LLC
Reel/Frame 075991/0981 →