IP Library › Granted Patent US 9,129,103
Granted Patent B2
US 9,129,103 · App. 13/824,530 · Granted Sep 8, 2015

Authenticate a hypervisor with encoded information

Inventors: Lan Wang (Cypress, TX); Boris Balacheff (Bristol, GB); Chris I. Dalton (Bristol, GB)
Assignee: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
G06F21/44G06F9/45558G06F21/575G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,129,103
App. No.
13/824,530
Granted
Sep 8, 2015
Kind
B2
Abstract

Disclosed embodiments relate to authenticating a hypervisor with encoded hypervisor information. In one embodiment, booting firmware 112 includes instructions to determine whether a received hypervisor 108 is an authentic hypervisor. In one embodiment, booting firmware 112 includes instructions to determine whether the received hypervisor 108 is in a selected configuration. In one embodiment, booting firmware 112 includes instructions to determine whether the receive hypervisor 108 is a selected version.

Claims (27)

1. An electronic device for authenticating a hypervisor, comprising:

a first memory resource to store a hypervisor;

a second memory resource to store a hypervisor digital signature associated with a boot loader for the electronic device, wherein the second memory resource is separate from the first memory resource;

a third memory resource to store firmware for the hypervisor, wherein the firmware includes instructions related to a boot process of the electronic device; and

a processor to execute the instructions to:

access the hypervisor and the hypervisor digital signature to perform one or more authentication operations during the boot process to authenticate the hypervisor, wherein the authentication is performed with the hypervisor stored in a location where the hypervisor is incapable of being updated during the boot process; and

perform at least one of terminating the boot process or providing an error message when the hypervisor is determined to be not authentic.

2. The electronic device of claim 1 , wherein authenticating the hypervisor comprises verifying the hypervisor digital signature with a public key.

3. The electronic device of claim 1 , wherein the firmware comprises a setting indicating whether to determine if the hypervisor is authentic.

4. The electronic device of claim 1 , wherein the instructions further cause the processor to:

determine whether the hypervisor is in a selected configuration by comparing a configuration of the hypervisor to encoded configuration information; and

perform at least one of terminating the boot process or providing an error message when it is determined that the hypervisor is not in the selected configuration.

5. The electronic device of claim 4 , wherein the firmware comprises a setting indicating whether to determine if the hypervisor is in the selected configuration.

6. The electronic device of claim 1 , wherein the instructions further cause the processor to:

determine whether the hypervisor is a selected version by comparing the hypervisor version to encoded version information; and

if determined that the hypervisor is not the selected version, perform at least one of terminating the boot process or providing an error message.

7. The electronic device of claim 6 , wherein the firmware comprises a setting indicating whether to determine if the hypervisor is the selected version.

8. A method for authenticating a hypervisor, comprising:

accessing a hypervisor digital signature for a hypervisor on an electronic device, wherein the hypervisor digital signature and the hypervisor are stored in separate memory resources and the hypervisor digital signature is associated with a boot loader for the electronic device;

accessing firmware for the hypervisor, wherein the firmware includes instructions related to a boot process of the electronic device;

determining, by a processor executing the instructions during the boot process, whether the hypervisor is authentic based on the hypervisor digital signature, wherein the authentication is performed with the hypervisor stored in a location where the hypervisor is incapable of being updated during the boot process; and

performing, by the processor, at least one of terminating the boot process or providing an error message when it is determined that the hypervisor is not authentic.

9. A non-transitory machine-readable storage medium encoded with instructions executable by a processor to authenticate a hypervisor, comprising instructions to:

access a hypervisor digital signature for a hypervisor on an electronic device, wherein the hypervisor digital signature and the hypervisor are stored in separate memory resources and the hypervisor digital signature is associated with a boot loader for the electronic device;

access firmware for the hypervisor, wherein the firmware includes firmware instructions related to a boot process of the electronic device;

determine, by the processor executing the firmware instructions during the boot process, whether the hypervisor is authentic based on the hypervisor digital signature, wherein the authentication is performed with the hypervisor stored in a location where the hypervisor is incapable of being updated during the boot process; and

perform, by the processor, at least one of terminating the boot process or providing an error message when it is determined that the hypervisor is not authentic.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2013
From: WANG, LAN; DALTON, CHRIS I; BALACHEFF, BORIS
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 030139/0719 →
Continuity (1)
Related Publication 20130318595A1 · Nov 28, 2013