IP Library Granted Patent US 11,714,910
Granted Patent B2
US 11,714,910 · App. 16/007,722 · Granted Aug 1, 2023

Measuring integrity of computing system

Inventors: Geoffrey Ndu (Bristol, GB); David Altobelli (Houston, TX); Nigel Edwards (Bristol, GB); Luis Luciani, Jr. (Houston, TX)
Assignee: Hewlett Packard Enterprise Development LP
G06F21/577G06F21/554G06F21/575G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,714,910
App. No.
16/007,722
Granted
Aug 1, 2023
Kind
B2
Abstract

Examples disclosed herein relate to integrity monitoring of a computing system. Trust of state information is verified. Kernel code and module code are loaded into memory that is accessible to a device separate from a processor that loads the kernel code and module code. A measurement module is verified and loaded into memory. The state information can correspond to multiple symbols. The measurement module can measure the state information corresponding to each of the respective symbols to generate a set of initial measurements. The set of initial measurements can be provided to a device for integrity monitoring.

Claims (33)

1. A method comprising:

verifying trust in a plurality of state information including a kernel code and a module code to load onto a computing system;

loading, by at least one processor of the computing system, the kernel code and the module code to a memory,

wherein the memory is accessible by a device separate from the at least one processor,

verifying and loading a measurement module into the memory;

wherein the state information corresponds to a plurality of symbols;

measuring, by the measurement module, after the measurement module is loaded and before loading a plurality of other modules, the state information corresponding to each of the symbols to generate a set of respective initial measurements; and

providing the set of initial measurements associated with the respective symbols to the device for integrity monitoring;

monitoring, by the device, respective state information in the memory corresponding to each of the symbols by:

measuring, by the device, the state information corresponding to each of the symbols to

determine a second set of measurements; comparing, by the device, the second set of the measurements with the initial measurements; determining, by the device, that there is a violation based on the comparison; and

performing, by the device, a security action based on the determination of the violation,

loading, by the measurement module, a hook into a function for loading the other modules, wherein each of the other modules correspond to other symbols;

measuring, by the measurement module, respective baseline measurements associated with each of the other symbols; and

sending the respective baseline measurements to the device, wherein the device monitors the respective memory corresponding to each of the symbols and other symbols for violations.

2. The method of claim 1 , wherein monitoring includes regularly re-measuring the state information corresponding to the respective symbols and other symbols to determine whether a violation exists.

3. A computing system comprising:

at least one processor;

memory coupled to the at least one processor; a device separate from the at least one processor capable of accessing the memory,

wherein the at least one processor is to:

load a kernel code and a module code to the memory,

wherein the kernel code and the module code are included as part of state information,

wherein a trust of the state information is verified;

verify and load a measurement module into the memory, wherein the state information corresponds to a plurality of symbols;

measure, using the measurement module, after the measurement module is loaded and before loading a plurality of other modules, the state information corresponding to each of the symbols to generate a set of respective initial measurements; and provide the set of initial measurements associated with the respective symbols to the device for integrity monitoring,

wherein the device is further to:

measure, the state information corresponding to each of the symbols to determine a second set of measurements;

compare the second set of measurements with the initial measurements;

determine that there is a violation based on the comparison; and perform a security action based on the determination of the violation;

wherein the measurement module is further to load a hook into a function for loading the other modules,

wherein each of the other modules correspond to other symbols;

measuring, by the measurement module, respective baseline measurements associated with other state information for each of the other symbols; and

sending the respective baseline measurements to the device, wherein the device monitors the respective memory corresponding to each of the symbols and other symbols for an integrity violation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2020
From: NDU, GEOFFREY; ALTOBELLI, DAVID; EDWARDS, NIGEL; LUCIANI, LUIS, JR.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 053044/0459 →
Continuity (1)
Related Publication 20190384918A1 · Dec 19, 2019
Cited By (1)
US 12,634,146