IP Library › Granted Patent US 12,189,542
Granted Patent B2
US 12,189,542 · App. 17/543,267 · Granted Jan 7, 2025

Technologies for secure device configuration and management

Inventors: Reshma Lal (Portland, OR); Pradeep M. Pappachan (Tualatin, OR); Luis Kida (Beaverton, OR); Krystof Zmudzinski (Forest Grove, OR); Siddhartha Chhabra (Portland, OR); Abhishek Basak (Bothell, WA); Alpa Narendra Trivedi (Hillsboro, OR); Anna Trikalinou (Hillsboro, OR); David M. Lee (Portland, OR); Vedvyas Shanbhogue (Austin, TX); Utkarsh Y. Kakaiya (Folsom, CA)
Assignee: Intel Corporation
G06F12/1408G06F9/3877G06F9/45558G06F12/0802G06F21/57G06F21/602G06F21/606G06F21/64G06F21/76G06F21/79H04L9/0631H04L9/0637H04L9/083H04L9/0838H04L9/0844H04L9/085H04L9/0891H04L9/321H04L9/3215H04L9/3226H04L9/3268H04L9/3278H04L41/046H04L41/28G06F2009/45591G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,189,542
App. No.
17/543,267
Granted
Jan 7, 2025
Kind
B2
Abstract

Technologies for secure device configuration and management include a computing device having an I/O device. A trusted agent of the computing device is trusted by a virtual machine monitor of the computing device. The trusted agent securely commands the I/O device to enter a trusted I/O mode, securely commands the I/O device to set a global lock on configuration registers, receives configuration data from the I/O device, and provides the configuration data to a trusted execution environment. In the trusted I/O mode, the I/O device rejects a configuration command if a configuration register associated with the configuration command is locked and the configuration command is not received from the trusted agent. The trusted agent may provide attestation information to the trusted execution environment. The trusted execution environment may verify the configuration data and the attestation information. Other embodiments are described and claimed.

Claims (73)

1. A computing device comprising:

processor circuitry coupled to a memory;

an input/output (I/O) device coupled to the processor circuitry; and

a trusted agent coupled to or hosted by the processor circuitry, the trusted agent to:

authenticate the I/O device;

perform an authenticated key exchange protocol with the I/O device in response to authentication of the I/O device;

verify a device configuration report in response to performance of the authenticated key exchange protocol, wherein the device configuration report is indicative of configuration registers of the I/O device; and

send the device configuration report to a trusted execution environment of the computing device in response to verification of the device configuration report, wherein the trusted execution environment includes a predetermined identify that is known to a trusted firmware component of the computing device.

2. The computing device of claim 1 , wherein the trusted agent is further to:

provide a trusted agent attestation report to the trusted firmware component of the computing device;

perform an authenticated key exchange protocol with the trusted execution environment in response to providing of the trusted agent attestation report; and

receive a request to authenticate the I/O device from a host operating system of the computing device, wherein to receive the request to authenticate the I/O device comprises to receive a device certificate, wherein

to authenticate the I/O device comprises to authenticate the I/O device with the device certificate in response to receipt of the request to authenticate the I/O device.

3. The computing device of claim 1 , wherein:

to perform the authenticated key exchange protocol with the I/O device comprises to provision a shared secret key to the I/O device; and

to verify the device configuration report comprises to verify integrity of the device configuration report with the shared secret key.

4. The computing device of claim 1 , wherein:

the host operating system of the computing device to:

command the I/O device to lock configuration of the I/O device;

receive the device configuration report from the I/O device in response to commanding of the I/O device to lock the configuration; and

provide the device configuration report to the trusted agent; and

the trusted agent is further to receive the device configuration report from the host operating system.

5. The computing device of claim 1 , wherein the trusted agent is further to:

determine whether the I/O device is assigned to a different trusted execution environment in response to verification of the device configuration report;

record a binding between the I/O device and the trusted execution environment in response to a determination that the I/O device is not assigned to a different trusted execution environment; and

send the device configuration report to the trusted execution environment further comprises to send the device configuration report to the trusted execution environment in response to recordation of the binding.

6. The computing device of claim 5 , wherein the trusted agent is further to:

receive a request to reclaim the I/O device from the host operating system;

verify, with the trusted firmware component of the computing device, that the trusted execution environment is terminated in response to receipt of the request to reclaim the I/O device; and

remove the binding between the I/O device and the trusted execution environment in response to verification that the trusted execution environment is terminated.

7. The computing device of claim 6 , wherein the trusted agent is further to:

receive a request to reclaim the I/O device from the host operating system;

verify that the I/O device is removed from the computing device in response to receipt of the request to reclaim the I/O device; and

remove the binding between the I/O device and the trusted execution environment in response to verification that the I/O device is removed, and wherein the trusted execution environment to:

verify the device configuration report in response to sending of the device configuration report; and

perform trusted I/O with the I/O device in response to verification of the device configuration report, wherein to perform the trusted I/O comprises to securely transfer, by the I/O device, I/O data with a link encryption key.

8. The computing device of claim 7 , wherein to verify the device configuration report comprises: to verify a device feature of the I/O device, to verify a register address indicated by the device configuration report, or to verify a link encryption status indicated by the device configuration report, wherein the trusted agent comprises a first trust domain and wherein the trusted execution environment comprises a second trust domain.

9. A method comprising:

providing, by a trusted agent of a computing device, a trusted agent attestation report to a trusted firmware component of the computing device;

performing, by the trusted agent, an authenticated key exchange protocol with a trusted execution environment of the computing device in response to providing the trusted agent attestation report;

authenticating, by the trusted agent, an input/output (I/O) device of the computing device;

performing, by the trusted agent, the authenticated key exchange protocol with the I/O device in response to authenticating the I/O device;

verifying, by the trusted agent, a device configuration report in response to performing the authenticated key exchange protocol, wherein the device configuration report is indicative of configuration registers of the I/O device; and

sending, by the trusted agent, the device configuration report to the trusted execution environment in response to verifying the device configuration report, wherein the trusted execution environment includes a predetermined identify that is known to a trusted firmware component of the computing device.

10. The method of claim 9 , further comprising:

performing, by the trusted agent, the authenticated key exchange protocol with the I/O device comprises provisioning a shared secret key to the I/O device; and

verifying, by the trusted agent, the device configuration report comprises verifying integrity of the device configuration report with the shared secret key;

commanding, by a host operating system of the computing device, the I/O device to lock configuration of the I/O device;

receiving, by the host operating system, the device configuration report from the I/O device in response to commanding the I/O device to lock the configuration;

providing, by the host operating system, the device configuration report to the trusted agent; and

receiving, by the trusted agent, the device configuration report from the host operating system.

11. The method of claim 10 , further comprising:

determining, by the trusted agent, whether the I/O device is assigned to a different trusted execution environment in response to verifying the device configuration report;

recording, by the trusted agent, a binding between the I/O device and the trusted execution environment in response to determining that the I/O device is not assigned to a different trusted execution environment; and

sending the device configuration report to the trusted execution environment further comprises sending the device configuration report to the trusted execution environment in response to recording the binding.

12. At least one non-transitory computer-readable medium having stored thereon instructions which, when executed, cause a computing device to facilitate operations comprising:

providing a trusted agent attestation report to a trusted firmware component of the computing device;

performing an authenticated key exchange protocol with a trusted execution environment of the computing device in response to providing the trusted agent attestation report;

authenticating an input/output (I/O) device of the computing device;

performing an authenticated key exchange protocol with the I/O device in response to authenticating the I/O device;

verifying a device configuration report in response to performing the authenticated key exchange protocol, wherein the device configuration report is indicative of configuration registers of the I/O device; and

sending the device configuration report to the trusted execution environment in response to verifying the device configuration report, wherein the trusted execution environment includes a predetermined identify that is known to a trusted firmware component of the computing device.

13. The non-transitory computer-readable medium of claim 12 , wherein the operations further comprise:

performing the authenticated key exchange protocol with the I/O device comprises provisioning a shared secret key to the I/O device; and

verifying the device configuration report comprises verifying integrity of the device configuration report with the shared secret key;

commanding the I/O device to lock configuration of the I/O device;

receiving the device configuration report from the I/O device in response to commanding the I/O device to lock the configuration;

providing the device configuration report to a trusted agent; and

receiving the device configuration report from the host operating system.

14. The non-transitory computer-readable medium of claim 13 , wherein the operations further comprise:

determining whether the I/O device is assigned to a different trusted execution environment in response to verifying the device configuration report; and

recording a binding between the I/O device and the trusted execution environment in response to determining that the I/O device is not assigned to a different trusted execution environment; and

sending the device configuration report to the trusted execution environment further comprises to send the device configuration report to the trusted execution environment in response to recording the binding.

Continuity (3)
Continuation 16444053 · Jun 18, 2019
Provisional Application 62687403 · Jun 20, 2018
Related Publication 20220091998A1 · Mar 24, 2022
References Cited (99)
US 7523097B1 · Wilson · 2009 [cited by applicant]
US 7716389B1 · Bruce et al. · 2010 [cited by applicant]
US 9141769B1 · Hitchcock et al. · 2015 [cited by applicant]
US 9215249B2 · Smith · 2015 [cited by applicant]
US 9524399B1 · Takahashi · 2016 [cited by applicant]
US 9769123B2 · Grewal et al. · 2017 [cited by applicant]
US 9954826B2 · Buer et al. · 2018 [cited by applicant]
US 10057243B1 · Kumar et al. · 2018 [cited by applicant]
US 10291395B1 · Nenov et al. · 2019 [cited by applicant]
US 10303645B2 · Franke et al. · 2019 [cited by applicant]
US 10419931B1 · Sohail et al. · 2019 [cited by applicant]
US 10469265B2 · Xing · 2019 [cited by applicant]
US 10515317B1 · Kenthapadi et al. · 2019 [cited by applicant]
US 10664179B2 · Alexandrovich et al. · 2020 [cited by applicant]
US 20030235310A1 · Saito et al. · 2003 [cited by applicant]
US 20040250097A1 · Cheung et al. · 2004 [cited by applicant]
US 20060126835A1 · Kim et al. · 2006 [cited by applicant]
US 20080209203A1 · Haneda · 2008 [cited by applicant]
US 20100178977A1 · Kim et al. · 2010 [cited by applicant]
US 20110280402A1 · Ibrahim · 2011 [cited by examiner]
US 20110314282A1 · Tanaka · 2011 [cited by examiner]
US 20130254494A1 · Oxford · 2013 [cited by applicant]
US 20140047174A1 · Sakthikumar · 2014 [cited by applicant]
US 20140056307A1 · Hutchison et al. · 2014 [cited by applicant]
US 20140177823A1 · Gopal et al. · 2014 [cited by applicant]
US 20140281544A1 · Paczkowski et al. · 2014 [cited by applicant]
US 20140281587A1 · Ignatchenko · 2014 [cited by applicant]
US 20140304649A1 · Phegade · 2014 [cited by applicant]
US 20150113241A1 · Martin et al. · 2015 [cited by applicant]
US 20150244530A1 · Clayton et al. · 2015 [cited by applicant]
US 20150249654A1 · Mundra et al. · 2015 [cited by applicant]
US 20150347768A1 · Martin et al. · 2015 [cited by applicant]
US 20160119318A1 · Zollinger et al. · 2016 [cited by applicant]
US 20160277372A1 · Shah et al. · 2016 [cited by applicant]
US 20160352701A1 · Vora et al. · 2016 [cited by applicant]
US 20160381005A1 · Mj et al. · 2016 [cited by applicant]
US 20170005809A1 · Adam et al. · 2017 [cited by applicant]
US 20170006030A1 · Krishnamoorthy et al. · 2017 [cited by applicant]
US 20170024568A1 · Pappachan et al. · 2017 [cited by applicant]
US 20170024569A1 · Xing et al. · 2017 [cited by applicant]
US 20170024570A1 · Pappachan et al. · 2017 [cited by applicant]
US 20170026171A1 · Lal et al. · 2017 [cited by applicant]
US 20170093571A1 · Satpathy et al. · 2017 [cited by applicant]
US 20170104597A1 · Negi et al. · 2017 [cited by applicant]
US 20170171194A1 · Durham et al. · 2017 [cited by applicant]
US 20170185514A1 · Blinzer et al. · 2017 [cited by applicant]
US 20180062829A1 · Suresh et al. · 2018 [cited by applicant]
US 20180084415A1 · Babbage · 2018 [cited by examiner]
US 20180107608A1 · Kaplan et al. · 2018 [cited by applicant]
US 20180114013A1 · Sood et al. · 2018 [cited by applicant]
US 20180365406A1 · Elnekaveh et al. · 2018 [cited by applicant]
US 20180365424A1 · Callaghan et al. · 2018 [cited by applicant]
US 20190013965A1 · Sindhu et al. · 2019 [cited by applicant]
US 20190044724A1 · Sood et al. · 2019 [cited by applicant]
US 20190081776A1 · Satou · 2019 [cited by applicant]
US 20190132136A1 · Scarlata et al. · 2019 [cited by applicant]
US 20190319785A1 · Kumar et al. · 2019 [cited by applicant]
US 20200159657A1 · Kida et al. · 2020 [cited by applicant]
US 20210081577A1 · Zhang · 2021 [cited by applicant]
CA 2303297C · 2008 [cited by applicant]
CN 110618947A · 2019 [cited by applicant]
DE 102019113352A1 · 2019 [cited by applicant]
WO 9914881A2 · 1999 [cited by applicant]
WO WO2013081441A1 · 2013 [cited by examiner]
Office Action issued in U.S. Appl. No. 16/444,053, mailed Dec. 9, 2021, 12 pages. [cited by applicant]
Advisory Action, U.S. Appl. No. 16/232,143, filed Jan. 14, 2022, 3 pages. [cited by applicant]
Advisory Action, U.S. Appl. No. 16/234,726, filed Dec. 1, 2022, 3 pages. [cited by applicant]
Advisory Action, U.S. Appl. No. 16/234,726, filed Sep. 20, 2021, 3 pages. [cited by applicant]
Advisory Action, U.S. Appl. No. 16/236,074, filed Jul. 25, 2022, 2 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/232,143, filed Oct. 25, 2021, 51 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/234,726, filed Jul. 20, 2022, 19 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/234,726, filed Jun. 8, 2021, 17 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/236,074, filed May 10, 2022, 18 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 17/496,147, filed Mar. 21, 2023, 13 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 18/060,702, filed Mar. 21, 2024, 12 pages. [cited by applicant]
Hu et al., “Certificate Revocation Guard (CRG): An Efficient Mechanism for Checking Certificate Revocation,” 2016 IEEE 41st Conference on Local Computer Networks (LCN), Dubai, 2016, pp. 527-530. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/232,139, filed Jan. 14, 2021, 15 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/232,143, filed Jan. 15, 2021, 43 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/232,143, filed Jul. 8, 2021, 48 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/234,726, filed Dec. 16, 2021, 22 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/234,726, filed Jan. 13, 2021, 16 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/236,074, filed Dec. 10, 2021, 15 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/444,053, filed Dec. 9, 2021, 12 pages. [cited by applicant]
Non-Final Office Action, U.S. App. No. 17/446,194, filed Oct. 12, 2023, 11 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/496,147, filed Nov. 10, 2022, 12 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/724,743, filed Nov. 25, 2022, 42 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/060,702, filed Sep. 21, 2023, 11 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/232,139, filed Jul. 8, 2021, 11 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/232,143, filed Apr. 26, 2022, 2 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/232,143, filed Mar. 11, 2022, 22 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/232,146, filed May 28, 2021, 22 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/234,726, filed Jan. 19, 2023, 12 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/236,074, filed Sep. 2, 2022, 12 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/444,053, filed Apr. 18, 2022, 8 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/724,743, filed Mar. 21, 2023, 10 pages. [cited by applicant]
Restriction Requirement, U.S. Appl. No. 16/444,053, Sep. 21, 2021, 7 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 18/060,702, Aug. 15, 2024, 11 pages. [cited by applicant]
Final Office Action, U.S. App. No. 17/446,194, May 9, 2024, 12 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 18/060,702, Sep. 5, 2024, 7 pages. [cited by applicant]
Cited By (1)
US 12,657,283