Interface for ensuring system boot image integrity and authenticity

Number of patents in Portfolio can not be more than 2000

United States of America Patent

PATENT NO 6560706
SERIAL NO

09234757

Stats

ATTORNEY / AGENT: (SPONSORED)

Importance

Loading Importance Indicators... loading....

Abstract

See full text

A method and apparatus for ensuring system boot image integrity and authenticity is described. In one embodiment, the invention provides security from the end of Basic Input/Output System (BIOS) initialization to the point in time at which control is transferred to a high-level operating system (OS). The OS boot image is obtained via a network connection and is checked for integrity and authority to run on a particular platform. For this purpose, the invention provides a boot image security usage model that is simple and flexible enough to cover a variety of needs. Because receipt of boot images via a network connection can be subject to size constraints, the invention allows software to bootstrap more sophisticated security software if desired. In general, the invention utilizes one or more Remote-Boot Authorization Certificates for each group of platforms to be managed. The authorization certificate for a group of platforms is configured into each of the platforms in a group as the source of authority for allowing boot images to be executed. The authorization certificate is also the source of authority for allowing reconfiguration commands, including reconfiguration commands that transfer the source of authority to another authority. In one embodiment, IT organizations can create different authorization certificates for different groups to allow the different groups to be managed by different authorities. Authority can also be transferred between management groups. The Remote-Boot Authorization Certificates provide protection against remote-boot images that have been damaged and/or tampered with either in transit or on a server, the ability to designate and enforce which boot images are permitted, and a mechanism to limit the scope of management authorities having remote-boot authority.

Loading the Abstract Image... loading....

First Claim

See full text

Family

Loading Family data... loading....

Patent Owner(s)

  • INTEL CORPORATION

International Classification(s)

Inventor(s)

Inventor Name Address # of filed Patents Total Citations
Carbajal, John M Barcelona, ES 2 256
Dittert, Eric R Portland, OR 2 126
Drews, Paul C Gaston, OR 16 1294

Cited Art Landscape

Load Citation

Patent Citation Ranking

Forward Cite Landscape

Load Citation