US Patent Application 18223399. COMPUTING DEVICES WITH SECURE BOOT OPERATIONS simplified abstract

From WikiPatents
Jump to navigation Jump to search

COMPUTING DEVICES WITH SECURE BOOT OPERATIONS

Organization Name

Intel Corporation


Inventor(s)

Yeluri Raghuram of Sunnyvale CA (US)

Susanne M. Balle of Hudson NH (US)

Nigel Thomas Cook of Boulder CO (US)

Kapil Sood of Portland OR (US)

COMPUTING DEVICES WITH SECURE BOOT OPERATIONS - A simplified explanation of the abstract

This abstract first appeared for US patent application 18223399 titled 'COMPUTING DEVICES WITH SECURE BOOT OPERATIONS

Simplified Explanation

This patent application relates to security measures in cloudlet environments. It describes a computing device, known as a cloudlet, that includes various components to enhance security.

  • The cloudlet includes a trusted execution environment, which is a secure area where sensitive operations can be performed.
  • It also includes a Basic Input/Output System (BIOS) that can request a Key Encryption Key (KEK) from the trusted execution environment.
  • The cloudlet further includes a Self-Encrypting Storage (SES) that is associated with the KEK.
  • The trusted execution environment verifies the BIOS and provides the KEK to the BIOS after verification.
  • The BIOS then uses the KEK to unlock the SES, allowing the trusted execution environment to access it.

Overall, this patent application describes a system where the trusted execution environment and BIOS work together to enhance security in a cloudlet environment by utilizing encryption keys and secure storage.


Original Abstract Submitted

Disclosed herein are embodiments related to security in cloudlet environments. In some embodiments, for example, a computing device (e.g., a cloudlet) may include: a trusted execution environment; a Basic Input/Output System (BIOS) to request a Key Encryption Key (KEK) from the trusted execution environment; and a Self-Encrypting Storage (SES) associated with the KEK; wherein the trusted execution environment is to verify the BIOS and provide the KEK to the BIOS subsequent to verification of the BIOS, and the BIOS is to provide the KEK to the SES to unlock the SES for access by the trusted execution environment.