Protected mode for securing computing devices
Abstract
Methods and systems are disclosed for testing and/or validating that an untrusted device is operating according to an expected state or configuration. The methods and systems may be designed such that the volatile memory of the untrusted device is brought to a known state for validation, for example upon ingress to or egress from a protected mode of operation. The device may execute a first operating system when operating outside of the protected mode. Upon determining to transition to protected mode, an operational image of a second operating system may be loaded into the device. The device may write a pattern to unused memory for validation. The device may receive a first challenge request from a trusted monitor (TM). In order to be successfully validated, the device may answer the challenge correctly within a given response window based on the current state of its volatile memory.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A method implemented in a device to be secured for operating the device in a protected mode of operation, the method comprising:
operating the device outside of the protected mode, wherein the device executes a first operating system when operating outside of the protected mode; determining to transition the device into the protected mode; terminating the first operating system based on determining to transition the device into the protected mode; loading an operational image of a second operating system into the device based on determining to transition the device into the protected mode, wherein the operational image of the second operating system is copied to volatile memory; determining to transition the device out of the protected mode; and loading an operational image of the second operating system based on determining to transition the device out of the protected mode.
2 . The method as in claim 1 , further comprising:
receiving a first challenge from a trusted monitor (TM), wherein the first challenge is received based on the device transitioning into the protected mode; determining a first challenge response based on the first challenge; sending the first challenge response to the TM; receiving a second challenge from the TM, wherein the second challenge is received based on the device transitioning out of the protected mode; determining a second challenge response based on the second challenge; and sending the second challenge response to the TM.
3 . The method as in claim 2 , wherein the first challenge is indicative of a memory region of the device that is to be validated by the TM.
4 . The method as in claim 3 , wherein the memory region is associated with at least a portion of the operational image of the second operating system.
5 . The method as in claim 2 , further comprising writing a pattern to an unused memory region in order to answer the first challenge.
6 . The method as in claim 5 , wherein a value to be written in the pattern for a given memory address is dependent on the order in which the memory address was treated in the pattern.
7 . The method as in claim 6 , wherein the value to be written in the pattern for the given memory address is further dependent on a value stored at another memory address.
8 . The method as in claim 1 , further comprising:
storing operational data of the first operating system in non-volatile memory based on determining to transition the device into the protected mode; and restoring the first operating system using the operational data stored in non-volatile memory upon transitioning the device out of the protected mode.
9 . A method for bringing volatile memory to a known state for validation, the method comprising:
receiving a plurality of challenge parameters, wherein the plurality of challenge parameters comprise an indication of a memory region and a random number; writing a pattern to at least one portion of unused volatile memory, wherein at least one memory address to use for the pattern is selected based on a result of a pseudorandom function, a value of a counter initialized at the beginning of the pattern is an input to the pseudorandom function, and a value written to the at least one memory address is determined based on a value that was stored at another memory address in the volatile memory and the value of the counter used as the input to the pseudorandom function.
10 . The method as in claim 9 , wherein the challenge parameters further comprise a number of pattern generator cycles over which to apply the pattern to selected memory addresses.
11 . The method as in claim 9 , further comprising:
performing an integrity checksum across the volatile memory once the volatile memory has been brought to the known state; and transmitting the result of the integrity checksum to a trusted monitor (TM).
12 . The method as in claim 11 , wherein the integrity checksum function is performed first over memory values corresponding to the operational image of an operating system and then across the at least one portion of unused volatile memory.
13 . The method as in claim 9 , wherein the another memory address comprises an adjacent memory address to the at least one memory address.
14 . The method as in claim 9 , wherein the result of the pseudorandom function is utilized to select the at least one memory address by translating the result of the pseudorandom function to the at least one memory using a modulus operation.
15 . The method as in claim 9 , wherein a first memory address in the pattern is dependent on the random number.
16 . The method as in claim 15 , wherein the first memory address in the pattern is selected based on a result of a hash function being applied to the counter and the random number.
17 . The method as in claim 9 , further comprising initializing the at least one portion of unused volatile memory prior to writing the pattern to the unused volatile memory, wherein the at least one portion of unused volatile memory is initialized based on the random number.
18 . The method as in claim 17 , wherein initialing the at least one portion of unused volatile memory based on the random number comprises:
storing the random number at a first determined memory address of the unused volatile memory; incrementing the random number; storing the incremented random number at a next determined memory location; and repeating the incrementing of the random number and storing each iteration at a subsequent memory address until the at least one portion of unused volatile memory has been initialized.
19 . A trusted monitor (TM) for validating that volatile memory of an untrusted device is configured in a known state, the TM comprising:
a communication device configured to send a challenge to the untrusted device, the challenge comprising an indication of a memory region, a random number, and a number of pattern generator cycles over which to apply a generated pattern to selected memory addresses; a processor configured to determine an expected challenge response; the processor being further configured to determine an expected response time window based the challenge and a configuration of the untrusted device; and the processor being further configured to determine that validation of the untrusted device is successful based on the TM receiving a challenge response within the response time window that comprises the expected challenge response.
20 . The method as in claim 19 , wherein the processor is further configured to:
determine an expected state of the volatile memory of the untrusted device based on the challenge, wherein the expected state of the volatile memory of the untrusted device comprises a first region configured to store an operational image of an operating system and a second region configured to store a pattern; and determine the expected challenge response based on the expected stated of the volatile memory of the untrusted device, wherein the expected challenge response comprises a result of a hash function being applied across data corresponding to the expected state of the volatile memory.
21 . The TM as in claim 19 , wherein the communication device is configured to send the challenge based on one or more of the untrusted devices transitioning into a protected mode of operation or the untrusted device transitioning out of the protected mode of operation.
22 . A device configured to execute an operating system, the device comprising:
memory configured to store an operational image of the operating system and a pattern that is written to at least a portion of the memory that is not occupied by the operational image of the operating system; and an internal reference monitor (IRM) configured to validate that the memory is configured to store the operational image of the operating system and the pattern, wherein at least one memory address used for the pattern is selected based on a result of a pseudorandom function, a value of a counter initialized at the beginning of the pattern is an input to the pseudorandom function, and a value written to the at least one memory address is determined based on a value that was stored at another memory address in the memory and the value of the counter used as the input to the pseudorandom function.
23 . The device as in claim 22 , wherein the pseudorandom function comprises a hash function.Join the waitlist — get patent alerts
Track US2015052616A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.