User Authorization And Presence Detection In Isolation From Interference From And Control By Host Central Processing Unit And Operating System
Abstract
An embodiment may include circuitry to be included, at least in part, in a host. The host may include at least one host central processing unit (CPU) to execute, at least in part, at least one host operating system (OS). The circuitry may perform, at least in part, at least one operation in isolation both from interference from and control by the at least one host CPU and the at least one host OS. The at least one operation may include user authorization determination and user presence determination. The authorization determination may be in response, at least in part, to indication of physical presence of at least one user in proximity to the host. The user presence determination may determine, at least in part, whether, after the indication has been provided, the physical presence of the at least one user in the proximity to the host has ceased.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system comprising:
a host central processing unit (CPU) to execute, at least in part, a host operating system (OS) and comprising one or more hardware partitions; and logic, implemented at least in part by hardware coupled to the host CPU, to perform at least one operation in isolation from the host CPU and the host OS, the at least one operation comprising:
a user authorization determination in response to an indication of a physical presence of a user within a geographic region of the system, to determine whether the user is authorized to issue a command to a security-related component of the system, wherein the indication is based at least in part on one or more of:
activation of a secure attestation key of the system by the user;
provision of a general purpose input/output (GPIO) signal to the logic;
detection of a physical token associated with the user; and
detection of a physical characteristic of the user; and
a user presence determination to determine whether, after the indication has been provided, the physical presence of the user within the geographic region has ceased.
2 . The system of claim 1 , wherein the logic is to execute, at least in part, a software agent to perform one or more of the user authorization determination and the user presence determination.
3 . The system of claim 2 , further comprising a virtual machine manager comprising the software agent.
4 . The system of claim 3 , wherein the security-related component comprises a virtual trusted platform module that is to be implemented, at least in part, by the virtual machine manager.
5 . The system of claim 4 , wherein the virtual trusted platform module comprises a plurality of virtual trusted platform modules.
6 . The system of claim 1 , further comprising a device to removably couple to the system, the device comprising the logic.
7 . The system of claim 1 , wherein the user authorization determination is based at least in part on one or more of:
biometric information associated with the user; a challenge response provided by the user; and data provided by a near field communication device associated with the user.
8 . The system of claim 1 , wherein the security-related component comprises a trusted platform module.
9 . The system of claim 8 , wherein the logic is to store, at least in part, user authentication information and user privilege information in a manner that is inaccessible to the host OS and the host CPU, and the user authentication determination is based at least in part on whether the user authentication information matches, at least in part, other user-associated information provided by the user.
10 . The system of claim 9 , wherein the logic is to determine based at least in part on the user privilege information whether the user is authorized to issue the command to the security-related component.
11 . A method comprising:
determining, in logic coupled to a host central processing unit (CPU) of a system, in a manner isolated from the host CPU, in response to an indication of a physical presence of a user within a geographic region of the system, whether the user is authorized to issue a command to a security-related component of the system, wherein the indication is based at least in part on one or more of:
activation of a secure attestation key of the system by the user;
provision of a general purpose input/output (GPIO) signal to the logic;
detection of a physical token associated with the user; and
detection of a physical characteristic of the user; and
determining, after the indication has been provided, whether the physical presence of the user within the geographic region has ceased.
12 . The method of claim 11 , further comprising executing, at least in part, a software agent to perform one or more of the user authorization determining and the physical presence determining.
13 . The method of claim 11 , wherein the user authorization is based at least in part on one or more of:
biometric information associated with the user; a challenge response provided by the user; and data provided by a near field communication device associated with the user.
14 . The method of claim 11 , further comprising storing, at least in part, user authentication information and user privilege information in a manner that is inaccessible to a host operating system (OS) to execute on the host CPU.
15 . The method of claim 14 , further comprising determining the user authorization based at least in part on whether the user authentication information matches, at least in part, other user-associated information provided by the user.
16 . The method of claim 15 , further comprising determining based at least in part on the user privilege information whether the user is authorized to issue the command to the security-related component.
17 . A non-transitory machine-readable medium having stored thereon instructions, which if performed by a machine cause the machine to perform a method comprising:
determining, in logic, implemented at least in part by hardware coupled to a host central processing unit (CPU) of a system, in a manner isolated from the host CPU, in response to an indication of a physical presence of a user within a geographic region of the system, whether the user is authorized to issue a command to a security-related component of the system, wherein the indication is based at least in part on one or more of:
activation of a secure attestation key of the system by the user;
provision of a general purpose input/output (GPIO) signal to the logic;
detection of a physical token associated with the user; and
detection of a physical characteristic of the user; and
determining, after the indication has been provided, whether the physical presence of the user within the geographic region has ceased.
18 . The non-transitory machine-readable medium of claim 17 , further comprising instructions that if performed enable the machine to perform the user authorization based at least in part on one or more of:
biometric information associated with the user; a challenge response provided by the user; and data provided by a near field communication device associated with the user.
19 . The non-transitory machine-readable medium of claim 17 , further comprising instructions that if performed enable the machine to store, at least in part, user authentication information and user privilege information in a manner that is inaccessible to a host operating system (OS) to execute on the host CPU.
20 . The non-transitory machine-readable medium of claim 19 , further comprising instructions that if performed enable the machine to determine the user authorization based at least in part on whether the user authentication information matches, at least in part, other user-associated information provided by the user, and determine based at least in part on the user privilege information whether the user is authorized to issue the command to the security-related component.Join the waitlist — get patent alerts
Track US2016110532A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.