US2021014220A1PendingUtilityA1

Trusted container

Assignee: MCAFEE LLCPriority: Dec 23, 2012Filed: Aug 24, 2020Published: Jan 14, 2021
Est. expiryDec 23, 2032(~6.4 yrs left)· nominal 20-yr term from priority
H04L 63/0823H04L 63/18H04L 41/28H04L 63/20H04L 63/0838H04L 63/061H04L 41/046
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A secure identifier is derived, using a secured microcontroller of a computing device, that is unique to a pairing of the computing device and a particular domain. Secure posture data corresponding to attributes of the computing device is identified in secured memory of the computing device. The secure identifier and security posture is sent in a secured container to a management device of the particular domain. The particular domain can utilize the information in the secured container to authenticate the computing device and determine a security task to be performed relating to interactions of the computing device with the particular domain.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 - 20 . (canceled) 
     
     
         21 . An apparatus to securely communicate with domain devices, comprising:
 secure memory to store secure identifiers, the secure memory inaccessible by an operating system (OS) of a system device;   a management controller to:
 retrieve, from a first domain device and a second domain device, first seed data and second seed data, respectively; 
 generate a first secure identifier and a second secure identifier based on the first seed data and the second seed data, respectively; and 
 store the first and second secure identifiers in the secure memory; 
   a communication manager to circumvent the OS of the system device by:
 pairing the system device to the first domain device via the first secure identifier; and 
 pairing the system device to the second domain device via the second secure identifier. 
   
     
     
         22 . The apparatus as defined in  claim 21 , wherein the management controller is to perform a management task on the system device independent of the OS of the system device, the management tasks retrieved from at least one of the first or the second domain device. 
     
     
         23 . The apparatus as defined in  claim 21 , wherein the secure memory includes security posture data, the security posture data indicative of attributes corresponding to the system device. 
     
     
         24 . The apparatus as defined in  claim 23 , wherein the attributes include at least one of a respective type of the system device, particular computing equipment on the system device, a particular model of the system device, or particular software versions installed on the system device. 
     
     
         25 . The apparatus as defined in  claim 21 , wherein the management controller is to inspect traffic packets before a central processing unit of the system device has access to the traffic packets. 
     
     
         26 . The apparatus as defined in  claim 21 , further including a network filter to redirect traffic packets to one of the management controller or the operating system. 
     
     
         27 . The apparatus as defined in  claim 26 , wherein the network filter is to redirect the traffic packets based on port numbers associated with the traffic packets. 
     
     
         28 . At least one storage device or storage disk comprising instructions that, when executed on at least one processor, cause the at least one processor to at least:
 retrieve first seed data from a first domain device and second seed data from a second domain device;   store the first and second seed data in secure memory, the secure memory inaccessible by an operating system (OS) of a system device;   generate a first secure identifier and a second secure identifier based on the first and second seed data, respectively; and   circumvent the OS of the system device by:
 pairing the system device to the first domain device via the first secure identifier; and 
 pairing the system device to the second domain device via the second secure identifier. 
   
     
     
         29 . The at least one storage device or storage disk as defined in  claim 28 , wherein the instructions, when executed, cause the at least one processor to perform a management task on the system device independent of the OS of the system device, the management tasks retrieved from at least one of the first or the second domain device. 
     
     
         30 . The at least one storage device or storage disk as defined in  claim 28 , wherein the instructions, when executed, cause the at least one processor to store security posture data on the secure memory, the security posture data indicative of attributes corresponding to the system device. 
     
     
         31 . The at least one storage device or storage disk as defined in  claim 30 , wherein the instructions, when executed, cause the at least one processor to store attributes as at least one of a respective type of the system device, particular computing equipment on the system device, a particular model of the system device, or particular software versions installed on the system device. 
     
     
         32 . The at least one storage device or storage disk as defined in  claim 28 , wherein the instructions, when executed, cause the at least one processor to inspect traffic packets before a central processing unit of the system device has access to the traffic packets. 
     
     
         33 . The at least one storage device or storage disk as defined in  claim 28 , wherein the instructions, when executed, cause the at least one processor to redirect traffic packets to one of the management controller or the operating system. 
     
     
         34 . The at least one storage device or storage disk as defined in  claim 33 , wherein the instructions, when executed, cause the at least one processor to redirect the traffic packets based on port numbers associated with the traffic packets. 
     
     
         35 . A method to communicate with domain devices, comprising:
 retrieving, by executing an instruction with at least one processor, first seed data from a first domain device;   retrieving, by executing an instruction with the at least one processor, second seed data from a second domain device;   storing, by executing an instruction with the at least one processor, the first and second seed data in secure memory, the secure memory inaccessible by an operating system (OS) of a system device;   generating, by executing an instruction with the at least one processor, a first secure identifier and a second secure identifier based on the first and second seed data, respectively; and   circumventing, by executing an instruction with the at least one processor, the OS of the system device by:
 pairing the system device to the first domain device via the first secure identifier; and 
 pairing the system device to the second domain device via the second secure identifier. 
   
     
     
         36 . The method as defined in  claim 35 , further including perform a management task on the system device independent of the OS of the system device. 
     
     
         37 . The method as defined in  claim 35 , further including storing security posture data on the secure memory, the security posture data indicative of attributes corresponding to the system device. 
     
     
         38 . The method as defined in  claim 37 , further including storing the attributes as at least one of a respective type of the system device, particular computing equipment on the system device, a particular model of the system device, or particular software versions installed on the system device. 
     
     
         39 . The method as defined in  claim 35 , further including inspecting traffic packets before a central processing unit of the system device has access to the traffic packets. 
     
     
         40 . The method as defined in  claim 35 , further including redirecting traffic packets to one of the management controller or the operating system. 
     
     
         41 . The method as defined in  claim 40 , wherein the redirecting of the traffic packets is based on port numbers associated with the traffic packets.

Join the waitlist — get patent alerts

Track US2021014220A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.