Patent
Multiple trusted computing environments
Jonathan Griffin,Christopher I Dalton,Michael Child,Liqun Chen,Andrew Patrick Norman +4 more
- 18 Jun 2002
114
TL;DR: In this article, the authors describe a secure and trusted computing environment where each computing environment is isolated and secure, and can be verified as trustworthy independent of any other computing environment, by forming integrity metrics which can be interrogated by a user.
read more
Abstract: A computing platform 20 provides multiple computing environments 24 each containing a guest operating system 25 provided by a virtual machine application 26. Optionally, each computing environment 24 is formed in a compartment 220 of a compartmented host operating system 22. A trusted device 213 verifies that the host operating system 22 and each guest operating system 25 operates in a secure and trusted manner by forming integrity metrics which can be interrogated by a user 10. Each computing environment is isolated and secure, and can be verified as trustworthy independent of any other computing environment.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Patent
Securing customer virtual machines in a multi-tenant cloud
Irfan Ahmad,Mukund Gunti,Abhishek Chaturvedi,Vladimir Kiriansky +3 more
- 10 Mar 2011
TL;DR: A trusted virtualization platform as discussed by the authors protects sensitive customer data during operation of virtual machines in a multi-tenant cloud computing center by limiting administrator access to the data and state of the virtual machines running thereon, reports any changes made thereto, and requires keys provided by the customer or a trusted third party of the customer to perform management operations.
216
Patent
Impeding progress of malicious guest software
Dmitriy Budko,Xiaoxin Chen,Oded Horovitz,Carl A. Waldspurger +3 more
- 19 Mar 2008
TL;DR: In this article, the authors present a method of operating a virtualization system, the method including: instantiating a virtualisation system on an underlying hardware machine, exposing a virtual machine in which multiple execution contexts of a guest execute, and selectively impeding computational progress of a particular one of the execution contexts.
202
Patent
Memory addressing for a virtual machine implementation on a computer processor supporting virtual hash-page-table searching
Todd Kjos,Jonathan K. Ross,Christophe de Dinechin +2 more
- 26 Sep 2002
TL;DR: In this paper, a software monitor, interposed between the hardware layer of a computer system and one or more guest operating systems, constructs and maintains a guest-physical address-to-host-physical-address map for each guest operating system, and maintains virtual memory addressing context for each operating system that may include a virtual-hash-page table for each host operating system.
179
Patent
Encrypting operating system
Ernst B. Carter,Vasily Zolotov +1 more
- 25 Aug 2003
TL;DR: In this article, a method of and system for encrypting and decrypting data on a computer system is disclosed, which comprises an encrypting operating system (EOS), which is a modified UNIX operating system.
169
Patent
Systems and methods for dynamically managing virtual machines
Kirk A. Beaty,Norman Bobroff,Gautam Kar,Gunjan Khanna,Andrzej Kochut +4 more
- 28 Feb 2006
Abstract: Techniques for dynamic management of virtual machine environments are disclosed. For example, a technique for automatically managing a first set of virtual machines being hosted by a second set of physical machines comprises the following steps/operations. An alert is obtained that a service level agreement (SLA) pertaining to at least one application being hosted by at least one of the virtual machines in the first set of virtual machines is being violated. Upon obtaining the SLA violation alert, the technique obtains at least one performance measurement for at least a portion of the machines in at least one of the first set of virtual machines and the second set of physical machines, and a cost of migration for at least a portion of the virtual machines in the first set of virtual machines. Based on the obtained performance measurements and the obtained migration costs, an optimal migration policy is determined for moving the virtual machine hosting the at least one application to another physical machine.
143
References
Patent
Systems and Methods for Secure Transaction Management and Electronic Rights Protection
Karl L Ginter,Victor H Shear,Francis J Spahn,David M. Van Wie +3 more
- 30 Sep 2010
TL;DR: In this article, the authors proposed a secure content distribution method for a configurable general-purpose electronic commercial transaction/distribution control system, which includes a process for encapsulating digital information in one or more digital containers, a process of encrypting at least a portion of digital information, a protocol for associating at least partially secure control information for managing interactions with encrypted digital information and/or digital container, and a process that delivering one or multiple digital containers to a digital information user.
7.6K
Security without identification: transaction systems to make big brother obsolete
TL;DR: The large-scale automated transaction systems of the near future can be designed to protect the privacy and maintain the security of both individuals and organizations.
Patent
Interactive market management system
Eyal Shavit,Lester Teichner +1 more
- 29 Sep 1987
TL;DR: In this paper, the authors present a system for interactive on-line electronic communications and processing of business transactions between a plurality of different types of independent users including at least a plurality sellers, and a plurality buyers, as well as financial institutions, and freight service providers.
1.7K
Patent
System for controlling access and distribution of digital property
Paul B. Schneck,Marshall D. Abrams +1 more
- 09 Jan 1997
TL;DR: In this article, a method and device are provided for controlling access to data, where portions of the data are protected and rules concerning access rights to data are determined, and a method is also provided for distributing data for subsequent controlled use of those data.
1.4K
Formal requirements for virtualizable third generation architectures
TL;DR: A model of a third-generation-like computer system is developed and formal techniques are used to derive precise sufficient conditions to test whether such an architecture can support virtual machines.
1.1K