EP0443423A2

Method for executing trust-path commands.

Abstract

A method for executing trusted commands, in which a trusted command is first received from a user at a user terminal and parsed by untrusted code; then passed to a trusted computing base for execution. The trusted computing base displays to the user for confirmation some indication of what is to be done. Confirmation of the commands prevents unauthorized modification of the commands and increases system confidence. A randomly (or pseudo-randomly) generated process identifier is employed to verify the existence of a trusted path.

EP0443423A2, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Projected expiry passed 13 February 2011, 15.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

20 claims: 9 independent, 11 dependent

  1. 1
    A machine-executable method for executing a trusted command issued by a user, said method comprising the steps of:(a) parsing the trusted command in an untrusted computing environment to generate a parsed command;(b) submitting the parsed command to a trusted computing environment;(c) in the trusted environment, displaying a representation of the parsed command to the user;(d) receiving a signal from the user signifying whether the displayed representation accurately represents the user's intentions;and (e) if the signal signifies that the displayed representation does not accurately represent the user's intentions, then preventing the execution of the parsed command.
  2. 6
    A method for executing in a computing system a trusted command issued by a user, said method comprising the steps of:(a) receiving user identification data from the user via a trusted path;(b) receiving the trusted command from the user via an untrusted path;(c) parsing the trusted command in an untrusted computing environment to generate a parsed command;(d) submitting the parsed command to a trusted computing environment;(e) in the trusted computing environment, performing a security check on the parsed command and user identification data;and (f) in the trusted computing environment, executing the trusted command.
  3. 10
    A method for ensuring the existence of a trusted path in a computing system comprising the steps of:(a) in a trusted computing environment, upon login by a user, assigning a process identifier to the user in the trusted computing environment;(b) storing the assigned process identifier in trusted memory;(c) establishing a trusted path;(d) in the trusted path, displaying the process identifier to the user;and (e) upon a subsequent entry into the trusted path, displaying the process identifier to the user.
  4. 13
    An automatic data processing machine programmed to execute the method of any one of claims 1 to 12.
  5. 14
    An automatic data processing machine comprising means for performing the method steps of any one of claims 1 to 12.
  6. 15
    A program storage device readable by a machine and tangibly embodying a representation of a program of instructions adaptable to be executed by said machine to perform the method of any one of claims 1 to 12.
  7. 16
    Apparatus for executing a trusted command that is issued by a user and that is parsed by untrusted parsing means to generate a parsed command, comprising:(a) trusted means for receiving the parsed command via a trusted path;(b) means for displaying a representation of the parsed command to the user;and (c) trusted means for executing the parsed command.
  8. 17
    Apparatus for controlling the execution by a machine of a trusted command that is issued by a user and that is parsed by untrusted parsing means to generate a parsed command, comprising:(a) trusted-program storage means, readable by the machine, for causing the machine to receive the parsed command from the untrusted parsing means;and (b) trusted-program storage means, readable by the machine, for causing the machine to execute the parsed command.
  9. 18
    Apparatus for controlling the execution by a machine of a trusted command that is issued by a user with user identification data and that is parsed by untrusted parsing means to generate a parsed command, comprising:(a) trusted program storage means, readable by the machine, for causing the machine to receive the user identification data from the user;(b) trusted program storage means, readable by the machine, for causing the machine to receive the parsed command from the untrusted parsing means;(c) trusted program storage means, readable by the machine, for causing the machine to perform a security check on the parsed command and a security check on the user identification data;and (d) trusted program storage means, readable by the machine, for causing the machine to execute the trusted command.