EP0443423B1

Method and apparatus for executing trusted-path commands

Abstract

This record has no abstract on file.

EP0443423B1, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Expired 13 February 2011, 15.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

21 claims: 9 independent, 12 dependent

  1. 1
    A machine-executed method for executing, in a trusted environment (TCB 10) on a computer system, a command issued by a subject, the computer system also including an untrusted computing environment (UOS 20), the method characterized by :(a) parsing a trusted command (70) issued by the subject in the untrusted computing environment to generate a parsed command;(b) submitting the parsed command (80) to the trusted computing environment;(c) communicating a representation of the parsed command (170) to the subject through a trusted path;(d) receiving a signal from the subject through a trusted path signifying confirmation or non-confirmation of the parsed command (180);(e) if the received signal signifies non-confirmation, then preventing the execution of the parsed command;and (f) if the received signal signifies confirmation, then executing the parsed command in the trusted environment.
  2. 4
    The method of any preceding claim in which the subject is a user, and in which the communication of the representation of the parsed command comprises displaying said representation to said user.
  3. 9
    The method of any of claims 1 to 8 wherein the trusted computing environment comprises a security kernel.
  4. 10
    The method of any of claims 1 to 9 wherein the untrusted environment (UOS 20) comprises a general operating system.
  5. 12
    A computer program product, comprising a computer readable medium having thereon computer program code means adapted, when said program is loaded onto a computer, to make the computer execute the procedure of any one of claims 1 to 11.
  6. 13
    A computer apparatus including an untrusted computing environment (UOS 20) and a trusted computing environment (TCB 10), characterized by :means for parsing (70) in said untrusted computing environment, a subject-issued trusted command to generate a parsed command;means for submitting (80) the parsed command to said trusted computing environment;means for communicating (SSRV12) a representation of the parsed command over a trusted path to the subject for confirmation (170) ;and means (180) for receiving a signal from the subject through a trusted path signifying confirmation or non-confirmation of the parsed command, and means operable to prevent execution of the parsed command if the received signal signifies non-confirmation, and to execute the parsed command in the trusted computing environment (TCB 10) if the received signal signifies confirmation.
  7. 16
    The computer apparatus of any one of claims 13 to 15 wherein the subject is a user, and in which the means for communicating the representation of the parsed command comprises means for displaying said representation to said user.
  8. 18
    The computer apparatus of any one of claims 13 to 16 further including:means for receiving a signal from the subject signifying whether or not the communicated representation accurately represents the trusted command.
  9. 19
    The computer apparatus of any one of claims 13 to 18 wherein the trusted computing environment comprises a security kernel.
  10. 20
    The computer apparatus of any one of claims 13 to 19 wherein the untrusted environment (UOS 20) comprises a general operating system.
  11. 21
    The computer apparatus of any one of claims 13 to 20 further including:means for communicating, to the trusted environment, a representation of the parsed command to a second subject;means for receiving a signal from the second subject signifying confirmation or non-confirmation of the parsed command;and means for preventing the execution of the parsed command if the received signal from the second subject signifies non-confirmation of the parsed command.