IL264706A

Preserving protected secrets across a secure boot update

Abstract

This record has no abstract on file.

IL264706A, drawing sheet 1
Sheet 1 of 5

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 3 independent, 17 dependent

  1. 1
    CLAIMS:1. A computing system enabled to preserve protected secrets across a secure boot update, the system comprising: one or more processors;and one or more computer-readable storage devices having stored thereon instructions that are executable by the one or more processors to configure the computer system to obtain a sealed secret, including instructions that are executable to configure the computer system to perform at least the following: maintaining a plurality of binary large objects (BLOBs), each BLOB in the plurality of BLOBs containing the encrypted data and the sealed secret, each sealed secret in each BLOB having been sealed to a different condition, each condition being a reflection of a system state indicative of whether or not the system can be trusted to receive the secret;attempting to unseal the sealed secret contained in a first BLOB using a first condition: based on the attempt to unseal the sealed secret contained in the first BLOB being successful, determining whether a second BLOB needs to be updated and, if so, update the second BLOB;based on the attempt to unseal the sealed secret contained in the first BLOB being unsuccessful, attempt to unseal the sealed secret contained in the second BLOB using a second condition;and based on either the attempt to unseal the sealed secret contained in the first BLOB or the attempt to unseal the sealed secret contained in the second BLOB being successful, providing the unsealed secret to an entity, the unsealed sealed secret enabling the entity to access the encrypted data.
  2. 9
    A computer implemented method of obtaining a sealed secret, the method comprising:accessing one or more binary large objects (BLOBs) at a computing system from among a plurality of different BLOBs, wherein each of the BLOBs in the plurality of BLOBs contains the secret, wherein each of the BLOBs in the plurality of BLOBs is sealed to a different condition from among a plurality of conditions, and wherein a given condition is a reflection of a system state where the system state is indicative of whether or not the system can be trusted to receive the secret;attempting to unseal the sealed secret contained in a first BLOB using a first condition;based on the attempt to unseal the sealed secret contained in the first BLOB being successful, determining whether a second BLOB needs to be updated and, if so, update the second BLOB;Version 2 / Amended 4 Feb. 2021 based on the attempt to unseal the sealed secret contained in the first BLOB being unsuccessful, attempt to unseal the sealed secret contained in the second BLOB using a second condition;and based on either the attempt to unseal the sealed secret contained in the first BLOB or the attempt to unseal the sealed secret contained in the second BLOB being successful, providing the unsealed secret to an entity, the unsealed sealed secret enabling the entity to access encrypted data.
  3. 17
    A computer implemented method of sealing a secret, the method comprising:obtaining a secret;and sealing the secret into a first Binary Large Object (BLOB) of a plurality of BLOBs at a computing system such that the first BLOB contains the secret and such that the first BLOB is Version 2 / Amended 4 Feb. 2021 sealed to a first condition of a plurality of conditions, wherein each condition of the plurality of conditions is a reflection of a system state indicative of whether or not the system can be trusted to receive the secret;and sealing the secret into a second Binary Large Object (BLOB) of the plurality of BLOBs 5 such that the second BLOB contains the secret and such that the first BLOB is sealed to a second condition of the plurality of conditions.