Patents by Inventor Nigel John Edwards
Nigel John Edwards has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12681748Abstract: In some examples, a bus device includes a device controller to perform input/output (I/O) virtualization to provide a virtualized instance of the bus device. The device controller establishes a channel between the virtualized instance of the bus device and a guest operating system (OS) of a virtual machine (VM). The device controller receives, from the VM, address information relating to a portion of a memory containing information associated with a kernel of the guest OS, and obtains, for integrity inspection, the information associated with the kernel from the memory based on the address information.Type: GrantFiled: February 17, 2023Date of Patent: July 14, 2026Assignee: Hewlett Packard Enterprise Development LPInventors: Nigel John Edwards, Geoffrey Ndu, Jason Christopher Cohen, Theofrastos Koulouris
-
Publication number: 20260111571Abstract: In some examples, a secure service module that provides security services for a virtual compute entity requests a key from a processor. A system encrypts a state of a virtual security processor using the key to produce an encrypted virtual security processor state, and the system stores the encrypted virtual security processor state in a persistent storage.Type: ApplicationFiled: January 28, 2025Publication date: April 23, 2026Inventors: Jean Snyman, Geoffrey Ndu, Nigel John Edwards
-
Patent number: 12602479Abstract: A process includes, in a computer system, acquiring a first measurement that corresponds to a software container. Acquiring the measurement includes a hardware processor of the computer system measuring a given layer of a plurality of layers of layered file system structure corresponding to the software container. The given layer includes a plurality of files, and the first measurement includes a measurement of the plurality of files. The process includes storing the first measurement in a secure memory of the computer system. A content of the secure memory is used to verify an integrity of the software container.Type: GrantFiled: December 14, 2023Date of Patent: April 14, 2026Assignee: Hewlett Packard Enterprise Development LPInventors: Francisco Plinio Oliveira Silveira, Nigel John Edwards, Ludovic Emmanuel Paul Noel Jacquin, Guilherme de Campos Magalhaes, Leandro Augusto Penna dos Santos, Rodrigo Jose Da Rosa Antunes
-
Publication number: 20260058821Abstract: In some examples, an electronic device downloads an attestation agent from an open-source distribution system, and initiates a registration process of the electronic device with an attestation server. The registration process includes sending, by the attestation agent in the electronic device, a cryptographic device identity for receipt by the attestation server, and receiving, by the attestation agent, an indication of registration of the electronic device based on the attestation server verifying the cryptographic device identity.Type: ApplicationFiled: August 20, 2024Publication date: February 26, 2026Inventors: Isaac John Matthews, Jean Snyman, Supreshna Gurung, Nigel John Edwards, Timothy J. Pletcher
-
Publication number: 20250390402Abstract: In some examples, a verifier system receives, over a network from a computing system, attestation data including information from a data structure stored in a kernel integrity monitoring controller. The information includes a configuration value derived based on applying a function on monitoring configuration information, and an extended value derived based on extending a prior value in the data structure with a new value from a log recording changed measurements of the kernel information. The verifier system determines an integrity of the kernel information using the configuration value and the extended value for attestation of the computing system.Type: ApplicationFiled: June 19, 2024Publication date: December 25, 2025Inventors: Nigel John Edwards, Theofrastos Koulouris, Geoffrey Ndu
-
Publication number: 20250363208Abstract: In some examples, a kernel monitoring device includes a communication interface to communicate with a processing resource that executes a virtual machine (VM). The kernel monitoring device also includes a device processor to trigger a hot add of the kernel monitoring device with respect to the VM to enable communications between the kernel monitoring device and the VM. After the hot add of the kernel monitoring device with respect to the VM, the device processor receives, from the VM, information associated with a kernel of the VM, and measures the received information to determine an integrity of the kernel of the VM.Type: ApplicationFiled: May 24, 2024Publication date: November 27, 2025Inventors: Geoffrey Ndu, Nigel John Edwards, Seosamh Donnchadh O'Riordain
-
Patent number: 12363111Abstract: In some examples, a system receives information from electronic devices comprising network devices and computing devices in a computing environment that are subject to attestations of interfaces of the network devices and the computing devices. For each interface of a given computing device being attested, the system verifies that the interface of the given computing device is connected to an interface of a corresponding network device that is being attested. For each interface of a given network device being attested, the system verifies that the interface of the given network device is connected to an interface of a corresponding computing device that is being attested or an interface of another network device that is being attested.Type: GrantFiled: October 19, 2022Date of Patent: July 15, 2025Assignee: Hewlett Packard Enterprise Development LPInventors: Nigel John Edwards, Thomas M. Laffey, Ludovic Emmanuel Paul Noel Jacquin, Sunil James
-
Patent number: 12353559Abstract: Systems and methods are provided for agentless attestation. Agentless attestation can measure the integrity of customer servers without requiring an agent software program to be downloaded to each of the enterprise computer devices. In particular, the system can integrate several standalone components to measure the integrity of monitored devices. This also allows the data center to authenticate, verify, audit, and update any hardware change, including a Platform Certificate.Type: GrantFiled: September 1, 2023Date of Patent: July 8, 2025Assignee: Hewlett Packard Enterprise Development LPInventors: Nigel John Edwards, Blaine R. Southam, Luis E. Luciani, Jr., Darrell R. Haskell, Nicholas Mark Hawkins, Walton A. Rosen, Guilherme De Campos Magalhaes, Kairo Cesar Pinto Tavares, Timothy Pletcher
-
Publication number: 20240419802Abstract: Systems and methods are provided for agentless attestation. Agentless attestation can measure the integrity of customer servers without requiring an agent software program to be downloaded to each of the enterprise computer devices. In particular, the system can integrate several standalone components to measure the integrity of monitored devices. This also allows the data center to authenticate, verify, audit, and update any hardware change, including a Platform Certificate.Type: ApplicationFiled: September 1, 2023Publication date: December 19, 2024Inventors: NIGEL JOHN EDWARDS, Blaine R. SOUTHAM, Luis E. LUCIANI, JR., Darrell R. HASKELL, Nicholas Mark HAWKINS, Walton A. ROSEN, Guilherme DE CAMPOS MAGALHAES, Kairo Cesar Pinto TAVARES, Timothy PLETCHER
-
Patent number: 12111937Abstract: A technique includes an operating system agent of a computer system monitoring a process to detect whether an integrity of the process has been compromised. The monitoring includes the operating system agent scanning a data structure. The process executes in a user space, and the data structure is part of an operating system kernel space. The technique includes a hardware controller of the computer system listening for a heartbeat that is generated by the operating system agent. The hardware controller takes a corrective action in response to at least one of the hardware controller detecting an interruption of the heartbeat, or the operating system agent communicating to the hardware controller a security alert for the process.Type: GrantFiled: March 21, 2023Date of Patent: October 8, 2024Assignee: Hewlett Packard Enterprise Development LPInventors: Geoffrey Ndu, Nigel John Edwards
-
Publication number: 20240281272Abstract: In some examples, a bus device includes a device controller to perform input/output (I/O) virtualization to provide a virtualized instance of the bus device. The device controller establishes a channel between the virtualized instance of the bus device and a guest operating system (OS) of a virtual machine (VM). The device controller receives, from the VM, address information relating to a portion of a memory containing information associated with a kernel of the guest OS, and obtains, for integrity inspection, the information associated with the kernel from the memory based on the address information.Type: ApplicationFiled: February 17, 2023Publication date: August 22, 2024Inventors: Nigel John Edwards, Geoffrey Ndu, Jason Christopher Cohen, Theofrastos Koulouris
-
Publication number: 20240236089Abstract: In some examples, a system receives information from electronic devices comprising network devices and computing devices in a computing environment that are subject to attestations of interfaces of the network devices and the computing devices. For each interface of a given computing device being attested, the system verifies that the interface of the given computing device is connected to an interface of a corresponding network device that is being attested. For each interface of a given network device being attested, the system verifies that the interface of the given network device is connected to an interface of a corresponding computing device that is being attested or an interface of another network device that is being attested.Type: ApplicationFiled: October 19, 2022Publication date: July 11, 2024Inventors: Nigel John Edwards, Thomas M. Laffey, Ludovic Emmanuel Paul Noel Jacquin, Sunil James
-
Patent number: 12020010Abstract: In some examples, a system receives first measurements of data items used by a build server in building an executable program, the data items copied from a data repository to a storage partition that is separate from the data repository, and the storage partition to store the data items relating to building the executable program by the build server. The system determines, based on the first measurements and according to a policy specified for the storage partition, whether a corruption of the data items used by the build server in building the executable program has occurred.Type: GrantFiled: August 10, 2021Date of Patent: June 25, 2024Assignee: Hewlett Packard Enterprise Development LPInventors: Nigel John Edwards, Guilherme de Campos Magalhaes
-
Publication number: 20240137363Abstract: In some examples, a system receives information from electronic devices comprising network devices and computing devices in a computing environment that are subject to attestations of interfaces of the network devices and the computing devices. For each interface of a given computing device being attested, the system verifies that the interface of the given computing device is connected to an interface of a corresponding network device that is being attested. For each interface of a given network device being attested, the system verifies that the interface of the given network device is connected to an interface of a corresponding computing device that is being attested or an interface of another network device that is being attested.Type: ApplicationFiled: October 18, 2022Publication date: April 25, 2024Inventors: Nigel John Edwards, Thomas M. Laffey, Ludovic Emmanuel Paul Noel Jacquin, Sunil James
-
Publication number: 20240126883Abstract: A process includes, in a computer system, acquiring a first measurement that corresponds to a software container. Acquiring the measurement includes a hardware processor of the computer system measuring a given layer of a plurality of layers of layered file system structure corresponding to the software container. The given layer includes a plurality of files, and the first measurement includes a measurement of the plurality of files. The process includes storing the first measurement in a secure memory of the computer system. A content of the secure memory is used to verify an integrity of the software container.Type: ApplicationFiled: December 14, 2023Publication date: April 18, 2024Inventors: Francisco Plinio Oliveira Silveira, Nigel John Edwards, Ludovic Emmanuel Paul Noel Jacquin, Guilherme de Campos Magalhaes, Leandro Augusto Penna dos Santos, Rodrigo Jose da Rosa Antunes
-
Patent number: 11874926Abstract: A process includes, in a computer system, acquiring a first measurement that corresponds to a software container. Acquiring the measurement includes a hardware processor of the computer system measuring a given layer of a plurality of layers of layered file system structure corresponding to the software container. The given layer includes a plurality of files, and the first measurement includes a measurement of the plurality of files. The process includes storing the first measurement in a secure memory of the computer system. A content of the secure memory is used to verify an integrity of the software container.Type: GrantFiled: December 7, 2020Date of Patent: January 16, 2024Assignee: Hewlett Packard Enterprise Development LPInventors: Francisco Plinio Oliveira Silveira, Nigel John Edwards, Ludovic Emmanuel Paul Noel Jacquin, Guilherme de Campos Magalhaes, Leandro Augusto Penna dos Santos, Rodrigo Jose da Rosa Antunes
-
Patent number: 11861372Abstract: Examples disclosed herein relate to using an integrity manifest certificate to verify the state of a platform. A device identity of a device that has the device identity provisioned and stored in a security co-processor to retrieve an integrity proof from the security co-processor. The device includes at least one processing element, at least one memory device, and a bus including at least one bus device, and wherein the device identity is associated with a device identity certificate signed by a first authority. The integrity proof includes a representation of each of a plurality of hardware components including the at least one processing element, the at least one memory device, the at least one bus device, and a system board and a representation of plurality of firmware components included in the device. The integrity proof is provided to a certification station.Type: GrantFiled: May 16, 2022Date of Patent: January 2, 2024Assignee: Hewlett Packard Enterprise Development LPInventors: Ludovic Emmanuel Paul Noel Jacquin, Nigel John Edwards, Thomas M. Laffey
-
Publication number: 20230222226Abstract: A technique includes an operating system agent of a computer system monitoring a process to detect whether an integrity of the process has been compromised. The monitoring includes the operating system agent scanning a data structure. The process executes in a user space, and the data structure is part of an operating system kernel space. The technique includes a hardware controller of the computer system listening for a heartbeat that is generated by the operating system agent. The hardware controller takes a corrective action in response to at least one of the hardware controller detecting an interruption of the heartbeat, or the operating system agent communicating to the hardware controller a security alert for the process.Type: ApplicationFiled: March 21, 2023Publication date: July 13, 2023Inventors: Geoffrey Ndu, Nigel John Edwards
-
Patent number: 11636214Abstract: A technique includes an operating system agent of a computer system monitoring a process to detect whether an integrity of the process has been compromised. The monitoring includes the operating system agent scanning a data structure. The process executes in a user space, and the data structure is part of an operating system kernel space. The technique includes a hardware controller of the computer system listening for a heartbeat that is generated by the operating system agent. The hardware controller takes a corrective action in response to at least one of the hardware controller detecting an interruption of the heartbeat, or the operating system agent communicating to the hardware controller a security alert for the process.Type: GrantFiled: December 11, 2020Date of Patent: April 25, 2023Assignee: Hewlett Packard Enterprise Development LPInventors: Geoffrey Ndu, Nigel John Edwards
-
Publication number: 20230049131Abstract: In some examples, a system receives first measurements of data items used by a build server in building an executable program, the data items copied from a data repository to a storage partition that is separate from the data repository, and the storage partition to store the data items relating to building the executable program by the build server. The system determines, based on the first measurements and according to a policy specified for the storage partition, whether a corruption of the data items used by the build server in building the executable program has occurred.Type: ApplicationFiled: August 10, 2021Publication date: February 16, 2023Inventors: Nigel John Edwards, Guilherme de Campos Magalhaes