Skip to navigation
   
Simon Bisson & Mary Branscombe's Blog

You say Express Gate, I say Palladium

By Simon Bisson & Mary Branscombe in Editorial

Posted in Futures, Silicon, virtualisation, Hardware, Laptop, Mobile, Security, Intel, Microsoft on July 28, 2008 at 12:41 pm

Permalink | Author Profile

Imagine a second, simpler operating system on your PC with fixed features, so it’s more secure - after all, if you can’t add more programs you can’t add a virus either. It would have to start up quickly, so that Windows wasn’t waiting for it, so it would be ideal for listening to music and watching video. I’m not thinking about virtualization per se, although that’s one way to achieve something similar; this is two operating systems side by side, both with access to the PC hardware, but one of them does much more limited and circumscribed things.

Can you tell what it is yet?

No, actually, I’m not talking about Palladium - sorry, Microsoft Next Generation Secure Computing Base. That grew out of an attempt to reassure Sony that it would be OK to allow DVD movies to play on a PC without piracy becoming endemic and turned into a much more useful and visionary idea about using public key cryptography not to identify people but to secure machines. It would have been a good way to implement the DRM it was associated with in the public eye, though wouldn’t have forced it on anyone who didn’t want to run it. Palladium loaded a secure piece of software called the TOR that acted as a secure area that could only run trusted code (written to public APIs), where the apps would be invisible to the main OS - all secured by the machine-specific key in your TPM and some new technology from Intel.

12345
Not yet rated
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by steven Sprague - August 7, 2008 on 5:49 pm

Great article. You should also point out that the TPM which is now on about 150 million pcs is a fantastic way to have a common authentication platform for all web services. This will be the technology that kill UID and PW. Every VPN and Wireless access point be putting the keys in the TPM. It works today, Its easy to do however most IT professionals haven’t tried. Best Practice is all software certificates need to be moved to hardware.

Steven Sprague

Comment by Simon Bisson & Mary Branscombe - August 7, 2008 on 6:44 pm

Good point Steve; I actually like Intel’s notion of a trusted PC and a trusted platform as the root of trust for user identity feeding into an Internet identity layer (I’m a big fan of Kim Cameron’s infocard approach). But how do we get things to move forward? So far I’ve found nothing mainstream but fingerprint password vaults that actually use TPM in the real world (and vPro, but that still seems to be in demo mode)…

Trackback by Theodore Mcoy - February 9, 2012 on 7:56 am

will smith gay role…

[…]first portion of the new year. Numerous men and women believe that the circumstance […]…

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

todo list benchmark radeon OFCOM SSD IIW2008b mythbusters Embarcadero T-Mobile Tombstone Objects accessories HSPA NexT public cloud Opsware merger terabytes Live Mesh fingerprint scanner OpenID parallel computing outlook power goview private cloud Wimbledon Chrome support troubleshooting cloud service google online applications netiquette encryption amazon BBC futura i-mate Internet Explorer 8 IM network Mini-Note Hp 2710p networks ADFS 2.0 MAX Barracuda pen computing tele atlas BT Xen SBS aws Smartbook CTO etech offload fire Facebook bletchley park sun mysql DSL web 2.0 expo colossus Magny-Cours Windows Server 2008 cracking VSSAdmin innovation hard drive demo09 augmented reality optical interconnects information rights management national museum of computing apps FUD bandwidth regulations 2.0 deborah adler Fire Eagle Bill Gates police mash-up business model eu bug 3G Verbatim setup icons vulnerabilities greenplum mobile broadband AIR fonts desktop. PC upgrade high performance computing 2009 ribbon WPF BitLocker CardSpace Eee PC disk space Opera Mercury LiveID DOS data centre hibernation virus application compatibility backhaul task bar ubuntu voice ANR AMD co-processor identity metasystem Mozilla utility CUDA Tripit Clear RX natural interface Frauenhofer web2expo evernote ballmerbot old software wubi Hugh Thompson gabriola Firefox screencam direct access yahoo Adobe interoperability Qualcomm atom streaming media control panel security paradox Windows Mobile RIM hp microsoft research magic macbook Treo Pro netbook p2v citrix database wes camera Tom Hogan migration Pal Trolltech AskEraser switch TouchSmart IO city international roaming ec2 traffic secure green IT thermo tablet SP1 hdmi logitech video anti-patterns workflow Netscape HTC isp media center microsoft security essentials distributed computing market share enterprise architecture ucsd griffin verdana codec OEM pgp HSDPA Beacon CPU WinHEC hierarchical temporal memory amherst geek tourism cold fusion power cuts cellcrypt html no signal teched enterprise business intelligence fault office politics mms 2009 Linux conferences TSA Netscan installation Vista mscape christmas android GPU RAZR Google IO Xobni xT9 O'Reilly exabytes Protected View Ask.com LHC media mobility nvision08 Intel EEE mobile Location appstore laptop HP annotation display spam instant messaging Moonlight community server Vodafone Palm appzero uninstall CERN identity theft privacy credit crunch g-1 service oriented enterprise Google geotagging electricity price Trend Micro Bing MING emulator Gartner timezones cosmic rays SMB 2 Dopplr Bill Cheswick advertising bugs phone settings RSA 2008 development information QWERTY Palladium fingerprint it pro SapphireSteel robot smartphone Jeff Hawkins Wyse multiple monitors BlackBerry biometrics mapping adfs information cards analytics Windows Server training regulation virtual desktop Nuance DLP wireless USB office 2010 quiz Reqall design toshiba MacWorld 2008 Safari visualisation system center accelerator business connectivity Itanium infrastructure mobile data tariffs SKU mobile Linux Secunia CIO twitter fibre HTML 5 iPass cam IT policy Mark Hurd conference culture Gears Istanbul vmware Microsoft legislation Girl Geek Dinners beta email RSS search windows voice recognition T9 cisco active digitiser management Web 2.0 Loki remove back Greasemoneky telecoms target how do I get the back off? Toshiba Portege R500 Credentica rtm system management flash drive october Windows 7 vs Windows Vista trends gamer business continuity windows 7 security EMC data loss power saving data tariff M&A Skyfire ProCurve Dell applications whitelist social engineering designer transcoding ipsec hyper-v cloud computing safend case Delphi MRDA processors lost server congestion charge Sony hacking consolidation data centre transformation bolt Apple relocation cables context OQO Crossfader Previous Versions clean install people developer maps software browser Ruby On Rails d2c acquisitions licensing Ray Ozzie Motorola cloud Windows Live security theatre Corsair geneva mainframe turing Tablet PC WEI 64-bit bombe phone management patch Tuesday navigation Salesforce Nokia Volume Shadow Copy wildfire ultraportable Google Sets ontier NVIDIA insert SIM dual boot utilities anti-trust IT value Visual Studio microsoft research machine learning Silverlight Seagate IT automation meaning future in review firewall gaming Google Spreadsheets open Tim Berners-Lee UMPC WWW NGSCB productivity search hold music politics bbc iplayer Opteron Active Directory docking station catalyst pre-boot lawsuit HMT rich client lockdown DOSBox GPS BES disk legacy project ClipMate battery life mobile ofcom network Jeff Jones macro storage claims hardware Numenta web moscow MWC identitity images keyboard collaboration winhec2008 virtualisation Trampoline beta test mobile working moblin performance server sprawl MIX08 exchange Java Internet Explorer business technology automation ruggedized Mono education wifi Ruby malware g-2 drivers routing gameboard 965 data loss prevention ports oracle social networking IT transformation flex numbers green printing Lenovo Large Hadron Collider downturn ikea O2 thin client patent windows server 2008 r2 user interface venture capital dvi monitor AuthenTec Tablet Kiosk Internet IDF geocaching navteq iPhone .NET MacBook Air history pixetell london Quest MIX screen installer RIA data webkit forensics usb Enterprise 2.0 dual display demo rc Asus mobile network deperimeterization isps ipv6 disaster recovery calit2 TechEd 2008 Express Gate bea user experience semiotics business technology optimisation office Acrobat Pro NAS open source ATI DisplayLink GPL CES anti-virus competition RBL netbooks flash spam fighting IBM wave power supply tennis
Advertisement
Advertisement