Skip to navigation
   
Simon Bisson & Mary Branscombe's Blog

You say Express Gate, I say Palladium

By Simon Bisson & Mary Branscombe in Editorial

Posted in Futures, Silicon, virtualisation, Hardware, Laptop, Mobile, Security, Intel, Microsoft on July 28, 2008 at 12:41 pm

Permalink | Author Profile

Imagine a second, simpler operating system on your PC with fixed features, so it’s more secure - after all, if you can’t add more programs you can’t add a virus either. It would have to start up quickly, so that Windows wasn’t waiting for it, so it would be ideal for listening to music and watching video. I’m not thinking about virtualization per se, although that’s one way to achieve something similar; this is two operating systems side by side, both with access to the PC hardware, but one of them does much more limited and circumscribed things.

Can you tell what it is yet?

No, actually, I’m not talking about Palladium - sorry, Microsoft Next Generation Secure Computing Base. That grew out of an attempt to reassure Sony that it would be OK to allow DVD movies to play on a PC without piracy becoming endemic and turned into a much more useful and visionary idea about using public key cryptography not to identify people but to secure machines. It would have been a good way to implement the DRM it was associated with in the public eye, though wouldn’t have forced it on anyone who didn’t want to run it. Palladium loaded a secure piece of software called the TOR that acted as a secure area that could only run trusted code (written to public APIs), where the apps would be invisible to the main OS - all secured by the machine-specific key in your TPM and some new technology from Intel. 

Ironically, trust was the issue with Palladium; nobody trusted Microsoft to either be building a secure system that didn’t impact on a very robust interpretation of free speech or if it was, to do it right. The smallest part of the concept made it in a couple of versions of Vista as BitLocker; whole disk encryption secured by the TPM.
But the Palladium concepts are showing up in a lot of other places, including the NSA’s Security Enhanced Linux and Citrix’s Security Enhanced Xen - a small OS that runs as a secure virtual machine with isolated applications, using the TPM and Intel’s new hardware virtualization technology …

Intel even uses the words Trusted Computing Base, which might be a hostage to fortune given the fate of Palladium. The DRM discussion hasn’t started yet, but there’s a trusted channel to the keyboard, mouse, memory - and the graphics subsystem, which is what some thought would allow copy-protected DVDs to be watched in the secure area of Palladium, without the option to copy them. This time around it’s more likely to be copy-protected downloads: killing off HD DVD has actually made Blu-Ray less likely to get mass adoption,  as player and disc prices stay high.

There are far more benefits to Palladium-style secure computing than protecting the movie industry or saving the banking industry from having to upgrade anti-fraud backends. You may keep your AV up to date and your company documents secure, but one in six of all PCs that touch the Google site has a bot and they’re all sending you spam.

And while the systems that look so much like Palladium that I get déjà vu are still a little way off, Asus is already selling machines with Express Gate. Granted, this is more like the embedded operating systems you see on a lot of media notebooks; it boots up in eight seconds and lets you see your photos and play your music. It has an Internet connection, so you can browse the Web without waiting for Windows. But it also uses the TPM in Montevina and you can treat it as an isolated operating system, says the press release: “Friends and family can use your notebook to nip online, use IM, listen to music, play and view without having access to your data, the system or the Windows environment.” Very Palladian.
-Mary

12345
Not yet rated
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by steven Sprague - August 7, 2008 on 5:49 pm

Great article. You should also point out that the TPM which is now on about 150 million pcs is a fantastic way to have a common authentication platform for all web services. This will be the technology that kill UID and PW. Every VPN and Wireless access point be putting the keys in the TPM. It works today, Its easy to do however most IT professionals haven’t tried. Best Practice is all software certificates need to be moved to hardware.

Steven Sprague

Comment by Simon Bisson & Mary Branscombe - August 7, 2008 on 6:44 pm

Good point Steve; I actually like Intel’s notion of a trusted PC and a trusted platform as the root of trust for user identity feeding into an Internet identity layer (I’m a big fan of Kim Cameron’s infocard approach). But how do we get things to move forward? So far I’ve found nothing mainstream but fingerprint password vaults that actually use TPM in the real world (and vPro, but that still seems to be in demo mode)…

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

ruggedized CUDA Vista isp optical interconnects greenplum 24 hours ADFS 2.0 yahoo security CPU benchmark Nokia history Intel Linux Google IO provisioning SBS telecoms geotagging Delphi virtual desktop SSD disk space cloud service google online applications IT automation hp microsoft research .NET OFCOM machine learning numbers deperimeterization regulations digital signature Motorola Trend Micro Express Gate Microsoft firewall Beacon Web 2.0 AuthenTec HP Palm BT open source fingerprint scanner IT value sun ballmerbot Tripit power supply 3G LiveID SP1 Google parallel computing TNT Enterprise 2.0 OpenID CardSpace TouchSmart Google Spreadsheets wifi Tim Berners-Lee electricity price Internet Explorer 8 Moonlight MRDA payroll isps green IT Secunia merger utilities spin high performance computing enterprise open Google Sets ucsd enterprise architecture pgp robot ubuntu Wyse mobile ofcom network griffin. microsoft research camera smartphone Salesforce whitelist geocaching conference cracking storage SSVAGENT.EXE lawsuit Windows Server 2008 bandwidth bletchley park case bbc iplayer amherst automation Xen TechEd 2008 Crossfader mysql geneva co-processor Internet identity metasystem email Jeff Hawkins bombe TSA IBM Jeff Jones pen computing iPhone fault GPU acquisitions business intelligence exabytes eu Seagate Firefox Bill Gates toshiba UMPC evernote CES privacy battery Volume Shadow Copy wubi fibre migration MING EEE software traffic networks Xobni OEM patch Tuesday windows 7 Facebook oracle nvision08 todo list service oriented enterprise beta Ruby On Rails voice recognition adfs Dopplr Greasemoneky forensics 64-bit CTO WWW SMB 2 WinHEC NVIDIA support management community RBL winhec2008 National Insurance server spam Internet Explorer Palladium legislation natural interface BBC video NGSCB colossus laptop AskEraser accessories Gears Reqall control panel Frauenhofer identitity fraud hierarchical temporal memory flash processors mscape business technology optimisation images Live Mesh productivity browser Girl Geek Dinners MIX08 mobile hold music Ray Ozzie politics MacBook Air hacking EMC SapphireSteel visualisation vulnerabilities network troubleshooting power cuts GPS bea desktop. PC cables wildfire business continuity spam fighting user interface O'Reilly Adobe Loki codec Previous Versions information NexT etech ProCurve CERN dual display licensing Gartner office interoperability Silverlight Lenovo blog Fire Eagle data onboarding disk Visual Studio thin client transcoding geek tourism Opsware advertising Hp 2710p user experience mash-up Tom Hogan business technology automation i-mate Location HTML 5 installer accelerator developer DSL VSSAdmin phone management information cards Credentica Windows Mobile Windows Live anti-virus Trampoline Nuance patent Verbatim fire fingerprint Mercury IIW2008b HTC security paradox HSDPA Mono mobile Linux regulation gaming cosmic rays HMT biometrics Tablet Kiosk O2 Embarcadero credit crunch NAS Ask.com conferences quiz html analytics education business Numenta LHC Tablet PC green printing wireless USB RAZR national museum of computing RIA calit2 Mozilla Ruby Apple distributed computing virtualisation Corsair DisplayLink Toshiba Portege R500 WPF Large Hadron Collider media power IT transformation Bill Cheswick security theatre Asus AMD upgrade timezones macbook RSA 2008 identity theft Trolltech IDF hardware mobile data tariffs exchange cisco active digitiser mobility CIO social networking data centre terabytes moscow offload MacWorld 2008 QWERTY christmas xT9 Hugh Thompson Dell HR automation Netscan T9 streaming media Barracuda mythbusters performance OQO turing mobile working
Advertisement
Advertisement
Advertisement