Skip to navigation
   
Simon Bisson & Mary Branscombe's Blog

You say Express Gate, I say Palladium

By Simon Bisson & Mary Branscombe in Editorial

Posted in Futures, Silicon, virtualisation, Hardware, Laptop, Mobile, Security, Intel, Microsoft on July 28, 2008 at 12:41 pm

Permalink | Author Profile

Imagine a second, simpler operating system on your PC with fixed features, so it’s more secure - after all, if you can’t add more programs you can’t add a virus either. It would have to start up quickly, so that Windows wasn’t waiting for it, so it would be ideal for listening to music and watching video. I’m not thinking about virtualization per se, although that’s one way to achieve something similar; this is two operating systems side by side, both with access to the PC hardware, but one of them does much more limited and circumscribed things.

Can you tell what it is yet?

No, actually, I’m not talking about Palladium - sorry, Microsoft Next Generation Secure Computing Base. That grew out of an attempt to reassure Sony that it would be OK to allow DVD movies to play on a PC without piracy becoming endemic and turned into a much more useful and visionary idea about using public key cryptography not to identify people but to secure machines. It would have been a good way to implement the DRM it was associated with in the public eye, though wouldn’t have forced it on anyone who didn’t want to run it. Palladium loaded a secure piece of software called the TOR that acted as a secure area that could only run trusted code (written to public APIs), where the apps would be invisible to the main OS - all secured by the machine-specific key in your TPM and some new technology from Intel.

12345
Not yet rated
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by steven Sprague - August 7, 2008 on 5:49 pm

Great article. You should also point out that the TPM which is now on about 150 million pcs is a fantastic way to have a common authentication platform for all web services. This will be the technology that kill UID and PW. Every VPN and Wireless access point be putting the keys in the TPM. It works today, Its easy to do however most IT professionals haven’t tried. Best Practice is all software certificates need to be moved to hardware.

Steven Sprague

Comment by Simon Bisson & Mary Branscombe - August 7, 2008 on 6:44 pm

Good point Steve; I actually like Intel’s notion of a trusted PC and a trusted platform as the root of trust for user identity feeding into an Internet identity layer (I’m a big fan of Kim Cameron’s infocard approach). But how do we get things to move forward? So far I’ve found nothing mainstream but fingerprint password vaults that actually use TPM in the real world (and vPro, but that still seems to be in demo mode)…

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

SBS cloud service google online applications conference pixetell Intel wave keyboard installation cloud enterprise architecture natural interface National Insurance Mark Hurd no signal Clear RX fibre innovation logitech OpenID ClipMate citrix IIW2008b laptop Microsoft BT ec2 navteq telecoms mobile Linux IT transformation IT policy cold fusion iPhone Web 2.0 BitLocker beta test insert SIM education battery life claims wubi hardware congestion charge TouchSmart IDF macbook cellcrypt Opera Active Directory SSVAGENT.EXE system center SapphireSteel interoperability camera MIX08 Google IO merger business cracking ADFS 2.0 green IT office politics community wireless USB CardSpace anti-patterns WEI bletchley park SMB 2 wifi Xen microsoft research electricity price i-mate security paradox Embarcadero annotation Toshiba Portege R500 Google Spreadsheets RSA 2008 quiz MIX RBL ucsd Windows 7 vs Windows Vista trends wes data loss colossus greenplum LHC eu police power supply backhaul CPU UMPC Sony html disaster recovery RAZR anti-virus Vodafone Beacon fingerprint scanner case transcoding project pgp ultraportable thin client disk space AdaLovelaceDay09 analytics NGSCB sun hp microsoft research Delphi developer task bar usb timezones traffic radeon streaming media OQO CUDA evernote turing ProCurve mainframe Acrobat Pro deperimeterization visualisation people Visual Studio offload market share Trend Micro history Volume Shadow Copy credit crunch target spam fighting mobile benchmark isp Ray Ozzie Internet Explorer video lawsuit toshiba Itanium mobile data tariffs business technology optimisation T-Mobile Netscape CIO oracle Tim Berners-Lee pre-boot 3G data centre transformation Hugh Thompson flash Chrome biometrics Previous Versions Ask.com Tablet PC netiquette vmware geocaching screencam exchange codec Dell secure hacking outlook AskEraser Location goview international roaming ruggedized Mercury NVIDIA training TSA DLP Internet Jeff Hawkins identity theft migration Treo Pro Girl Geek Dinners system management HMT isps Enterprise 2.0 demo support robot ipv6 Internet Explorer 8 calit2 twitter virtual desktop TNT moscow rich client aws flash drive mscape DisplayLink power cuts HP xT9 browser MacWorld 2008 HTML 5 M&A email acquisitions power saving Seagate rtm service oriented enterprise Motorola Loki management city switch data magic Dopplr cables open source ontier multiple monitors Ruby On Rails Asus NexT wildfire Silverlight private cloud CTO Large Hadron Collider hyper-v mobile working Bill Gates SP1 windows 7 ports virtualisation cam data tariff DSL IO mythbusters vulnerabilities mms 2009 business model forensics relocation october routing web OEM flex utilities virus O2 Safari .NET 2.0 software Google Apple macro business technology automation HSDPA encryption amazon terabytes mapping icons web2expo applications voice recognition gameboard hdmi screen information RIM geotagging Trampoline Mono Mozilla Netscan MAX bombe storage 64-bit mobile ofcom network Frauenhofer ANR dvi augmented reality london processors Adobe competition catalyst remove back Ruby office Bill Cheswick VSSAdmin Tripit Corsair troubleshooting productivity Istanbul christmas ubuntu smartphone ballmerbot networks windows server 2008 r2 media center RIA Salesforce fingerprint geneva lockdown etech QWERTY WWW Wimbledon Windows Server dual boot downturn IT value gamer business intelligence Verbatim Facebook drivers Fire Eagle dual display Gartner IT automation GPU direct access MING Firefox BBC gaming disk Google Sets AuthenTec Tablet Kiosk patent identity metasystem parallel computing social networking mobility uninstall server sprawl Credentica Nokia display Crossfader Nuance consolidation user interface MRDA regulation hard drive business continuity Moonlight Opteron regulations bug privacy cisco active digitiser teched Windows Live Tombstone Objects Palm politics Eee PC beta Opsware OFCOM Barracuda nvision08 NAS Vista machine learning desktop. PC data centre Pal demo09 android g-1 Skyfire it pro advertising thermo Lenovo LiveID Xobni database Reqall mash-up social engineering mysql designer hierarchical temporal memory Hp 2710p HTC IBM navigation deborah adler rc maps workflow Palladium exabytes control panel infrastructure hold music RSS search Magny-Cours T9 accelerator Express Gate bandwidth instant messaging CERN tele atlas phone settings CES WPF todo list connectivity tennis future in review SSD MacBook Air Tom Hogan cloud computing pen computing Windows Mobile monitor identitity high performance computing server optical interconnects yahoo d2c numbers amherst Wyse fault security theatre co-processor whitelist ipsec network 965 how do I get the back off? Numenta design p2v green printing windows culture Gears open user experience fire Windows Server 2008 SKU adfs information cards utility O'Reilly venture capital enterprise EMC phone management voice Quest bea appzero safend WinHEC spam GPS firewall digital signature Secunia mobile network 2009 security lost server docking station MWC distributed computing EEE collaboration geek tourism cosmic rays netbook netbooks patch Tuesday media TechEd 2008 images Trolltech licensing national museum of computing upgrade ATI bbc iplayer public cloud development BES Live Mesh griffin conferences power Jeff Jones installer BlackBerry g-2 Linux IM AMD legislation Greasemoneky Mini-Note winhec2008 performance accessories web 2.0 expo
Advertisement
Advertisement