发明申请
- 专利标题: DEVICE, METHOD, AND SYSTEM FOR SECURE TRUST ANCHOR PROVISIONING AND PROTECTION USING TAMPER-RESISTANT HARDWARE
- 专利标题(中): 使用防潮硬件安全信赖锚定器和保护的装置,方法和系统
-
申请号: US13631562申请日: 2012-09-28
-
公开(公告)号: US20140095867A1公开(公告)日: 2014-04-03
- 发明人: Ned M. Smith , David Johnston , George W. Cox , Adi Shaliv
- 申请人: Ned M. Smith , David Johnston , George W. Cox , Adi Shaliv
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L9/32 ; G06F17/30 ; H04L9/00 ; H04L9/08
摘要:
A method and device for securely provisioning trust anchors includes generating a database wrapper key as a function of computing device hardware. The database wrapper key encrypts a key database when it is not in use by a trusted execution environment and may be generated using a Physical Unclonable Function (PUF). A local computing device establishes a secure connection and security protocols with a remote computing device. In establishing the secure connection, the local computing device and remote computing device may exchange and/or authenticate cryptographic keys, including Enhanced Privacy Identification (EPID) keys, and establish a session key and device identifier(s). One or more trust anchors are then provisioned depending on whether unilateral, bilateral, or multilateral trust is established. The local computing device may act as a group or domain controller in establishing multilateral trust. Any of the devices may also require user presence to be verified.
公开/授权文献
信息查询