发明授权
- 专利标题: Mechanisms to control access to cryptographic keys and to attest to the approved configurations of computer platforms
- 专利标题(中): 控制加密密钥访问的机制,并证明已批准的计算机平台配置
-
申请号: US11511773申请日: 2006-08-29
-
公开(公告)号: US07711960B2公开(公告)日: 2010-05-04
- 发明人: Vincent Scarlata
- 申请人: Vincent Scarlata
- 申请人地址: US CA Santa Clara
- 专利权人: Intel Corporation
- 当前专利权人: Intel Corporation
- 当前专利权人地址: US CA Santa Clara
- 代理机构: Schubert Osterrieder & Nickelson PLLC
- 代理商 Neil Cohen
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
Methods and arrangements to control access to cryptographic keys and to attest to the approved configurations of computer platforms able to access these keys, which include trusted platform modules (TPMs) are contemplated. Embodiments include transformations, code, state machines or other logic to control access to a cryptographic key by creating an authorization blob locking authorization data to access the cryptographic key to platform configuration register (PCR) values of a TPM, the PCR values representing a configuration of a computing platform. Embodiments may also involve generating a first TPM cryptographic key bound to PCR values, receiving a second TPM cryptographic key owned by software, and receiving evidence of the identity of an upgrade service controlling the upgrading of the software. Embodiment may also include certifying the first TPM cryptographic key; certifying the second TPM cryptographic key; concatenating the first certification, the second certification, and the evidence of the identity of the upgrade service; and signing the concatenation.
公开/授权文献
信息查询