发明授权
US07711960B2 Mechanisms to control access to cryptographic keys and to attest to the approved configurations of computer platforms 失效
控制加密密钥访问的机制,并证明已批准的计算机平台配置

  • 专利标题: Mechanisms to control access to cryptographic keys and to attest to the approved configurations of computer platforms
  • 专利标题(中): 控制加密密钥访问的机制,并证明已批准的计算机平台配置
  • 申请号: US11511773
    申请日: 2006-08-29
  • 公开(公告)号: US07711960B2
    公开(公告)日: 2010-05-04
  • 发明人: Vincent Scarlata
  • 申请人: Vincent Scarlata
  • 申请人地址: US CA Santa Clara
  • 专利权人: Intel Corporation
  • 当前专利权人: Intel Corporation
  • 当前专利权人地址: US CA Santa Clara
  • 代理机构: Schubert Osterrieder & Nickelson PLLC
  • 代理商 Neil Cohen
  • 主分类号: G06F21/00
  • IPC分类号: G06F21/00
Mechanisms to control access to cryptographic keys and to attest to the approved configurations of computer platforms
摘要:
Methods and arrangements to control access to cryptographic keys and to attest to the approved configurations of computer platforms able to access these keys, which include trusted platform modules (TPMs) are contemplated. Embodiments include transformations, code, state machines or other logic to control access to a cryptographic key by creating an authorization blob locking authorization data to access the cryptographic key to platform configuration register (PCR) values of a TPM, the PCR values representing a configuration of a computing platform. Embodiments may also involve generating a first TPM cryptographic key bound to PCR values, receiving a second TPM cryptographic key owned by software, and receiving evidence of the identity of an upgrade service controlling the upgrading of the software. Embodiment may also include certifying the first TPM cryptographic key; certifying the second TPM cryptographic key; concatenating the first certification, the second certification, and the evidence of the identity of the upgrade service; and signing the concatenation.
信息查询
0/0