发明授权
US08307098B1 System, method, and program for managing a user key used to sign a message for a data processing system
有权
用于管理用于对数据处理系统的消息进行签名的用户密钥的系统,方法和程序
- 专利标题: System, method, and program for managing a user key used to sign a message for a data processing system
- 专利标题(中): 用于管理用于对数据处理系统的消息进行签名的用户密钥的系统,方法和程序
-
申请号: US09651548申请日: 2000-08-29
-
公开(公告)号: US08307098B1公开(公告)日: 2012-11-06
- 发明人: Barry Atkins , David Carroll Challener , Frank Novak , Joseph Gary Rusnak , Kenneth D. Timmons , William W. Vetter
- 申请人: Barry Atkins , David Carroll Challener , Frank Novak , Joseph Gary Rusnak , Kenneth D. Timmons , William W. Vetter
- 申请人地址: SG Singapore
- 专利权人: Lenovo (Singapore) Pte. Ltd.
- 当前专利权人: Lenovo (Singapore) Pte. Ltd.
- 当前专利权人地址: SG Singapore
- 代理机构: Yudell Isidore Ng Russell PLLC
- 代理商 Antony P. Ng
- 主分类号: G06F15/16
- IPC分类号: G06F15/16
摘要:
A system, method, and program for managing a user key used to sign a message for a data processing system having an encryption chip are disclosed. A user is assigned a user key. In order to encrypt and send messages to a recipient(s), the messages are encrypted with the user key. The user key, in turn, is encrypted with an associated key. The associated key is further encrypted using an encryption chip key stored on the encryption chip. The encrypted messages are communicated to a recipient to validate an association of the user with the encrypted messages. The associated key is decrypted with the encryption chip key. The user key is decrypted with the associated key, and the messages are decrypted with the user key. Thereafter, validation of the association of messages with the user is removed by revoking the associated key. In a preferred embodiment, encryption resources are centralized in a server system having the encryption chip. The server system is coupled to and provides encryption services to a plurality of client systems. Messages to be encrypted are sent from a user's client system to the server system, which encrypts the messages using the encryption chip. The encrypted messages are sent from the server system to the client system, which then transmits the encrypted messages to their intended recipient(s). All data relating to the encrypted messages are erased from the server system after the encrypted messages are sent from the server system to the client system.
信息查询