METHOD AND DEVICE FOR SECURE COMMUNICATIONS OVER A NETWORK USING A HARDWARE SECURITY ENGINE

    公开(公告)号:EP4040717A1

    公开(公告)日:2022-08-10

    申请号:EP22166740.5

    申请日:2011-12-15

    Abstract: A system-on-a-chip (112) apparatus comprising a system-on-a-chip (112) comprising a security engine (110) that is separate from a processor core (118) of the system-on-a-chip (112) and has a secure memory (114) accessible only by the security engine, wherein the secure memory (114) includes a security key (150) that was encoded in the secure memory (114) during a manufacturing process of the system-on-a-chip (112), the security engine to generate a random nonce for initiating a request for a secure communication session with a remote server (104) over a network (106) using the nonce; perform a cryptographic key exchange with the remote server; generate a symmetric session key, based on the cryptographic key exchange, to encrypt messages sent to the remote server and decrypt messages received from the remote server during the secure communication session; encrypt the symmetric session key (150) based on the security key; and store the encrypted session key in the secure memory, the system-on-a-chip to establish the secure communication session with the remote server over the network using the session key.

    SYSTEM PLATFORM FOR CONTEXT-BASED CONFIGURATION OF COMMUNICATION CHANNELS
    2.
    发明公开
    SYSTEM PLATFORM FOR CONTEXT-BASED CONFIGURATION OF COMMUNICATION CHANNELS 审中-公开
    用于基于上下文的通信信道配置的系统平台

    公开(公告)号:EP3235221A1

    公开(公告)日:2017-10-25

    申请号:EP15870515.2

    申请日:2015-10-05

    Abstract: The techniques described herein include configuration of channels between devices and service providers at a connectable system platform. For example, a system platform may include a receiver to receive data from a communicatively coupled device. The system platform may include a controller having logic, at least partially comprising hardware logic, to configure communications channels. The communication channels include a communication channel for transmission between the system platform and a service provider to receive the data, and a communication channel for transmission between the system platform and the coupled device. The communication channels are configured based on a context. The context comprises characteristics of the coupled device, content of the data, and security requirements associated with the service provider.

    Abstract translation: 这里描述的技术包括在可连接系统平台处的设备和服务提供商之间的信道配置。 例如,系统平台可以包括接收器以从通信耦合的设备接收数据。 该系统平台可以包括具有逻辑的控制器,该逻辑至少部分地包括硬件逻辑以配置通信信道。 通信信道包括用于在系统平台和服务提供商之间传输以接收数据的通信信道以及用于在系统平台和耦合设备之间传输的通信信道。 通信通道基于上下文进行配置。 上下文包括耦合设备的特性,数据内容以及与服务提供商相关的安全要求。

    SECURELY PAIRING COMPUTING DEVICES
    3.
    发明公开
    SECURELY PAIRING COMPUTING DEVICES 审中-公开
    安全配对计算设备

    公开(公告)号:EP3198789A1

    公开(公告)日:2017-08-02

    申请号:EP15844536.1

    申请日:2015-08-21

    Abstract: In an embodiment, an apparatus comprises a secure storage to store an entry having an identifier of a device to be paired with the apparatus and a master key shared between the apparatus and the device, and a connection logic to enable the apparatus to be securely connected to the device according to a connection protocol in which the device is authenticated based on the identifier received from the device and the master key. Other embodiments are described and claimed.

    Abstract translation: 在一个实施例中,一种设备包括:安全存储器,用于存储具有将与设备配对的设备的标识符和在设备与设备之间共享的主密钥的条目;以及连接逻辑,用于使设备安全地连接 根据其中设备根据从设备接收到的标识符和主密钥而被认证的连接协议向设备发送。 描述并要求保护其他实施例。

    Providing software distribution and update services regardless of the state or physical location of an end point machine
    10.
    发明公开
    Providing software distribution and update services regardless of the state or physical location of an end point machine 有权
    软件分发和更新服务的提供,无论国家或端点设备的物理位置

    公开(公告)号:EP2339460A2

    公开(公告)日:2011-06-29

    申请号:EP10252160.6

    申请日:2010-12-17

    CPC classification number: G06F8/61 G06F8/65

    Abstract: In accordance with some embodiments, software may be downloaded to an end point, even when that said end point is not fully functional. An indication that software is available for distribution may be stored in a dedicated location within a non-volatile memory. That location may be checked for software to download, for example, on each boot up. The software may then be downloaded and verified. Thereafter, the location is marked to indicate that the software has already been downloaded.

    Abstract translation: 在一些实施方案雅舞蹈,软件可以被下载到结束点,即使这就是说终点是没有充分发挥作用。 的指示的确软件可用于分配可被存储在专用位置的非易失性存储器内。 该位置可检查软件进行下载,例如,在每次启动起来。然后,该软件可以下载和验证。 那里以后,位置标记来指示DASS模具软件已经被下载。

Patent Agency Ranking