Methods and apparatus for mixing encrypted data with unencrypted data
    31.
    发明申请
    Methods and apparatus for mixing encrypted data with unencrypted data 有权
    将加密数据与未加密数据进行混合的方法和装置

    公开(公告)号:US20050135618A1

    公开(公告)日:2005-06-23

    申请号:US10745424

    申请日:2003-12-22

    IPC分类号: H04N7/24 H04N7/167

    摘要: Methods and apparatus for mixing encrypted data with unencrypted data are disclosed. A disclosed system receives data from a first media source, such as DVD-Audio content, and encrypts the data from the first media source using a key stream to form an encrypted data stream. The disclosed system may separate the encrypted data stream into a plurality of encrypted data streams and may combine the plurality of encrypted data streams with an unencrypted data stream associated with a second media source to form a mixed data stream. The mixed data stream is formed without decrypting the plurality of encrypted data streams and is transmitted to hardware or a hardware driver.

    摘要翻译: 公开了加密数据与未加密数据混合的方法和装置。 所公开的系统从诸如DVD音频内容的第一媒体源接收数据,并且使用密钥流来加密来自第一媒体源的数据以形成加密的数据流。 所公开的系统可以将加密的数据流分离成多个加密数据流,并且可以将多个加密数据流与与第二媒体源相关联的未加密数据流组合以形成混合数据流。 形成混合数据流,而不对多个加密数据流进行解密,并将其传输到硬件或硬件驱动器。

    Revocation distribution
    32.
    发明申请
    Revocation distribution 有权
    撤销分配

    公开(公告)号:US20050015586A1

    公开(公告)日:2005-01-20

    申请号:US10622286

    申请日:2003-07-18

    申请人: Ernie Brickell

    发明人: Ernie Brickell

    IPC分类号: H04L9/32 H04L29/06 H04L9/00

    摘要: A server registering a first party as a party relying upon a second party's certificate, revoking the second party's certificate after registering the first party, and initiating communication with the first party to indicate that the second party's certificate has been revoked.

    摘要翻译: 注册第一方作为依靠第二方证书的一方的服务器,在注册第一方之后撤销第二方的证书,以及发起与第一方的通信以指示第二方的证书已被撤销。

    Replacing Blinded Authentication Authority
    33.
    发明申请
    Replacing Blinded Authentication Authority 审中-公开
    更换盲人认证机构

    公开(公告)号:US20110307704A1

    公开(公告)日:2011-12-15

    申请号:US13217151

    申请日:2011-08-24

    IPC分类号: H04L9/32

    摘要: A manufacturing entity provides a blinded signature to a secure device and associates a time with the blinded signature. If a signing key is compromised, the manufacturing entity provides a time of the compromise and the time associated with the blinded signature to the replacement authority.

    摘要翻译: 制造实体向安全设备提供盲目签名,并将时间与盲人签名相关联。 如果一个签名密钥被泄露,制造实体提供了一个妥协的时间和与被替换机构的盲人签名相关联的时间。

    Method and system for creating random cryptographic keys in hardware
    34.
    发明授权
    Method and system for creating random cryptographic keys in hardware 有权
    用于在硬件中创建随机加密密钥的方法和系统

    公开(公告)号:US07813507B2

    公开(公告)日:2010-10-12

    申请号:US11112817

    申请日:2005-04-21

    IPC分类号: H04L9/00 H04K1/00

    CPC分类号: H04L9/0662 H04L9/0869

    摘要: A method and system for creating random cryptographic keys in hardware is described. One or more bits are generated via one or more random bit circuits. Each random bit circuit includes a sensing device coupled to a first device and a second device to compare the first device against the second device and to generate a random bit from a random state value. The generated bits from the random bit circuits are read, and a cryptographic key may then be computed based on the generated bits.

    摘要翻译: 描述了一种用于在硬件中创建随机加密密钥的方法和系统。 经由一个或多个随机位电路产生一个或多个位。 每个随机位电路包括耦合到第一设备的感测设备和用于将第一设备与第二设备进行比较并从随机状态值生成随机位的第二设备。 读取来自随机位电路的生成位,然后可以基于所生成的位来计算加密密钥。

    Method of using signatures for measurement in a trusted computing environment
    36.
    发明申请
    Method of using signatures for measurement in a trusted computing environment 有权
    在可信计算环境中使用签名进行测量的方法

    公开(公告)号:US20070226505A1

    公开(公告)日:2007-09-27

    申请号:US11390920

    申请日:2006-03-27

    申请人: Ernie Brickell

    发明人: Ernie Brickell

    IPC分类号: H04L9/00

    CPC分类号: G06F21/57

    摘要: Verification of an encrypted blob of data passed to a sealed storage function in a trusted platform module (TPM) of a computing platform by a software component, may be accomplished by receiving the encrypted blob of data and a digital signature for each of a set of platform configuration register (PCR) indicators and PCR value pairs from the software component. The encrypted blob of data may be decrypted using a TPM key to form a decrypted blob of data, the decrypted blob of data including a secret and a verification key. For each received digital signature of the set of PCR identifier and PCR value pairs, it may be determined if each received digital signature verifies using the verification key and rejecting the decrypted blob of data when any signature is not verified. For each received digital signature of the set of PCR identifier and a PCR value pairs, it may be determined if each received PCR value matches a current value stored in a corresponding PCR in the TPM and rejecting the decrypted blob of data when any corresponding pair of PCR values do not match. The secret may be output from the decrypted blob of data when the decrypted blob of data has not been rejected.

    摘要翻译: 通过软件组件验证传递给计算平台的可信平台模块(TPM)中的密封存储功能的加密数据块可以通过接收加密的数据块和数字签名来实现 平台配置寄存器(PCR)指示器和PCR值对从软件组件。 可以使用TPM密钥解密加密的数据块,以形成解密的数据块,解密的数据块包括秘密和验证密钥。 对于PCR标识符和PCR值对集合中的每个接收到的数字签名,可以确定每个接收的数字签名是否使用验证密钥进行验证,并且当没有验证任何签名时拒绝解密的数据块。 对于PCR标识符集合和PCR值对的每个接收到的数字签名,可以确定每个接收到的PCR值是否与存储在TPM中的相应PCR中的当前值相匹配,并且当任何相应的一对 PCR值不匹配。 当解密的数据块未被拒绝时,秘密可以从解密的数据块输出。

    Method of confirming a secure key exchange
    37.
    发明申请

    公开(公告)号:US20060245590A1

    公开(公告)日:2006-11-02

    申请号:US11479747

    申请日:2006-06-30

    申请人: Ernie Brickell

    发明人: Ernie Brickell

    IPC分类号: H04L9/00

    摘要: A key exchange protocol can be performed between components of a system, such as between a computer program being executed by the processor of a PC (or other computer system) and a peripheral. A peripheral with a user input capability and a very limited display capability, such as a keyboard or a mouse, may be used to confirm a key exchange between the system components in a way that requires the user to enter only small amounts of input data (e.g., keystrokes or mouse clicks). Security between components may be enhanced without having a negative impact on usability of the system. Embodiments of the present invention help to deter “man in the middle” attacks wherein an attacker gains control of a system component situated between certain communicating system components.

    Digital credential usage reporting
    38.
    发明申请
    Digital credential usage reporting 审中-公开
    数字凭证使用报告

    公开(公告)号:US20050198536A1

    公开(公告)日:2005-09-08

    申请号:US11122893

    申请日:2005-05-04

    IPC分类号: G06Q10/00 G06Q30/00 H04L9/00

    摘要: An credential verification service (CVS) authenticates digital credentials, such as, digital certificates, at the request of online service providers. The CVS stores the authentication results and transaction information in a central activity log. The transaction information can include a size of the transaction, the online service requesting the authentication, an internet protocol (IP) address of a computing device originating the transaction and the goods or services involved in the transaction. The CVS generates an activity report from the activity log that lists the authentication results and the transaction information. A fraud detection module within the CVS analyzes the activity log to identify any unusual patterns in order to identify fraudulent activities or general misuse of the digital credential.

    摘要翻译: 凭证验证服务(CVS)可以根据在线服务提供商的要求对数字证书(如数字证书)进行认证。 CVS将认证结果和交易信息存储在中央活动日志中。 交易信息可以包括交易的大小,请求认证的在线服务,发起交易的计算设备的因特网协议(IP)地址以及交易中涉及的商品或服务。 CVS从活动日志生成一个列出身份验证结果和交易信息的活动报告。 CVS中的欺诈检测模块分析活动日志以识别任何不寻常的模式,以识别欺诈活动或普遍滥用数字凭证。

    Direct anonymous attestation scheme with outsourcing capability
    40.
    发明授权
    Direct anonymous attestation scheme with outsourcing capability 有权
    具有外包能力的匿名认证方案

    公开(公告)号:US08874900B2

    公开(公告)日:2014-10-28

    申请号:US13398626

    申请日:2012-02-16

    IPC分类号: H04L9/32 H04L9/30

    摘要: A Direct Anonymous Attestation (DAA) scheme using elliptic curve cryptography (ECC) and bilinear maps. A trusted platform module (TPM) may maintain privacy of a portion of a private membership key from an issuer while joining a group. Moreover, the TPM can outsource most of the computation involved in generating a signature to a host computer.

    摘要翻译: 使用椭圆曲线加密(ECC)和双线性映射的直接匿名证明(DAA)方案。 可信平台模块(TPM)可以在加入组时从发行商维护私有成员密钥的一部分的隐私。 此外,TPM可以将生成签名所涉及的大部分计算外包给主机。