VOTING AS LAST RESORT ACCESS RECOVERY FOR COMMON IDENTITY AND ACCESS MANAGEMENT

    公开(公告)号:US20240171589A1

    公开(公告)日:2024-05-23

    申请号:US18057287

    申请日:2022-11-21

    IPC分类号: H04L9/40

    摘要: Reinstating access to a system of an admin whose certificate is invalid or expired is disclosed. When the admin's certificate is expired, the admin may send a request for reinstatement to tenant admins. One of the tenant admins, if satisfied as to the admin's identity, can invoke a voting operation that allows the tenant admins to vote on whether to reinstate the admin. If the vote is successful, one of the tenant admins is given temporary privileges or permissions to install the admin's new certificate, after which the admin is reinstated and has access to the system.

    PLUGGABLE TRUSTED PLATFORM MODULE REMOTE ATTESTATION

    公开(公告)号:US20240163282A1

    公开(公告)日:2024-05-16

    申请号:US18508313

    申请日:2023-11-14

    发明人: Cheng-Ming Chien

    IPC分类号: H04L9/40 G06F21/10

    摘要: A computer system may receive, from a second electronic device, provisioning information for the electronic device and may confirm a license associated with the electronic device based at least in part on the provisioning information. Moreover, the computer system may receive, from the electronic device, confirmation information and may perform a join flow with the electronic device based at least in part on the confirmation information. Then, the computer system may provide, to the electronic device, authorization information. When the electronic device includes an instance of a trusted platform module (TPM) chip, prior to performing the join flow, the computer system may: provide, to the electronic device, an attestor identity key (AIK) certificate; perform remote attestation with the electronic device based at least in part on the AIK certificate; and verify the electronic device based at least in part on a result of the remote attestation.

    CREDENTIAL DEPENDENCY ENCODING AND VERIFICATION BASED ON OTHER CREDENTIAL RESOURCES

    公开(公告)号:US20240163274A1

    公开(公告)日:2024-05-16

    申请号:US18541973

    申请日:2023-12-15

    申请人: Intel Corporation

    发明人: Ned M. Smith

    IPC分类号: H04L9/40 H04L67/142

    摘要: Various systems and methods of establishing and providing credential dependency information in RESTful transactions are described. In an example, accessing credential resource dependencies may be performed by a credential management service (CMS) or other server, with operations including: receiving a request for a credential resource in a Representation State Transfer (RESTful) communication; identifying the credential resource which has a credential path that indicates a dependency associated with a credential; identifying dependency characteristics of the credential resource, based on the dependency; populating the credential resource to include a dependent credential, based on the dependency characteristics; and transmitting the populated credential resource in response to the request. In further examples, the credential resource and the credential path within the credential resource may be established, such as by defining paths to trust anchor entries, or dependencies to a trusted computing key of a trusted computing module that attests to trust properties.