System and method for protecting against dictionary attacks on password-protected TPM keys
    2.
    发明申请
    System and method for protecting against dictionary attacks on password-protected TPM keys 审中-公开
    防止对密码保护的TPM密钥的字典攻击的系统和方法

    公开(公告)号:US20070014416A1

    公开(公告)日:2007-01-18

    申请号:US11183116

    申请日:2005-07-15

    IPC分类号: H04L9/00

    摘要: A computer system that may include a trusted platform module (TPM) along with a processor hashes a user-supplied password for a predetermined time period that is selected to render infeasible a dictionary attack on the password. The results of the hash are used to render an AES key, which is used to encrypt an RSA key. The encrypted RSA key along with the total number of hash cycles that were used is stored and the RSA key is provided to the TPM as a security key. In the event that the RSA key in the TPM must be recovered, the encrypted stored version is decrypted with an AES key that is generated based on the user inputting the same password and hashing the password for the stored number of cycles.

    摘要翻译: 可以包括可信平台模块(TPM)以及处理器的计算机系统将用户提供的密码散列在预定时间段内,该预定时间段被选择为对密码进行字典攻击不可行。 哈希的结果用于渲染AES密钥,用于加密RSA密钥。 存储加密的RSA密钥以及所使用的散列周期的总数,并将RSA密钥作为安全密钥提供给TPM。 在必须恢复TPM中的RSA密钥的情况下,加密的存储版本将使用基于用户输入相同密码生成的AES密钥解密,并对存储的周期数进行散列密码。

    System and method for providing endorsement certificate
    4.
    发明申请
    System and method for providing endorsement certificate 有权
    提供认可证书的制度和方法

    公开(公告)号:US20050132182A1

    公开(公告)日:2005-06-16

    申请号:US10735388

    申请日:2003-12-12

    IPC分类号: G06F21/00 H04L9/00

    CPC分类号: G06F21/57 G06F2221/2117

    摘要: A Trusted Computing Platform Alliance (TCPA) endorsement certificate is provided by comparing a trusted platform module (TPM) public key transmitted by an owner of the computing device to which the TPM belongs to a copy of the key as originally stored in a remote database prior to vending the device. If a match is found the certificate is created using the public key, and then sent to the owner of the computing device.

    摘要翻译: 通过将由TPM所属的计算设备的所有者发送的可信平台模块(TPM)公钥与原始存储在远程数据库中的密钥的副本进行比较来提供可信计算平台联盟(TCPA)认可证书 自动售货机。 如果发现匹配,则使用公钥创建证书,然后发送给计算设备的所有者。

    Backup restore in a corporate infrastructure
    5.
    发明申请
    Backup restore in a corporate infrastructure 有权
    企业基础架构中的备份还原

    公开(公告)号:US20060230264A1

    公开(公告)日:2006-10-12

    申请号:US11101290

    申请日:2005-04-07

    IPC分类号: H04L9/00

    摘要: A method and system for remotely storing a user's admin key to gain access to an intranet is presented. The user's admin key and intranet user identification (ID) are encrypted using an enterprise's public key, and together they are concatenated into a single backup admin file, which is stored in the user's client computer. If the user needs his admin file and is unable to access it in a backup client computer, he sends the encrypted backup admin file to a backup server and his unencrypted intranet user ID to an intranet authentication server. The backup server decrypts the user's single backup admin file to obtain the user's admin key and intranet user ID. If the unencrypted intranet user ID in the authentication server matches the decrypted intranet user ID in the backup server, then the backup server sends the backup client computer the decrypted admin key.

    摘要翻译: 介绍一种用于远程存储用户管理密钥以访问内联网的方法和系统。 用户的管理密钥和内部网用户标识(ID)使用企业的公钥进行加密,并将它们并入一个备份管理文件,该文件存储在用户的客户端计算机中。 如果用户需要他的管理员文件,并且无法在备份客户端计算机中访问它,则他将加密的备份管理文件发送到备份服务器,并将其未加密的内部网用户ID发送到内部网认证服务器。 备份服务器解密用户的单备份管理文件,获取用户的管理密钥和内部网用户ID。 如果身份验证服务器中未加密的Intranet用户ID与备份服务器中的解密内网用户ID匹配,则备份服务器将备份客户端计算机发送解密的管理密钥。

    Method for securely creating an endorsement certificate in an insecure environment
    6.
    发明申请
    Method for securely creating an endorsement certificate in an insecure environment 失效
    在不安全的环境中安全地创建背书证书的方法

    公开(公告)号:US20050144440A1

    公开(公告)日:2005-06-30

    申请号:US10750594

    申请日:2003-12-31

    IPC分类号: G06F21/00 H04L9/00

    摘要: A method and system for ensuring security-compliant creation and signing of endorsement keys of manufactured TPMs. The endorsement keys are generated for the TPM. The TPM vendor selects an N-byte secret and stores the N-byte secret in the TPM along with the endorsement keys. The secret number cannot be read outside of the TPM. The secret number is also provided to the OEM's credential server. During the endorsement key (EK) credential process, the TPM generates an endorsement key, which comprises both the public key and a hash of the secret and the public key. The credential server matches the hash within the endorsement key with a second hash of the received public key (from the endorsement key) and the vendor provided secret. The EK certificate is generated and inserted into the TPM only when a match is confirmed.

    摘要翻译: 一种用于确保制造TPM的签注密钥的安全兼容创建和签名的方法和系统。 为TPM生成认可密钥。 TPM供应商选择一个N字节的秘密,并将N字节的秘密与支持密钥一起存储在TPM中。 无法在TPM之外读取密码。 秘密编号也提供给OEM的凭据服务器。 在认可密钥(EK)凭证处理过程中,TPM产生一个签名密钥,其包括公开密钥和密钥的散列以及公开密钥。 凭证服务器将签名密钥内的散列与接收到的公钥(来自认可密钥)和供应商提供的秘密的第二散列进行匹配。 仅当匹配确认时,EK证书才会生成并插入到TPM中。

    Method for Securely Creating an Endorsement Certificate in an Insecure Environment
    7.
    发明申请
    Method for Securely Creating an Endorsement Certificate in an Insecure Environment 有权
    在不安全的环境中安全地创建认可证书的方法

    公开(公告)号:US20080069363A1

    公开(公告)日:2008-03-20

    申请号:US11858977

    申请日:2007-09-21

    IPC分类号: H04L9/08 H04L9/28 H04L9/30

    摘要: A method and system for ensuring security-compliant creation and signing of endorsement keys of manufactured TPMs. The endorsement keys are generated for the TPM. The TPM vendor selects an N-byte secret and stores the N-byte secret in the TPM along with the endorsement keys. The secret number cannot be read outside of the TPM. The secret number is also provided to the OEM's credential server. During the endorsement key (EK) credential process, the TPM generates an endorsement key, which comprises both the public key and a hash of the secret and the public key. The credential server matches the hash within the endorsement key with a second hash of the received public key (from the endorsement key) and the vendor provided secret. The EK certificate is generated and inserted into the TPM only when a match is confirmed.

    摘要翻译: 一种用于确保制造TPM的签注密钥的安全兼容创建和签名的方法和系统。 为TPM生成认可密钥。 TPM供应商选择一个N字节的秘密,并将N字节的秘密与支持密钥一起存储在TPM中。 无法在TPM之外读取密码。 秘密编号也提供给OEM的凭据服务器。 在认可密钥(EK)凭证处理过程中,TPM产生一个签名密钥,其包括公开密钥和密钥的散列以及公开密钥。 凭证服务器将签名密钥内的散列与接收到的公钥(来自认可密钥)和供应商提供的秘密的第二散列进行匹配。 仅当匹配确认时,EK证书才会生成并插入到TPM中。

    Method for securely creating an endorsement certificate utilizing signing key pairs
    8.
    发明申请
    Method for securely creating an endorsement certificate utilizing signing key pairs 失效
    使用签名密钥对安全地创建签注证书的方法

    公开(公告)号:US20050149733A1

    公开(公告)日:2005-07-07

    申请号:US10749261

    申请日:2003-12-31

    IPC分类号: G06F21/00 H04L9/00

    CPC分类号: G06F21/602 G06F21/57

    摘要: A method and system for ensuring security-compliant creation and certificate generation for endorsement keys of manufactured TPMs. The endorsement keys are generated by the TPM manufacturer and stored within the TPM. The TPM manufacturer also creates a signing key pair and associated signing key certificate. The signing key pair is also stored within the TPM, while the certificate is provided to the OEM's credential server. During the endorsement key (EK) credential process, the TPM generates a signed endorsement key, which comprises the public endorsement key signed with the public signing key. The credential server matches the public signing key of the endorsement key with a public signing key within the received certificate. The EK certificate is generated and inserted into the TPM only when a match is confirmed.

    摘要翻译: 一种用于确保制造TPM的认可密钥的安全兼容创建和证书生成的方法和系统。 认可密钥由TPM制造商生成并存储在TPM内。 TPM制造商还创建了一个签名密钥对和相关的签名密钥证书。 签名密钥对也存储在TPM中,同时将证书提供给OEM的凭据服务器。 在认可密钥(EK)凭证过程中,TPM生成签名的背书密钥,其包括用公共签名密钥签名的公开签名密钥。 凭证服务器将签名密钥的公共签名密钥与接收到的证书中的公共签名密钥相匹配。 仅当匹配确认时,EK证书才会生成并插入到TPM中。

    Enabling attestation during return from S4 state with standard TCG hardware
    10.
    发明申请
    Enabling attestation during return from S4 state with standard TCG hardware 有权
    在使用标准TCG硬件从S4状态返回期间启用认证

    公开(公告)号:US20060085630A1

    公开(公告)日:2006-04-20

    申请号:US10967760

    申请日:2004-10-16

    IPC分类号: G06F9/24

    CPC分类号: G06F21/575

    摘要: A method and system for enabling security attestation for a computing device during a return from an S4 sleep state. When the computing device enters into the S4 state following a successful boot up, the attestation log is appended to the TPM tick count and the log is signed (with a security signature). When the device is awaken from S4 state, the BIOS obtains and verifies the log created during the previous boot. The CRTM maintains a set of virtual PCRs and references these virtual PCRs against the log. If the values do not match, the return from S4 state fails and the device is rebooted.

    摘要翻译: 一种用于在从S4睡眠状态返回期间为计算设备提供安全认证的方法和系统。 当计算设备在成功启动后进入S4状态时,认证日志会追加到TPM刻度计数,并且日志被签名(具有安全签名)。 当设备从S4状态唤醒时,BIOS将获取并验证在以前引导过程中创建的日志。 CRTM维护一组虚拟PCR,并将这些虚拟PCR引用到日志中。 如果值不匹配,则S4状态返回失败,设备重启。