发明名称 System and method for distributed security
摘要 A security architecture in which a security module is integrated in a client machine, wherein the client machine includes a local host that is untrusted. The security module performs encryption and decryption algorithms, authentication, and public key processing. The security module also includes separate key caches for key encryption keys and application keys. A security module can also interface a cryptographic accelerator through an application key cache. The security module can authorize a public key and an associated key server. That public key can subsequently be used to authorize additional key servers. Any of the authorized key servers can use their public keys to authorize the public keys of additional key servers. Secure authenticated communications can then transpire between the client and any of these key servers. Such a connection is created by a secure handshake process that takes place between the client and the key server. A time value can be sent from the key server to the client, allowing for secure revocation of keys. In addition, secure configuration messages can be sent to the security module.
申请公布号 US9264223(B2) 申请公布日期 2016.02.16
申请号 US201414263844 申请日期 2014.04.28
申请人 BROADCOM INC. 发明人 Buer Mark
分类号 H04L29/06;H04L9/08;G06Q20/36;H04L9/32 主分类号 H04L29/06
代理机构 Sterne, Kessler, Goldstein & Fox P.L.L.C. 代理人 Sterne, Kessler, Goldstein & Fox P.L.L.C.
主权项 1. A client device configured to create a hierarchy of key servers, the client device comprising: a local host configured to transfer a first public key associated with a first key server, wherein the first public key is configured to expire after a predetermined period of time; and a security module configured to: determine that the first key server is authorized by comparing information stored in the security module with a hash value of the first public key,determine whether the first key server is permitted to authorize additional key servers, andsign a second public key of a second key server with the first public key to authorize the second key server in response to determining that the first key server is permitted to authorize additional key servers.
地址 Irvine CA US