发明名称 Policy for secure packet transmission using required node paths and cryptographic signatures
摘要 Techniques (400, 600, 700) and apparatuses (102, 106, 108, 800) are described that enable a policy for secure packet transmission using required node paths and cryptographic signatures. These techniques and apparatuses enable a secure execution environment (SEE) of a target device to receive trustworthy sensitive data.
申请公布号 US9053332(B2) 申请公布日期 2015.06.09
申请号 US201313786980 申请日期 2013.03.06
申请人 GOOGLE TECHNOLOGY HOLDINGS LLC 发明人 Nakhijiri Madjid F.
分类号 G06F17/00;G06F21/60;H04L9/32;H04L29/06;H04L12/721 主分类号 G06F17/00
代理机构 Fox Rothschild LLP 代理人 Fox Rothschild LLP
主权项 1. A method for providing end-to-end security for transport of a sensitive packet to a target device through an infrastructure based on a policy, the method comprising: receiving the policy, the policy enforcing at least one of a transport, an installation, or a consumption of the sensitive packet by the target device or a node of the infrastructure through which the sensitive packet is intended to be transported; appending the policy as data fields of the sensitive packet prior to transport of the sensitive packet, wherein the sensitive packed is encrypted for end-to-end confidentiality protection between the target device and an initial node of the infrastructure through which the sensitive packet is initially transported; cryptographically signing the sensitive packet; and causing the sensitive packet to be transmitted to the target device through at least the node of the infrastructure, wherein the sensitive packet is encrypted for end-to-end confidentiality protection between the target device and an initial node of the infrastructure through which the sensitive packet is initially transported and the encryption for end-to-end confidentiality protection is an end-to-end inner layer encryption and is performed prior to a hop-by-hop encryption.
地址 Mountain View CA US