发明名称 Key certification in one round trip
摘要 Certification of a key, which a Trusted Platform Module (TPM) has attested as being non-migratable, can be performed in a single round trip between the certificate authority (CA) and the client that requests the certificate. The client creates a certificate request, and then has the TPM create an attestation identity key (AIK) that is bound to the certificate request. The client then asks the TPM to sign the new key as an attestation of non-migratability. The client then sends the certificate request, along with the attestation of non-migratability to the CA. The CA examines the certificate request and attestation of non-migratability. However, since the CA does not know whether the attestation has been made by a trusted TPM, it certifies the key but includes, in the certificate, an encrypted signature that can only be decrypted using the endorsement key of the trusted TPM.
申请公布号 US8700893(B2) 申请公布日期 2014.04.15
申请号 US20090607937 申请日期 2009.10.28
申请人 THOM STEFAN;ANDERSON SCOTT D.;HOLT ERIK L.;MICROSOFT CORPORATION 发明人 THOM STEFAN;ANDERSON SCOTT D.;HOLT ERIK L.
分类号 H04L9/00;H04L9/32 主分类号 H04L9/00
代理机构 代理人
主权项
地址