发明名称 Method of using signatures for measurement in a trusted computing environment
摘要 Verification of an encrypted blob of data passed to a sealed storage function in a trusted platform module (TPM) of a computing platform by a software component, may be accomplished by receiving the encrypted blob of data and a digital signature for each of a set of platform configuration register (PCR) indicators and PCR value pairs from the software component. The encrypted blob of data may be decrypted using a TPM key to form a decrypted blob of data, the decrypted blob of data including a secret and a verification key. For each received digital signature of the set of PCR identifier and PCR value pairs, it may be determined if each received digital signature verifies using the verification key and rejecting the decrypted blob of data when any signature is not verified. For each received digital signature of the set of PCR identifier and a PCR value pairs, it may be determined if each received PCR value matches a current value stored in a corresponding PCR in the TPM and rejecting the decrypted blob of data when any corresponding pair of PCR values do not match. The secret may be output from the decrypted blob of data when the decrypted blob of data has not been rejected.
申请公布号 US8631507(B2) 申请公布日期 2014.01.14
申请号 US20060390920 申请日期 2006.03.27
申请人 BRICKELL ERNIE F.;INTEL CORPORATION 发明人 BRICKELL ERNIE F.
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址