发明名称 Mechanisms to control access to cryptographic keys and to attest to the approved configurations of computer platforms
摘要 Methods and arrangements to control access to cryptographic keys and to attest to the approved configurations of computer platforms able to access these keys, which include trusted platform modules (TPMs) are contemplated. Embodiments include transformations, code, state machines or other logic to control access to a cryptographic key by creating an authorization blob locking authorization data to access the cryptographic key to platform configuration register (PCR) values of a TPM, the PCR values representing a configuration of a computing platform. Embodiments may also involve generating a first TPM cryptographic key bound to PCR values, receiving a second TPM cryptographic key owned by software, and receiving evidence of the identity of an upgrade service controlling the upgrading of the software. Embodiment may also include certifying the first TPM cryptographic key; certifying the second TPM cryptographic key; concatenating the first certification, the second certification, and the evidence of the identity of the upgrade service; and signing the concatenation.
申请公布号 US7711960(B2) 申请公布日期 2010.05.04
申请号 US20060511773 申请日期 2006.08.29
申请人 INTEL CORPORATION 发明人 SCARLATA VINCENT
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址