发明名称 Method for securely creating an endorsement certificate in an insecure environment
摘要 A Method and system for ensuring security-compliant creation and signing of endorsement keys of manufactured trusted platform modules. The endorsement keys are generated for the trusted platform module (TPM). The TPM vendor selects an N-byte secret and stores the N-type secret in the trusted platform module along with the endorsement keys. The secret number cannot be read outside of the trusted platform module. The secret number is also provided to the credential server of the original equipment manufacturer. During the endorsement key (EK) credential process, the trusted platform module generates an endorsement key, which comprises both the public key and a hash of the secret and the public key. The credential server matches the hash within the endorsement key withy a second hash of the received public key (from the endorsement key) and the vendor provided secret. The EK certificate is generated and inserted into the trusted platform module only when a match is confirmed.
申请公布号 US7644278(B2) 申请公布日期 2010.01.05
申请号 US20030750594 申请日期 2003.12.31
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 CATHERMAN RYAN CHARLES;CHALLENER DAVID CARROLL;HOFF JAMES PATRICK
分类号 H04L9/32;G06F21/00;H04L9/00 主分类号 H04L9/32
代理机构 代理人
主权项
地址