发明名称 SOFTWARE SECURE AUTHENTICATED CHANNEL
摘要 Software manufacturers examine their module and determine a range of addresses in memory which the module occupies. A protected range of addresses in memory is predefined to not allow changes, such as patching by hackers. Each manufacturer delivers the range of addresses describing the protected area and a known good version of their module to other manufacturers that they want to interoperate with. The other manufacturers return digital signatures on the protected area, and these digital signatures are stored in the first manufacturer's module. Correspondingly, the other manufacturers do the same with their own modules. Then, in order to effect a secure communication channel between two modules the modules first pass each other the signatures previously produced. Then, to ensure that communication is being effected with an authentic authorized module, through the use of the signature and the address ranges in the protected area, each module checks that the other module has not been patched. They each further verify that all the entry points in the other module they intend to call are in fact within the protected area. In the event that both modules are verified as being trustworthy, the modules now call each other freely. However, each module, when it is called must verify that it was called from within the protected area of the other module.
申请公布号 KR100561497(B1) 申请公布日期 2006.03.17
申请号 KR20037003480 申请日期 2003.03.08
申请人 发明人
分类号 G06F15/00;G06F21/22;G06F1/00;G06F21/00;G06F21/44;G06F21/64 主分类号 G06F15/00
代理机构 代理人
主权项
地址