发明名称 Method and apparatus for providing public key security control for a cryptographic processor
摘要 Public key security control (PKSC) is provided for a cryptographic module by means of digitally signed communications between the module and one or authorities with whom it interacts. Authorities interact with the crypto module by means of unsigned queries seeking nonsecret information or signed commands for performing specified operations. Each command signed by an authority also contains a transaction sequence number (TSN), which must match a corresponding number stored by the crypto module for the authority. The TSN for each authority is initially generated randomly and is incremented for each command accepted from that authority. A signature requirement array (SRA) controls the number of signatures required to validate each command type. Upon receiving a signed command from one or more authorities, the SRA is examined to determine whether a required number of authorities permitted to sign the command have signed the command for each signature requirement specification defined for that command type. A command requiring multiple signatures is held in a pending command register (PCR) while awaiting the required cosignatures. The crypto module also stores a single crypto module signature sequence number (CMSSN) which it increments for each reply to any authority to enable one authority to determine whether any other authority has communicated with the module.
申请公布号 US6339824(B1) 申请公布日期 2002.01.15
申请号 US19970884724 申请日期 1997.06.30
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 SMITH, SR. RONALD M.;D'AVIGNON EDWARD J.;DEBELLIS ROBERT S.;EASTER RANDALL J.;GREEN LUCINA L.;KELLY MICHAEL J.;MERZ WILLIAM A.;SPANO VINCENT A.;YEH PHIL CHI-CHUNG
分类号 G06F21/00;H04L9/30;(IPC1-7):H04L9/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址