发明名称 PARAMETERIZED HASH FUNCTIONS FOR ACCESS CONTROL
摘要 A method and apparatus for access control in a computer system are disclosed. A storage unit receives a block of data having an encrypted executable image and a signature component. A separation unit coupled to the storage unit separates the signature component from the encrypted executable image. A decryption unit coupled to the separation unit decrypts the encrypted executable image using the signature component as a key. This yields a decrypted executable program. An identification unit coupled to the decryption unit locates an identification mark in the decrypted executable program and identifies a composite key assigned to the identification mark. A signature generation unit coupled to the identification unit performs a keyed cryptographic hash algorithm on the decrypted executable program using the composite key as a key. A verification unit coupled to the signature generation unit compares the signature component with the computed keyed cryptographic hash value to verify the source of the block of data and to determine whether it has been modified. If the signature matches the keyed cryptographic hash value, a rights assignment unit coupled to the verification unit assigns appropriate access rights to the decrypted executable program and allows it to be executed by a computer system.
申请公布号 WO9707657(A2) 申请公布日期 1997.03.06
申请号 WO1996US11925 申请日期 1996.07.19
申请人 INTEL CORPORATION;AUCSMITH, DAVID, W.;KNAUERHASE, ROBERT, C. 发明人 AUCSMITH, DAVID, W.;KNAUERHASE, ROBERT, C.
分类号 G06F21/22;G06F1/00;G06F21/00;G09C1/00;H04L9/32 主分类号 G06F21/22
代理机构 代理人
主权项
地址