发明名称 METHOD FOR NOTARIZING PACKET TRACES
摘要 A system and method for capturing non-forgeable packet traces. Upon start-up of a sniffer, a first quote of Platform Configuration Register (PCR) values in a Trusted Platform Module (TPM) utilized by the sniffer is obtained, wherein the first quote comprises a list of starting values in the PCRs and is signed by the TPM and stored in a packet log. When a packet of interest is intercepted by the sniffer, the sniffer obtains a hash of the packet and instructs the TPM to extend a PCR with the hash value. The packet of interest is then stored in the packet log. When the sniffer is shutdown, a second quote of values in the PCRs is obtained, wherein the second quote comprises a list of current values in the PCRs, and wherein the second quote is signed by the TPM and stored in the packet log.
申请公布号 US2008098107(A1) 申请公布日期 2008.04.24
申请号 US20060550462 申请日期 2006.10.18
申请人 JONES DANIEL HORACIO;LENDACKY THOMAS GIRARD;RATLIFF EMILY JANE 发明人 JONES DANIEL HORACIO;LENDACKY THOMAS GIRARD;RATLIFF EMILY JANE
分类号 G06F15/173 主分类号 G06F15/173
代理机构 代理人
主权项
地址