US2003105965A1PendingUtilityA1

Business method for secure installation of a credit authorization key on a remote tcpa compliant system

Assignee: IBMPriority: May 9, 2001Filed: Feb 19, 2003Published: Jun 5, 2003
Est. expiryMay 9, 2021(expired)· nominal 20-yr term from priority
G06Q 40/03G06Q 20/38215G06Q 20/3558G06Q 20/10G06Q 20/3821G06Q 20/105G07F 7/1008G06Q 20/3552G06Q 20/24G06Q 20/342G07F 7/025G06Q 40/04G06Q 30/0609G06Q 20/12G06Q 20/102G07F 7/1016
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Abstract of the Disclosure A business method employing hardware complaint to the Trusted Computing Platform Alliance (TCPA) Specification is implemented to allow a credit card company to remotely install a credit card private key into a TCPA module to create a Trusted Platform Module (TPM). More specifically, when a credit worthy user applies for a credit card, the user will send the credit card company a public portion of a "non-migratable storage key," which is accredited a TPM endorsed by a Certification Authority. The credit card company will create its own public/private key pair according to the TCPA Specification, to create a TCPA header, and wrap the full structure by encrypting it with the public portion of the TCPA non-migratable storage key. The credit card company then sends by email the encrypted bundle with a certificate for it, and sends a corresponding pass phrase by regular mail.

Claims

exact text as granted — not AI-modified
What is Claimed is: 
     
       A business method comprising the steps of:
    1.  (a)  receiving a request for a private key over a first network and from a remote device
having a TPM (Trusted Platform Module) associated with an end user entity; 
      (b)  verifying the worthiness of the received request as represented by a TPM identity
of the remote device;  
      (c)  requesting and receiving over the first network a non-migratable storage key from
the TPM of the remote device when the received request is deemed worthy as determined
by said verifying step (b); 
      (d)  receiving a certificate from a Certificate Authority which certifies the non-migratable storage key as both secure and non-migratable; and 
      (e)  wrapping an encrypted private key with the non-migratable storage key as per the
TCPA specification, and sending the encrypted private key  to the remote device over the
first network. 
 
     
     
         2.  The method of claim 1  further
comprising the step of sending over a second network a pass code which facilitates the decryption
of the encrypted private key, wherein the second network is a network selected from the group
consisting of a network which is physically different than the first network, a network which is
logically different than the first network, and a network which is physically and logically different
than the first network. 
     
     
         3.  The method of claim 1  further
comprising the step of sending over regular mail a pass code which facilitates the decryption of
the encrypted private key. 
     
     
       A business method comprising the steps of:
   4.  (a)  receiving a request for a private key over a first network and from a remote device
having a TPM (Trusted Platform Module) associated with an end user entity; 
      (b)  verifying the worthiness of the received request as represented by a TPM identity
of the remote device;  
      (c)  requesting and receiving over the first network a non-migratable storage key from
the TPM of the remote device when the received request is deemed worthy as determined
by said verifying step (b); 
      (d)  receiving a certificate from a TPM identity certifying the non-migratable storage
key as both secure and non-migratable, and further receiving a certificate from a
Certificate Authority certifying that the TPM identity is a TPM identity; and 
      (e)  wrapping an encrypted private key with the non-migratable storage key as per the
TCPA specification, and sending the encrypted private key  to the remote device over the
first network. 
 
     
     
         5.  The method of claim 4  further
comprising the step of sending over a second network a pass code which facilitates the decryption
of the encrypted private key, wherein the second network is a network selected from the group
consisting of a network which is physically different than the first network, a network which is
logically different than the first network, and a network which is physically and logically different
than the first network. 
     
     
         6.  The method of claim 4  further
comprising the step of sending over regular mail a pass code which facilitates the decryption of
the encrypted private key. 
     
     
       A business method comprising the steps of:
    7.  (a)  receiving a request for a private key over a first network and from a remote device
having a TPM (Trusted Platform Module) associated with an end user entity; 
      (b)  verifying the worthiness of the received request as represented by a TPM identity
of the remote device;  
      (c)  requesting and receiving over the first network a non-migratable storage key from
the TPM of the remote device when the received request is deemed worthy as determined
by said verifying step (b); 
      (d)  receiving an endorsement key certificate from a Certificate Authority, and further
receiving a certificate from a TPM identity certifying the non-migratable storage key as
both secure and non-migratable, and further receiving a certificate from a Certificate
Authority certifying that the TPM identity is a TPM identity;  
      (e) originating a certificate for the TPM identity and encrypting the certificate as per
the TCPA specification and sending the encrypted certificate to the remote device wherein
the encryption is based on the endorsement key certificate;  
      (f)  receiving a decrypted identity certificate which is decrypted by the remote device
when the TPM identity certificate as originated in said originating step (e) matches the
TPM identity of the remote device; and 
      (g)  wrapping an encrypted private key with the non-migratable storage key as per the
TCPA specification, and sending the encrypted private key  to the remote device over the
first network. 
 
     
     
         8.  The method of claim 7  further
comprising the step of sending over a second network a pass code which facilitates the decryption
of the encrypted private key, wherein the second network is a network selected from the group
consisting of a network which is physically different than the first network, a network which is
logically different than the first network, and a network which is physically and logically different
than the first network. 
     
     
         9.  The method of claim 7  further
comprising the step of sending over regular mail a pass code which facilitates the decryption of
the encrypted private key. 
     
     
       A program product comprising:
 a computer usable medium having computer readable program code embodied therein, the
computer readable program code in said program product being effective in executing the steps
of:     10.  (a)  receiving a request for a private key over a first network and from a remote device
having a TPM (Trusted Platform Module) associated with an end user entity; 
      (b)  verifying the worthiness of the received request as represented by a TPM identity
of the remote device;  
      (c)  requesting and receiving over the first network a non-migratable storage key from
the TPM of the remote device when the received request is deemed worthy as determined
by said verifying step (b); 
      (d)  receiving a certificate from a Certificate Authority which certifies the non-migratable storage key as both secure and non-migratable; and 
      (e)  wrapping an encrypted private key with the non-migratable storage key as per the
TCPA specification, and sending the encrypted private key  to the remote device over the
first network. 
 
     
     
         11.  The program product of claim 10 
further comprising the step of sending over a second network a pass code which facilitates the
decryption of the encrypted private key, wherein the second network is a network selected from
the group consisting of a network which is physically different than the first network, a network
which is logically different than the first network, and a network which is physically and logically
different than the first network. 
     
     
         12.  The program product of claim 10 
further comprising the step of sending over regular mail a pass code which facilitates the
decryption of the encrypted private key. 
     
     
       A program product comprising:
 a computer usable medium having computer readable program code embodied therein, the
computer readable program code in said program product being effective in executing the steps
of: 
    13.  (a)  receiving a request for a private key over a first network and from a remote device
having a TPM (Trusted Platform Module) associated with an end user entity; 
      (b)  verifying the worthiness of the received request as represented by a TPM identity
of the remote device;  
      (c)  requesting and receiving over the first network a non-migratable storage key from
the TPM of the remote device when the received request is deemed worthy as determined
by said verifying step (b); 
      (d)  receiving a certificate from a TPM identity certifying the non-migratable storage
key as both secure and non-migratable, and further receiving a certificate from a
Certificate Authority certifying that the TPM identity is a TPM identity; and 
      (e)  wrapping an encrypted private key with the non-migratable storage key as per the
TCPA specification, and sending the encrypted private key  to the remote device over the
first network. 
 
     
     
         14.  The program product of claim 13 
further comprising the step of sending over a second network a pass code which facilitates the
decryption of the encrypted private key, wherein the second network is a network selected from
the group consisting of a network which is physically different than the first network, a network
which is logically different than the first network, and a network which is physically and logically
different than the first network. 
     
     
         15.  The program product of claim 13 
further comprising the step of sending over regular mail a pass code which facilitates the
decryption of the encrypted private key. 
     
     
       A program product comprising:
 a computer usable medium having computer readable program code embodied therein, the
computer readable program code in said program product being effective in executing the steps
of: 
    16.  (a)  receiving a request for a private key over a first network and from a remote device
having a TPM (Trusted Platform Module) associated with an end user entity; 
      (b)  verifying the worthiness of the received request as represented by a TPM identity
of the remote device;   
      (c)  requesting and receiving over the first network a non-migratable storage key from
the TPM of the remote device when the received request is deemed worthy as determined
by said verifying step (b); 
      (d)  receiving an endorsement key certificate from a Certificate Authority, and further
receiving a certificate from a TPM identity certifying the non-migratable storage key as
both secure and non-migratable, and further receiving a certificate from a Certificate
Authority certifying that the TPM identity is a TPM identity;  
      (e) originating a certificate for the TPM identity and encrypting the certificate as per
the TCPA specification and sending the encrypted certificate to the remote device wherein
the encryption is based on the endorsement key certificate;  
      (f)  receiving a decrypted identity certificate which is decrypted by the remote device
when the TPM identity certificate as originated in said originating step (e) matches the
TPM identity of the remote device; and 
      (g)  wrapping an encrypted private key with the non-migratable storage key as per the
TCPA specification, and sending the encrypted private key  to the remote device over the
first network. 
 
     
     
         17.  The program product of claim 16 
further comprising the step of sending over a second network a pass code which facilitates the
decryption of the encrypted private key, wherein the second network is a network selected from
the group consisting of a network which is physically different than the first network, a network
which is logically different than the first network, and a network which is physically and logically
different than the first network. 
     
     
         18.  The program product of claim 16 
further comprising the step of sending over regular mail a pass code which facilitates the
decryption of the encrypted private key.

Join the waitlist — get patent alerts

Track US2003105965A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.