Systems and methods using cryptography to protect secure computing environments
Abstract
Secure computation environments are protected from bogus or rogue load modules, executables and other data elements through use of digital signatures, seals and certificates issued by a verifying authority. A verifying authority—which may be a trusted independent third party—tests the load modules or other executables to verify that their corresponding specifications are accurate and complete, and then digitally signs the load module or other executable based on tamper resistance work factor classification. Secure computation environments with different tamper resistance work factors use different verification digital signature authentication techniques (e.g., different signature algorithms and/or signature verification keys)—allowing one tamper resistance work factor environment to protect itself against load modules from another, different tamper resistance work factor environment. Several dissimilar digital signature algorithms may be used to reduce vulnerability from algorithm compromise, and subsets of multiple digital signatures may be used to reduce the scope of any specific compromise.
Claims
exact text as granted — not AI-modified1 . A computer-readable medium comprising program code, the program code being operable, when executed by an electronic appliance comprising a protected processing environment that is resistant to tampering by users of the electronic appliance, to cause the electronic appliance to perform steps comprising:
receiving a first digital signature associated with a load module; receiving a second digital signature associated with the load module; authenticating the first digital signature using a first key; and conditionally executing the load module based at least in part on a result of the authenticating step.
2 . The computer-readable medium of claim 1 , in which the first digital signature is associated with a first part of the load module, and the second digital signature is associated with a second, different, part of the load module, the computer-readable medium further including program code that is operable, when executed by the electronic appliance, to cause the electronic appliance to perform the step of:
authenticating the second digital signature.
3 . The computer-readable medium of claim 1 , further including program code that is operable, when executed by the electronic appliance, to cause the electronic appliance to perform steps comprising:
after performing the conditionally executing step, authenticating the second digital signature; and conditionally executing the load module based, at least in part, on a result of the step of authenticating the second digital signature.
4 . The computer-readable medium of claim 3 , in which the first digital signature is associated with a first part of the load module, and the second digital signature is associated with a second, different, part of the load module.
5 . The computer-readable medium of claim 1 , further including program code that is operable, when executed by the electronic appliance, to cause the electronic appliance to perform the step of:
randomly selecting the first digital signature for authentication from a set of digital signatures comprising at least the first digital signature and the second digital signature.
6 . The computer-readable medium of claim 3 , further including program code that is operable, when executed by the electronic appliance, to cause the electronic appliance to perform the step of:
randomly selecting the second digital signature for authentication from a set of digital signatures comprising at least the first digital signature and the second digital signature.
7 . The computer-readable medium of claim 1 , in which the first digital signature is generated by a first entity and the second digital signature is generated by a second entity that is different from the first entity, the computer readable medium further including program code that is operable, when executed by the electronic appliance, to cause the electronic appliance to perform the step of:
authenticating the second digital signature.
8 . The computer-readable medium of claim 1 , further including program code that is operable, when executed by the electronic appliance, to cause the electronic appliance to perform steps comprising:
securely receiving the first key, the first key comprising a public key of a first entity; and securely receiving a public key of a second entity, the public key of the second entity being configured for use in authenticating the second digital signature.
9 . The computer-readable medium of claim 1 , further including program code that is operable, when executed by the electronic appliance, to cause the electronic appliance to perform the step of:
authenticating the second digital signature.
10 . The computer-readable medium of claim 1 , further including program code that is operable, when executed by the electronic appliance, to cause the electronic appliance to perform the step of:
distributing the load module to a second electronic appliance.
11 . The computer-readable medium of claim 1 , further including the load module, the load module being operable, when executed by the electronic appliance, to cause the electronic appliance to perform at least one action selected from the group consisting of:
recording an aspect of usage of a piece of electronic content, preventing a user of the electronic appliance from making a copy of a piece of electronic content, charging a user of the electronic appliance a fee for viewing a piece of electronic content, enabling the electronic appliance to playa piece of electronic content, and enabling the electronic appliance to perform a financial transaction.
12 . A system comprising:
an electronic appliance comprising a protected processing environment; means for receiving a first digital signature associated with a load module; means for receiving a second digital signature associated with the load module; means for authenticating the first digital signature using a first key; and means for conditionally executing the load module based at least in part on a result generated by the means for authenticating the first digital signature; wherein the protected processing environment is operable to impede tampering by a user of the electronic appliance with at least the means for authenticating the first digital signature and the means for conditionally executing the load module.
13 . The system of claim 12 , in which the protected processing environment is operable to maintain the first key as a secret from the user of the electronic appliance.
14 . The system of claim 13 , in which the first key comprises a public key.
15 . The system of claim 12 , in which the first digital signature is associated with a first part of the load module, and the second digital signature is associated with a second, different, part of the load module, the system further comprising:
means for authenticating the second digital signature; wherein the means for conditionally executing the load module comprises means for conditionally executing the load module based at least in part on a result generated by the means for authenticating the second digital signature.
16 . The system of claim 15 , in which the means for authenticating the second digital signature is configured to make use of a second key that is different from the first key.
17 . The system of claim 12 , further comprising:
means for authenticating the second digital signature after executing the load module at least a first time; and means for conditionally executing the load module at least a second time based, at least in part, on a result generated by the means for authenticating the second digital signature.
18 . The system of claim 17 , in which the first digital signature is associated with a first part of the load module, and the second digital signature is associated with a second, different, part of the load module.
19 . The system of claim 12 , further comprising:
means for randomly selecting the first digital signature for authentication from a set of digital signatures comprising at least the first digital signature and the second digital signature.
20 . The system of claim 17 , further comprising:
means for randomly selecting the second digital signature for authentication from a set of digital signatures comprising at least the first digital signature and the second digital signature.
21 - 25 . (canceled)Join the waitlist — get patent alerts
Track US2008114698A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.