Systems and Methods Using Cryptography to Protect Secure Computing Environments
Abstract
Secure computation environments are protected from bogus or rogue load modules, executables and other data elements through use of digital signatures, seals and certificates issued by a verifying authority. A verifying authority—which may be a trusted independent third party—tests the load modules or other executables to verify that their corresponding specifications are accurate and complete, and then digitally signs the load module or other executable based on tamper resistance work factor classification. Secure computation environments with different tamper resistance work factors use different verification digital signature authentication techniques (e.g., different signature algorithms and/or signature verification keys)—allowing one tamper resistance work factor environment to protect itself against load modules from another, different tamper resistance work factor environment. Several dissimilar digital signature algorithms may be used to reduce vulnerability from algorithm compromise, and subsets of multiple digital signatures may be used to reduce the scope of any specific compromise.
Claims
exact text as granted — not AI-modified1 . A method comprising:
associating a first digital certificate with a first piece of software, the first digital certificate designating the first piece of software for use in a first class of computing environments; associating a second digital certificate with a second piece of software, the second digital certificate designating the second piece of software for use in a second class of computing environments having a security level that is higher than that of a security level of the first class of computing environments; wherein a computing environment in the second class is operable to evaluate the first digital certificate and refuse to execute the first piece of software; and wherein the computing environment in the second class is further operable to evaluate the second digital certificate and allow execution of the second piece of software.
2 . The method of claim 1 , further including the step of conditionally executing, based at least in part on evaluating the first digital certificate, the first piece of software in a first computing environment within the first class of computing environments.
3 . The method of claim 2 , further including the step of conditionally executing, based at least in part on evaluating the second digital certificate, the second piece of software in a second computing environment different from the first computing environment, the second computing environment being within the second class of computing environments.
4 . The method of claim 1 , in which the first class of computing environments comprises personal computers having a first security level, and in which the second class of computing environments comprises personal computers having a second security level.
5 . A method of distinguishing between trusted and untrusted piece of software, the method comprising:
receiving a piece of software at a computer system; determining whether the piece of software has an associated digital certificate; if the piece of software has an associated digital certificate, evaluating the digital certificate using at least one key, the key being protected, at least in part, from being replaced by a user of the computer system; and conditionally executing the piece of software based at least in part on results of the evaluating step.
6 . The method of claim 5 , in which the key is secured behind a tamper resistant barrier.
7 . The method of claim 5 , in which the key's value is protected, at least in part, from being disclosed to a user of the computer system.
8 . The method of claim 5 , in which the key's value is not kept secret from users of the computer system.
9 . A method for protecting a first computing environment, the first computing environment having a first security level, the method including:
preventing the first computing environment from using a piece of software accessible by a second computing environment having a second security level different from the first security level.
10 . The method of claim 9 , in which the preventing step includes:
evaluating at least one digital certificate associated with the first computing environment.
11 . The method of claim 9 , in which the preventing step includes:
evaluating at least one digital certificate associated with the piece of software.Join the waitlist — get patent alerts
Track US2010023761A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.