US2010115283A1PendingUtilityA1

Systems and methods for using cryptography to protect secure and insecure computing environments

Assignee: INTERTRUST TECH CORPPriority: Jul 29, 1999Filed: Jan 11, 2010Published: May 6, 2010
Est. expiryJul 29, 2019(expired)· nominal 20-yr term from priority
Inventors:W. Olin Sibert
G06F 21/51H04L 2209/56H04L 2209/60H04L 9/3252H04L 9/3236G06F 2221/033H04L 9/3271H04L 9/3247
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Computation environments are protected from bogus or rogue load modules, executables, and other data elements through use of digital signatures, seals, and certificates issued by a verifying authority. A verifying authority—which may be a trusted independent third party—tests the load modules and/or other items to verify that their corresponding specifications are accurate and complete, and then digitally signs them based on a tamper resistance work factor classification. Secure computation environments with different tamper resistance work factors use different digital signature authentication techniques (e.g., different signature algorithms and/or signature verification keys), allowing one tamper resistance work factor environment to protect itself against load modules from another tamper resistance work factor environment. The verifying authority can provide an application intended for insecure environments with a credential having multiple elements covering different parts of the application. To verify the application, a trusted element can issue challenges based on different parts of the authenticated credential that the trusted element selects in an unpredictable (e.g., random) way, and deny service (or take other appropriate action) if the responses do not match the authenticated credential.

Claims

exact text as granted — not AI-modified
1 - 27 . (canceled) 
   
   
       28 . A trusted element for use with a computer system including an insecure arrangement for using an application, the trusted element comprising:
 a challenge generator that selects, based at least in part on a credential associated with the application, at least one predetermined portion of the application, the predetermined portion of the application including at least some executable software code, and issues a challenge requesting a response from the application, the response providing a computation of at least one value based on the selected predetermined portion of the application; and   a response checker that checks the response against the credential.   
   
   
       29 . A trusted element as in  claim 28 , wherein the credential corresponds to a digital signature. 
   
   
       30 . A trusted element as in  claim 29 , wherein the trusted element further includes a validator that validates the digital signature. 
   
   
       31 . A trusted element as in  claim 28 , wherein the challenge generator randomly selects the predetermined portion from plural predetermined portions defined by the credential. 
   
   
       32 . A trusted element as in  claim 28 , wherein the challenge generator issues the challenge during execution of the application by the insecure arrangement. 
   
   
       33 . A trusted element as in  claim 28 , wherein the challenge generator requests the application to compute a cryptographic hash of the selected portion. 
   
   
       34 . A trusted element as in  claim 28 , wherein the challenge generator selects a virtual path within the application. 
   
   
       35 . A trusted element as in  claim 28 , wherein the challenge generator selects a byte range within the application. 
   
   
       36 . In an electronic appliance including a secure execution space and an insecure execution space, a method for permitting an application executing within the insecure execution space to request one or more services from a trusted element executing in the secure execution space, the method comprising:
 issuing a challenge from the trusted element to the application executing within the insecure execution space, the challenge being based at least in part on randomly selected parts of an authenticated credential, the challenge requesting the application to compute at least one value based on one or more portions of the application, the one or more portions of the application including at least some executable software code;   sending, from the application to the trusted element, the at least one value;   comparing, at the trusted element, information provided by the authenticated credential with said at least one value; and   denying the application access to said one or more services if the at least one value does not correspond with the information provided by the authenticated credential.   
   
   
       37 . A method as in  claim 36 , wherein the at least one value is computed by computing one or more cryptographic hashes of the one or more portions of the application. 
   
   
       38 . A method as in  claim 36 , in which the issuing, sending, and comparing steps are performed multiple times during execution of the application. 
   
   
       39 . A method as in  claim 36 , in which the authenticated credential is digitally signed. 
   
   
       40 . A method as in  claim 36 , in which the authenticated credential is at least in part encrypted. 
   
   
       41 . A method as in  claim 36 , in which at least one of the portions of the application overlaps another of the portions of the application. 
   
   
       42 . A method as in  claim 36 , in which at least one of the one or more portions of the application corresponds to a predetermined byte range or virtual path in the application. 
   
   
       43 . A computer readable medium storing a computer program, the computer program including instructions that, when executed by a processor of an electronic appliance, are operable to cause the electronic appliance to take actions comprising:
 issuing a challenge from a trusted element executing in a secure execution space to an application executing in an insecure execution space, the challenge being based at least in part on randomly selected parts of an authenticated credential, the challenge requesting the application to compute at least one value based on one or more portions of the application, the one or more portions of the application including at least some executable software code;   receiving, from the application, the at least one value;   comparing information provided by the authenticated credential with the at least one value; and   denying the application access to said one or more services if the at least one value does not correspond with the information provided by the authenticated credential.   
   
   
       44 . A computer readable medium as in  claim 43 , wherein the at least one value is computed by computing one or more cryptographic hashes of the one or more portions of the application. 
   
   
       45 . A computer readable medium  43 , in which the issuing, sending, and comparing steps are performed multiple times during execution of the application. 
   
   
       46 . A computer readable medium as in  claim 43 , in which the authenticated credential is digitally signed. 
   
   
       47 . A computer readable medium as in  claim 43 , in which the authenticated credential is at least in part encrypted. 
   
   
       48 . A computer readable medium as in  claim 43 , in which at least one of the portions of the application overlaps another of the portions of the application. 
   
   
       49 . A computer readable medium as in  claim 43 , in which at least one of the one or more portions of the application corresponds to a predetermined byte range or virtual path in the application. 
   
   
       50 . An electronic appliance comprising:
 a secure execution space;   an insecure execution space; and   a trusted element operable to execute within the secure execution space, the trusted element being operable to:
 issue a challenge to an application executing in the insecure execution space, the challenge being based at least in part on randomly selected parts of an authenticated credential, the challenge requesting the application to computer at least one value based on one or more portions of the application, the one or more portions of the application including at least some executable software code; 
 receive, from the application or agent, said at least one value; 
 compare information provided by the authenticated credential with said at least one value; and 
 deny the application access to one or more services provided by an application executing in the secure execution space if the at least one value does not correspond with the information provided by the authenticated credential. 
   
   
   
       51 . An electronic appliance as in  claim 50 , wherein the at least one value is computed by computing one or more cryptographic hashes of the one or more portions of the application. 
   
   
       52 . An electronic appliance as in  claim 50 , in which the secure execution space comprises a protected processing environment. 
   
   
       53 . An electronic appliance as in  claim 50 , in which the authenticated credential is digitally signed and at least in part encrypted. 
   
   
       54 . An electronic appliance as in  claim 50 , in which at least one of the portions of the application overlaps another of the portions of the application. 
   
   
       55 . An electronic appliance as in  claim 50 , in which at least one of the one or more portions of the application corresponds to a predetermined byte range or virtual path in the application.

Join the waitlist — get patent alerts

Track US2010115283A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.