US2012166807A1PendingUtilityA1

Systems and Methods Using Cryptography to Protect Secure Computing Environments

Individually held — no corporate assignee on recordPriority: Aug 12, 1996Filed: Feb 29, 2012Published: Jun 28, 2012
Est. expiryAug 12, 2016(expired)· nominal 20-yr term from priority
G06F 9/4406G06F 21/51H04L 9/3247
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Secure computation environments are protected from bogus or rogue load modules, executables and other data elements through use of digital signatures, seals and certificates issued by a verifying authority. A verifying authority—which may be a trusted independent third party—tests the load modules or other executables to verify that their corresponding specifications are accurate and complete, and then digitally signs the load module or other executable based on tamper resistance work factor classification. Secure computation environments with different tamper resistance work factors use different verification digital signature authentication techniques (e.g., different signature algorithms and/or signature verification keys)—allowing one tamper resistance work factor environment to protect itself against load modules from another, different tamper resistance work factor environment. Several dissimilar digital signature algorithms may be used to reduce vulnerability from algorithm compromise, and subsets of multiple digital signatures may be used to reduce the scope of any specific compromise.

Claims

exact text as granted — not AI-modified
1 . A system comprising:
 means for digitally signing a load module using a first key to yield a first digital signature;   means for digitally signing the load module using a second key to yield a second digital signature;   means for distributing at least the first digital signature to a first remote electronic appliance comprising a first protected processing environment operable to authenticate the first digital signature before the first remote electronic appliance executes the load module; and   means for distributing at least the second digital signature to a second remote electronic appliance comprising a second protected processing environment operable to authenticate the second digital signature before the second remote electronic appliance executes the load module.   
     
     
         2 . The system of  claim 1 , further comprising:
 means for testing the load module.   
     
     
         3 . The system of  claim 2 , in which the means for testing comprises means for testing the load module to determine if it does what it is supposed to do. 
     
     
         4 . The system of  claim 2 , in which the means for testing comprises means for determining whether the load module is operable to compromise or harm a system upon which it is executed. 
     
     
         5 . The system of  claim 2 , in which the means for testing comprises means for determining whether the load module performs as specified by a specification. 
     
     
         6 . The system of  claim 2 , in which the means for testing comprises means for determining whether the load module is a virus. 
     
     
         7 . The system of  claim 1 , in which the first protected processing environment has an assurance level that is different from an assurance level of the second protected processing environment. 
     
     
         8 . The system of  claim 1 , further comprising:
 means for securely distributing a third key to the first protected processing environment, the third key being configured for use in authenticating the first digital signature; and   means for securely distributing a fourth key to the second protected processing environment, the fourth key being configured for use in authenticating the second digital signature.   
     
     
         9 . The system of  claim 1 , further comprising:
 means for encrypting the load module.

Join the waitlist — get patent alerts

Track US2012166807A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.