US2014140512A1PendingUtilityA1
Requested and allowed cryptographic operations comparison
Individually held — no corporate assignee on recordPriority: Jun 18, 2011Filed: Jan 6, 2012Published: May 22, 2014
Est. expiryJun 18, 2031(~4.9 yrs left)· nominal 20-yr term from priority
Inventors:Ted A. Hadley
G06F 13/1663G06F 21/57G06F 21/575G06F 21/72G06F 21/602G06F 13/1642G06F 1/24G06F 21/55G01R 31/31719G06F 2221/2143G06F 21/74G06F 21/78G09C 1/00G06F 21/79H04L 9/088G06F 21/54H04L 2209/12H04L 9/32H04L 9/0816
54
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Embodiments herein relate to cryptographic operations. A process identifier (PID) identifying a process requesting a cryptographic operation is received. Next, at least one allowed cryptographic operation associated with the PID is determined. Then, the requested cryptographic operation is compared to the at least one allowed cryptographic operation, to determine if the requested cryptographic operation is allowable.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A device comprising:
an attribute module to receive a process identifier (PID) identifying a process requesting a cryptographic operation, the attribute module to determine at least one allowed cryptographic operation associated with the PID; and a comparison module to compare the requested cryptographic operation to the at least one allowed cryptographic operation, to determine if the requested cryptographic operation is allowable.
2 . The device of claim 1 , wherein,
the attribute module further receives at least one of a key value and a key identifier (KID), where the KID is a reference to the key value, and the attribute module further determines the at least one allowed cryptographic operation associated with the received PID and the received at least one of the key value and the KID.
3 . The device of claim 2 , wherein,
the comparison module receives process attributes related to the requested cryptographic operation and receives allowed attributes related to the at least one allowed cryptographic operation, the process and allowed attributes each include at least one of an algorithm, a mode, and an application field, and the application field indicates at least one of how and where the requested cryptographic operation is to be performed on data.
4 . The device of claim 3 , wherein,
the attribute module includes a plurality of attributes lists, each of the attributes lists include the algorithm, mode, and application field, each of the allowed attributes lists is associated with at least one of a plurality of the PIDs, each of the allowed attributes lists is associated with at least one of a plurality of the KIDs and the key values, and the attribute module outputs one of the attributes lists as the allowed attributes based on the received PID and the received at least one of the key value and the KID.
5 . The device of claim 4 , further comprising:
a crypto module to receive the process attributes from the process, wherein the comparison module indicates to the process that the requested cryptographic operation was not performed, if the comparison module determines that the requested cryptographic operation is not allowable
6 . The device of claim 5 , wherein the crypto module performs the requested cryptographic operation if the comparison module determines that the requested cryptographic operation is allowable.
7 . The device of claim 6 , wherein,
the algorithm, mode, and application fields are multi-bit fields, the comparison module includes a plurality of bitwise AND gates, each of the bitwise AND logic gates to bitwise logically AND one of the algorithm, mode, and application field of the process attributes with that of the allowed attributes, and the comparison module includes a plurality of OR gates, each of the OR gates to logically OR an output of one of the bitwise AND gates, and the comparison module includes an AND gate to logically AND an output of the plurality of OR gates.
8 . The device of claim 7 , wherein
only one of the bits is set for each of the algorithm, mode, and application fields of the process attributes, each of the bits of the algorithm field of the process and allowed attributes corresponds to one of a plurality of different types of cryptographic algorithms, each of the bits of the mode field of the process and allowed attributes corresponds to one of a plurality of different types of cryptographic modes, and. each of the bits of the application field of the process and allowed attributes corresponds to one of a plurality of different types of application uses.
9 . The device of claim 6 , further comprising:
a secure key memory to store the plurality of key values, wherein the secure key memory outputs one of the plurality of key values to the crypto module in response to receiving one of the plurality of KIDs from the attribute module, a supervisory application is to set at least one of the plurality of the attributes lists, and the process is to only add an attributes list associated with a first key value of the plurality of key values if the process added the first key value to the secure memory.
10 . The device of claim 9 , wherein,
the attribute module is to output the plurality of attributes lists and the plurality of KIDs associated therewith to the process, and the process is select one of the plurality of KIDs to output to the attribute module based on the allowed one or more operations associated with the plurality of attributes lists and the KIDs.
11 . A cryptographic method, comprising:
receiving a process identifier (PID) identifying a process requesting a cryptographic operation and a key identifier (KID) associated with the process; selecting one of a plurality of attributes lists based on the received PID and KID, each the attributes lists to be associated with at least one of a plurality of PIDs and at least one of a plurality of KIDs; receiving process attributes indicating the requested cryptographic operation of the process; and comparing the received process attributes to allowed attributes included in the selected attributes list to determine if the requested cryptographic operation is allowable, the allowed attributes to indicate at least one allowed cryptographic operation of the process.
12 . The method of claim 11 , wherein
the process attributes and each of the attributes lists include an algorithm, a mode, and an application field, and the application field indicates at least one of how and where the requested cryptographic operation is to be performed on information.
13 . The method of claim 12 , wherein
the algorithm, mode, and application fields include a plurality of bits, only one of the bits is set for each of the algorithm, mode, and application fields of the process attributes, at least one of bits is set for each of the algorithm, mode, and application fields of the allowed attributes, and the bits of the algorithm, mode and application fields are set to indicate a corresponding type of allowable algorithms, modes and applications.
14 . A non-transitory computer-readable storage medium storing instructions that, if executed by a processor of a device, cause the processor to:
receive process parameters defining a requested cryptographic operation by a process, the process parameters including a process ID (PID) identifying the process and a key identifier (KID) referencing a key value; select one of a plurality of attributes lists based on the PID and the KID, the selected attributes list to define at least one allowed operation; compare the selected attributes list to at least part of the process parameters; and determine if the at least one allowed operation includes the requested cryptographic operation, based on the comparison.
15 . The non-transitory computer-readable storage medium of claim 14 , further comprising instructions that, if executed by the processor, cause the processor to:
allow a crypto module to perform the requested cryptographic operation if the at least one allowed operation includes the requested cryptographic operation; and alert the process that the requested cryptographic operation is not performed if the at least one allowed operation does not include the requested cryptographic operation.Join the waitlist — get patent alerts
Track US2014140512A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.