USRE43934EExpiredUtility
Method and apparatus to assign trust to a key
Est. expirySep 16, 2019(expired)· nominal 20-yr term from priority
Inventors:Ned M. Smith
H04L 63/0823H04L 9/3265H04L 63/06H04K 1/02H04L 9/3247H04L 63/123H04L 9/0891H04L 9/0894
78
PatentIndex Score
4
Cited by
18
References
40
Claims
Abstract
A method includes determining whether a key is traceable to one of a set of keys associated with a trusted source and determining whether the key is identified in a list of compromised keys. If the key is not identified as compromised and is traceable to one of the keys in the set, the key is assigned a trusted status.
Claims
exact text as granted — not AI-modified1. A method comprising:
reading from a software module binary operating on a computing device, a set of keys associated with a trusted source, wherein the set of keys is embedded in the software module binary, the set of keys having been compiled and linked with a software module to generate the software module binary;
determining on the computing device, whether a key is traceable to one of the keys in the set of keys, the key being presented by or read from a document comprising a digital signature of the software module binary;
determining on the computing device, whether the key is identified in a list of compromised keys; and
if the key is not identified as compromised and is traceable to one of the keys in the set of keys, assigning the key a trusted status.
2. The method of claim 1 further comprising:
verifying on the computing device, the integrity of the document, the document further comprising the list of compromised keys.
3. The method of claim 1 in which determining on the computing device, whether the key is traceable to one of the keys in the set of keys further comprises:
tracing the key through a certificate chain to one of the keys in the set of keys.
4. The method of claim 1 wherein the digital signature is a hash of the software module binary.
5. The method of claim 2 in which the document is a manifest signed by the key.
6. The method of claim 1 in which determining on the computing device, whether the key is identified in the list of compromised keys further comprises:
searching on the computing device, the list of compromised keys for the key.
7. A method comprising:
producing on a computing device, a document comprising an identification of a software module binary and a list of compromised keys;
digitally signing the document, on the computing device, using a key presented by or read from the document and traceable to one key of a set of keys, wherein the set of keys is embedded in the software module binary, the set of keys having been compiled and linked with a software module to generate the software module binary; and
making the document available on a communication network by which computer systems comprising the software module binary may read the document.
8. The method of claim 7 in which the identification of the software module binary comprises a hash value of the software module binary.
9. The method of claim 7 in Which the key is traceable to one of the keys in the set of keys embedded in the software module binary by way of a certificate chain.
10. A device comprising:
a processor;
a machine-readable storage medium coupled to the processor by way of a bus, the storage medium storing instructions which, when executed by the processor, cause the device to
read from a software module binary a set of keys associated with a trusted source, wherein the set of keys is embedded in the software module binary, the set of keys having been compiled and linked with a software module to generate the software module binary,
determine whether a key is traceable to one of the keys in the set of keys, the key being presented by or read from a document comprising a digital signature of the software module binary,
determine whether the key is identified in a list of compromised key's, and
if the key is not identified as compromised and is traceable to one of the keys in the set of keys, assign the key a trusted status.
11. The device of claim 10 in which the instructions, when executed by the device, further cause the device to:
verify the integrity of the document, the document further comprising the list of compromised keys.
12. The device of claim 10 in which the instructions, when executed by the device, further cause the device to:
trace the key through a certificate chain to one of the keys in the set of keys.
13. A device comprising:
a processor;
a machine-readable storage medium coupled to the processor by way of a bus, the storage medium storing instructions which, when executed by the processor, cause the device to:
produce a document comprising an identification of a software module binary and a list of compromised keys; and
digitally sign the document using a key presented by or read from the document and traceable to one key of a set of keys, wherein the set of keys is embedded in the software module binary, the set of keys having been compiled and linked with a software module to generate the software module binary;
wherein the key is traceable to one of the keys in the set of keys embedded in the software module binary by way of a certificate chain.
14. The device of claim 13 in which the identification of the software module binary comprises a hash value of the software module binary.
15. An article comprising a machine tangible, non-transitory computer-readable medium having stored thereon instructions which, when executed by a processor of a device, result in:
reading from a software module binary operating on the device, a set of keys associated with a trusted source, wherein the set of keys is embedded in the software module binary, the set of keys having been compiled and linked with a software module to generate the software module binary;
determining on the device, whether a key is traceable to one of the keys in the set of keys, the key being presented by or read from a document comprising a digital signature of the software module binary;
determining on the device, whether the key is identified in a list of compromised keys; and
if the key is not identified as compromised and is traceable to one of keys in the set of keys, assigning the key a trusted status.
16. The article of claim 15 in which the instructions, when executed by the processor, further result in:
verifying on the device, the integrity of the document, the document further comprising the list of compromised keys.
17. The article of claim 15 in which the sequence of instructions, when executed by the processor, further result in:
tracing on the device, the key through a certificate chain to one of the keys in the set of keys.
18. An article comprising a machine tangible, non-transitory computer-readable medium having stored thereon instructions which, when executed by a processor of a device, result in:
producing on the device, a document comprising an identification of a software module binary and a list of compromised keys; and
digitally signing the document, on the device, using a key presented by or read from the document and traceable to one key of a set of keys, wherein the set of keys is embedded in the software module binary, the set of keys having been compiled and linked with a software module to generate the software module binary;
wherein the identification of the software module binary comprises a hash value of the software module binary.
19. The article of claim 18 in which the key is traceable by way of a certificate chain to one of the keys in the set of keys embedded in the software module binary.
20. A method comprising:
reading from a software module binary operating on a computing device, a set of values associated with a trusted source, wherein the set of values is embedded in the software module binary, the set of values having been compiled and linked with a software module to generate the software module binary; determining on the computing device, whether a value is traceable to one of the values in the set of values, the value being presented by or read from a file comprising a digital signature of the software module binary; determining whether the value is compromised; and if the value is not determined to be compromised and is traceable to one of the values in the set of values, assigning the value a trusted status.
21. The method of claim 20 further comprising:
verifying on the computing device, the integrity of the file, the file further comprising the list of compromised values.
22. The method of claim 20 in which determining on the computing device, whether the value is traceable to one of the values in the set of values further comprises:
tracing on the computing device, the value through a certificate chain to one of the values in the set of values.
23. The method of claim 20 wherein the digital signature is a hash of the software module binary.
24. The method of claim 21 in which the file is a manifest signed using the value.
25. The method of claim 20 in which determining on the computing device, whether the value is compromised values comprises:
searching on the computing device, the list of compromised values for the value.
26. A method comprising:
producing on a computing device, a file for facilitating determining of whether a value is compromised, wherein the file comprises an identification of a software module binary; digitally signing on the computing device, the file using a value presented by or read from the file and traceable to one value of a set of values, wherein the set of values is embedded in the software module binary, the set of values having been compiled and linked with a software module to generate the software module binary; and making the file available on a communication network by which other computing devices comprising the software module binary may read the file.
27. The method of claim 26 in which the identification of the software module binary comprises a hash value of the software module binary.
28. The method of claim 26 in which the value is traceable to one of the values in the set of values embedded in the software module binary by way of a certificate chain.
29. A device comprising:
a processor; a tangible, non-transitory computable-readable storage medium coupled to the processor, the storage medium storing instructions which, when executed by the processor, cause the device to: read from a software module binary a set of values associated with a trusted source, wherein the set of values is embedded in the software module binary, the set of values having been compiled and linked with a software module to generate the software module binary; determine whether a value is traceable to one of the values in the set of values, the value being presented by or read from a file comprising a digital signature of the software module binary; determine whether the value is compromised; and if the value is determined as compromised and is traceable to one of the values in the set of values, assign the value a trusted status.
30. The device of claim 29 in which the instructions, when executed by the device, further cause the device to:
verify the integrity of the file, the file further comprising a list of compromised values.
31. The device of claim 29 in which the instructions, when executed by the device, further cause the device to:
trace the value through a certificate chain to one of the values in the set of values.
32. A device comprising:
a processor; a tangible, non-transitory computer-readable storage medium coupled to the processor, the storage medium storing instructions which, when executed by the processor, cause the device to: produce on the device, a file for facilitating determining whether a value is compromised, the file comprising an identification of a software module binary; and digitally sign the file, on the device, using a value presented by or read from the file and traceable to one value of a set of values, wherein the set of values is embedded in the software module binary, the set of values having been compiled and linked with a software module to generate the software module binary; wherein the value is traceable to one of the values in the set of values embedded in the software module binary by way of a certificate chain.
33. The device of claim 32 in which the identification of the software module binary comprises a hash value of the software module binary.
34. An article comprising a tangible, non-transitory computer-readable medium having stored thereon instructions which, when executed on a device, result in:
reading on the device, from a software module binary a set of values associated with a trusted source, wherein the set of values is embedded in the software module binary, the set of values having been compiled and linked with a software module to generate the software module binary; determining on the device, whether a value is traceable to one of the values in the set of values, the value being presented by or read from a file comprising a digital signature of the software module binary; determining on the device, whether the value is compromised; and if the value is not identified as compromised and is traceable to one of values in the set of values, assigning the value a trusted status.
35. The article of claim 34 in which the instructions, when executed on the device, further result in:
verifying on the device, the integrity of the file, the file further comprising the list of compromised values.
36. The article of claim 34 in which the instructions, when executed by the processor, further result in:
tracing on the device, the value through a certificate chain to one of the values in the set of values.
37. An article comprising a tangible, non-transitory computer-readable medium having stored thereon instructions which, when executed on a device, result in:
producing on the device, a file for facilitating determining whether a value is compromised, the file comprising an identification of a software module binary; and digitally signing the file, on the device, using a value presented by or read from the file and traceable to one value of a set of values, wherein the set of values is embedded in the software module binary, the set of values having been compiled and linked with a software module to generate the software module binary; wherein the identification of the software module binary comprises a hash value of the software module binary.
38. The article of claim 37 in which the value is traceable by way of a certificate chain to one of the values in the set of values embedded in the software module binary.
39. An article comprising a tangible, non-transitory computer-readable medium having stored thereon instructions which, when executed on a device, result in:
receiving, by a compilation module operating on the device, a software module binary and a data file comprising a set of values; and generating, by the compilation module, a file for facilitating determining whether a value is compromised, using the software module binary and the data file, wherein the file comprises an identification of the software module binary and the set of values embedded in the software module binary; wherein the file is to be digitally signed, on the device, using a value presented by or read from the file and traceable to one value of a set of values; wherein the identification of the software module binary comprises a hash value of the software module binary.
40. The article of claim 39 in which the value is traceable by way of a certificate chain to one of the values in the set of values embedded in the software module binary.Join the waitlist — get patent alerts
Track USRE43934E — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.