会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 6. 发明申请
    • SYSTEMS AND METHODS FOR USING CRYPTOGRAPHY TO PROTECT SECURE AND INSECURE COMPUTING ENVIRONMENTS
    • 用于保护安全和计算机环境的系统和方法
    • US20150280922A1
    • 2015-10-01
    • US14683089
    • 2015-04-09
    • Intertrust Technologies Corporation
    • W. Olin SIBERT
    • H04L9/32G06F21/51
    • H04L9/3247G06F21/51G06F2221/033H04L9/3236H04L9/3252H04L9/3271H04L2209/56H04L2209/60
    • Computation environments are protected from bogus or rogue load modules, executables, and other data elements through use of digital signatures, seals, and certificates issued by a verifying authority. A verifying authority—which may be a trusted independent third party—tests the load modules and/or other items to verify that their corresponding specifications are accurate and complete, and then digitally signs them based on a tamper resistance work factor classification. Secure computation environments with different tamper resistance work factors use different digital signature authentication techniques (e.g., different signature algorithms and/or signature verification keys), allowing one tamper resistance work factor environment to protect itself against load modules from another tamper resistance work factor environment. The verifying authority can provide an application intended for insecure environments with a credential having multiple elements covering different parts of the application. To verify the application, a trusted element can issue challenges based on different parts of the authenticated credential that the trusted element selects in an unpredictable (e.g., random) way, and deny service (or take other appropriate action) if the responses do not match the authenticated credential.
    • 计算环境通过使用由验证机构颁发的数字签名,密封件和证书,免受假冒或流氓加载模块,可执行文件和其他数据元素的影响。 验证机构可以是可靠的独立第三方 - 对加载模块和/或其他项目进行测试,以验证其相应的规范是否准确和完整,然后根据防篡改工作因子分类对其进行数字签名。 具有不同防篡改工作因子的安全计算环境使用不同的数字签名认证技术(例如,不同的签名算法和/或签名验证密钥),允许一个防篡改工作因子环境来防止来自另一个防篡改工作因子环境的负载模块。 验证机构可以为具有覆盖应用程序的不同部分的多个元素的证书提供旨在用于不安全环境的应用程序。 为了验证应用程序,受信任的元素可以基于认证凭证的不同部分发出挑战,信任元素以不可预测(例如随机)的方式选择,如果响应不匹配则拒绝服务(或采取其他适当的操作) 认证凭证。