Invention Patent
- Patent Title: SECURE KEY MANAGEMENT USING PROGRAMMABLE CONTROL VECTOR CHECKING
-
Application No.: CA2036858Application Date: 1991-02-21
-
Publication No.: CA2036858CPublication Date: 1994-03-01
- Inventor: MATYAS STEPHEN M , JOHNSON DONALD B , LE AN V , MARTIN WILLIAM C , PRYMAK ROSTISLAW , WILKINS JOHN D
- Applicant: IBM
- Assignee: IBM
- Current Assignee: IBM
- Priority: US50631990 1990-04-09
- Main IPC: G06F21/22
- IPC: G06F21/22 ; G09C1/00 ; H04L9/08 ; G06F9/445 ; G06F9/00 ; G06F9/44
Abstract:
SECURE KEY MANAGEMENT USING PROGRAMMABLE CONTROL VECTOR CHECKING The invention includes a control vector checking code repository located either within the same system as the cryptographic facility or alternately remotely from the system containing the cryptographic facility. The control vector checking code repository will be linked to the cryptographic facility by one of several means. A first means for linking the repository to the cryptographic facility would include a physically secure data communications link. A second means for connecting the repository to the cryptographic facility would be by using an insecure channel with authentication, wherein either a modification detection code or alternately a message authentication code would be transmitted to the cryptographic facility and then the desired control vector checking code would be transmitted over the link. The cryptographic facility will include a code authorization mechanism to compare the transmitted MAC or MDC with a corresponding value computed from the received control vector checking code. If the two values of the MDC or the MAC compare, then the control vector checking code is authenticated and loaded into the control vector checking unit for carrying out the control vector checking operations desired. The control vector checking code repository can be located in a remote system connected by means of the communications link to the crypto facility, or alternately the repository can reside in the same system as the crypto facility. This provides for the dynamic updating of control vector checking code, where improvements or alterations are made to the control vector checking sequence. This also provides for a reduced memory size in the crypto facility, being sufficiently large to accommodate subsidiary control vector checking applications, with alternate control vector checking applications requiring the reloading of the control vector checking unit from the repository.
Public/Granted literature
- CA2036858A1 SECURE KEY MANAGEMENT USING PROGRAMMABLE CONTROL VECTOR CHECKING Public/Granted day:1991-10-10
Information query