Invention Grant
- Patent Title: Application-specific secret generation
- Patent Title (中): 特定于应用程序的秘密生成
-
Application No.: US11754667Application Date: 2007-05-29
-
Publication No.: US08422674B2Publication Date: 2013-04-16
- Inventor: Masana Murase , Wilfred E. Plouffe, Jr. , Kanna Shimizu , Vladimir Zbarsky
- Applicant: Masana Murase , Wilfred E. Plouffe, Jr. , Kanna Shimizu , Vladimir Zbarsky
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Yudell Isidore Ng Russell PLLC
- Main IPC: H04L9/00
- IPC: H04L9/00 ; H04L29/06 ; H04L9/28 ; G06F9/24 ; G06F12/14 ; G06F7/04 ; G08B29/00 ; H04K1/00

Abstract:
A method, computer program product, and data processing system for protecting sensitive program code and data (including persistently stored data) from unauthorized access. Dedicated hardware decrypts an encrypted kernel into memory for execution. When an application is to be executed, the kernel computes one or more secrets by cryptographically combining information contained in the application with secret information contained in the kernel itself. The kernel then deletes its secret information and passes the computed secrets to the application. To store data persistently in memory, the application uses one of the computed secrets to encrypt the data prior to storage. If the kernel starts another instance of the same application, the kernel (which will have been re-decrypted to restore the kernel's secrets) will compute the same one or more secrets, thus allowing the second application instance to access the data encrypted by the first application instance.
Public/Granted literature
- US20080298581A1 Application-Specific Secret Generation Public/Granted day:2008-12-04
Information query