Invention Grant
- Patent Title: Key certification in one round trip
- Patent Title (中): 重要认证一次往返
-
Application No.: US12607937Application Date: 2009-10-28
-
Publication No.: US08700893B2Publication Date: 2014-04-15
- Inventor: Stefan Thom , Scott D. Anderson , Erik L. Holt
- Applicant: Stefan Thom , Scott D. Anderson , Erik L. Holt
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agent Tony Azure; Andrew Sanders; Micky Minhas
- Main IPC: H04L9/00
- IPC: H04L9/00 ; H04L9/32

Abstract:
Certification of a key, which a Trusted Platform Module (TPM) has attested as being non-migratable, can be performed in a single round trip between the certificate authority (CA) and the client that requests the certificate. The client creates a certificate request, and then has the TPM create an attestation identity key (AIK) that is bound to the certificate request. The client then asks the TPM to sign the new key as an attestation of non-migratability. The client then sends the certificate request, along with the attestation of non-migratability to the CA. The CA examines the certificate request and attestation of non-migratability. However, since the CA does not know whether the attestation has been made by a trusted TPM, it certifies the key but includes, in the certificate, an encrypted signature that can only be decrypted using the endorsement key of the trusted TPM.
Public/Granted literature
- US20110099367A1 KEY CERTIFICATION IN ONE ROUND TRIP Public/Granted day:2011-04-28
Information query