Method of delivering direct proof private keys to devices using a distribution cd

    公开(公告)号:GB2430518A

    公开(公告)日:2007-03-28

    申请号:GB0700526

    申请日:2005-07-08

    Applicant: INTEL CORP

    Abstract: Delivering a Direct Proof private key to a device installed in a client computer system in the field may be accomplished in a secure manner without requiring significant non-volatile storage in the device. A unique pseudo-random value is generated and stored in the device at manufacturing time. The pseudorandom value is used to generate a symmetric key for encrypting a data structure holding a Direct Proof private key and a private key digest associated with the device. The resulting encrypted data structure is stored on a removable storage medium (such as a CD), and distributed to the owner of the client computer system. When the device is initialized on the client computer system, the system checks if a localized encrypted data structure is present in the system. If not, the system obtains the associated encrypted data structure from the removable storage medium. The device decrypts the encrypted data structure using a symmetric key regenerated from its stored pseudo-random value to obtain the Direct Proof private key. If the private key is valid, it may be used for subsequent authentication processing by the device in the client computer system.

    Initiating secure operations
    48.
    发明专利

    公开(公告)号:GB2419988A

    公开(公告)日:2006-05-10

    申请号:GB0601323

    申请日:2003-03-20

    Applicant: INTEL CORP

    Abstract: A method and apparatus for initiating secure operations in a microprocessor system is described. In one embodiment, one initiating logical processor initiates the process by halting the execution of the other logical processors, and then loading initialisation and secure virtual machine monitor software into memory. The initiating processor then loads the initialisation software into secure memory for authentication and execution. The initialisation software then authenticates and registers the secure virtual machine monitor software prior to secure system operations. Executing a secured enter instruction, detecting a time to execute secure initialisation code, and sending bus messages responsive to execution of the instruction and detection time.

    Resetting a register on receipt of a locality confirming message

    公开(公告)号:GB2412465A

    公开(公告)日:2005-09-28

    申请号:GB0513435

    申请日:2003-03-20

    Applicant: INTEL CORP

    Abstract: A method and apparatus for resetting and modifying special registers in a security token is described. In one embodiment, a register may be reset when a reset flag is true when a special transmission on a bus demonstrates the mutual locality of the associated processor and chipset. A modify flag may also be used to indicate whether the register contents may be modified. Modifications may also be dependent upon demonstration of mutual locality. A locality confirming message may be sent by security bus logic in response to receiving a special bus message from a processor.

Patent Agency Ranking