首页> 外国专利> APPARATUS AND METHOD FOR PROVISIONING AN ENDORSEMENT KEY CERTIFICATE FOR A FIRMWARE TRUSTED PLATFORM MODULE

APPARATUS AND METHOD FOR PROVISIONING AN ENDORSEMENT KEY CERTIFICATE FOR A FIRMWARE TRUSTED PLATFORM MODULE

机译:为固件信任平台模块提供认可密钥证书的装置和方法

摘要

Disclosed is a method for provisioning an endorsement key (EK) certificate for a firmware trusted platform module (fTPM). In the method, the fTPM receives a derived key (DK) from a hardware trusted platform (HWTP). The fTPM is implemented in the HWTP, the DK is derived from a hardware key (HWK) securely stored in the HWTP, the HWK is unique to the HWTP, and the HWK is not available to the fTPM. The fTPM generates an endorsement primary seed (EPS) based on the DK, and generates a hashed endorsement primary seed (HEPS) based on a hash of the EPS. The fTPM forwards the HEPS to a provisioning station, and receives, from the provisioning station, an EK certificate corresponding to the HEPS.
机译:公开了一种用于为固件受信任的平台模块(fTPM)供应认可密钥(EK)证书的方法。在该方法中,fTPM从硬件可信平台(HWTP)接收派生密钥(DK)。 fTPM是在HWTP中实现的,DK是从安全存储在HWTP中的硬件密钥(HWK)派生的,该HWK是HWTP所独有的,并且HTP对fTPM不可用。 fTPM基于DK生成背书主种子(EPS),并基于EPS的哈希表生成哈希背书主种子(HEPS)。 fTPM将HEPS转发到供应站,并从供应站接收与HEPS相对应的EK证书。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号