首页> 外国专利> Software level touchpoints for an international cryptography frameworks

Software level touchpoints for an international cryptography frameworks

机译:国际加密框架的软件级别接触点

摘要

An international cryptography framework (ICF) allows manufacturers to comply with varying national laws governing the distribution of cryptographic capabilities. The invention is concerned primarily with the application certification aspects of the framework where an application that requests cryptographic services from the ICF service elements is identified through some form of certificate to protect against the misuse of a granted level of cryptography. The levels of cryptography granted are described via security policies and expressed as classes of service. A cryptographic unit, one of the ICF core elements, can be used to build several certification schemes for application objects. The invention provides various methods that determine the strength of binding between an application code image and the issued certificates within the context of the ICF elements. A key element with regard to the exercise of a cryptographic function concerns the special requirements for the trust relation that an authority specifies for the cryptographic unit. Any function exercised by the cryptographic unit must be controllable by the associated class of service which represents the security policy. Touchpointing, both in the application and the firmware elements inside the cryptographic unit, plays a key role in exercising control over the functioning of these modules. Another fundamental requirement of the ICF architecture is that the application is assured of the integrity of the cryptographic unit from which it is receiving services. Thus, the invention also provides methods that allow a determination of whether or not the cryptographic unit has been replaced or tampered with.
机译:国际加密框架(ICF)允许制造商遵守有关加密功能分配的各种国家法律。本发明主要涉及框架的应用认证方面,其中通过某种形式的证书来识别从ICF服务元素请求密码服务的应用,以防止滥用已授予的密码级别。通过安全策略描述授予的加密级别,并表示为服务类别。密码单元是ICF核心元素之一,可用于为应用程序对象建立几种认证方案。本发明提供了各种方法,这些方法确定在ICF元素的上下文中应用程序代码映像和颁发的证书之间的绑定强度。行使密码功能的关键要素涉及授权机构为密码单元指定的信任关系的特殊要求。密码单元执行的任何功能必须可由代表安全策略的相关服务类别控制。在应用程序和加密单元内部的固件元素中,接触点在控制这些模块的功能方面起着关键作用。 ICF体系结构的另一个基本要求是,向应用程序保证从中接收服务的密码单元的完整性。因此,本发明还提供了允许确定密码单元是否已被替换或篡改的方法。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号