首页> 外国专利> TRUSTED PLATFORM MODULE ATTESTATION FLOW OVER SIMPLE AUTHENTICATION AND SECURITY LAYER WITH MULTIPLE SYMMETRIC KEY IDENTIFICATION

TRUSTED PLATFORM MODULE ATTESTATION FLOW OVER SIMPLE AUTHENTICATION AND SECURITY LAYER WITH MULTIPLE SYMMETRIC KEY IDENTIFICATION

机译:可信平台模块证明流过简单的身份验证和安全层,具有多个对称密钥识别

摘要

An existing Simple Authentication and Security Layer (SASL) framework is modified to overcome message size limitations by implementing a control byte that enables segmentation of SASL messages. In implementations in which client computing devices utilize a trusted platform module (TPM) for enhanced security, the client computing device can transmit multiple public keys and other information to a provisioning service during an attestation process. This information can be segmented across multiple messages while leveraging the SASL framework. A control byte may be utilized in each message and define attributes about the respective messages, such as whether a current message is an interim or final message segment. Likewise, the provisioning service can divide a challenge key into multiple segments and include a control byte for each segment. The control byte within segmented messages enables utilization of the TPM public keys and thereby can leverage the heightened security provided by the TPM.
机译:通过实现启用SASL消息的分割的控制字节,修改了现有的简单身份验证和安全层(SASL)框架以克服消息大小限制。在客户计算机计算设备利用可信平台模块(TPM)以增强安全性的实施方式中,客户端计算设备可以在证明过程期间将多个公共密钥和其他信息发送到供应服务。在利用SASL框架时,可以在多个消息中分段此信息。可以在每个消息中使用控制字节并定义关于各个消息的属性,例如当前消息是临时或最终消息段。同样地,供应服务可以将挑战键划分为多个段,并包括每个段的控制字节。分段消息中的控制字节可以利用TPM公钥,从而可以利用TPM提供的增强的安全性。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号