Patent · US Active

Method for securely creating an endorsement certificate utilizing signing key pairs

US7751568B2 · kind B2 · utility

10Cited by
17References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 31, 2003
Grant dateJul 6, 2010
Priority date
Expiry dateJul 5, 2027

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/57
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

A method and system for ensuring security-compliant creation and certificate generation for endorsement keys of manufactured TPMs. The endorsement keys are generated by the TPM manufacturer and stored within the TPM. The TPM manufacturer also creates a signing key pair and associated signing key certificate. The signing key pair is also stored within the TPM, while the certificate is provided to the OEM's credential server. During the endorsement key (EK) credential process, the TPM generates a signed endorsement key, which comprises the public endorsement key signed with the public signing key. The credential server matches the public signing key of the endorsement key with a public signing key within the received certificate. The EK certificate is generated and inserted into the TPM only when a match is confirmed.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.