FR2904169B1 - Procede et application d'association intersysteme bases sur une unite de securite logicielle. - Google Patents

Procede et application d'association intersysteme bases sur une unite de securite logicielle. Download PDF

Info

Publication number
FR2904169B1
FR2904169B1 FR0756146A FR0756146A FR2904169B1 FR 2904169 B1 FR2904169 B1 FR 2904169B1 FR 0756146 A FR0756146 A FR 0756146A FR 0756146 A FR0756146 A FR 0756146A FR 2904169 B1 FR2904169 B1 FR 2904169B1
Authority
FR
France
Prior art keywords
hardware security
association
security unit
computing systems
secure computing
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
FR0756146A
Other languages
English (en)
Other versions
FR2904169A1 (fr
Inventor
Xizhe Li
Xu Wang
Song Cheng
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Lenovo Beijing Ltd
Original Assignee
Lenovo Beijing Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Lenovo Beijing Ltd filed Critical Lenovo Beijing Ltd
Publication of FR2904169A1 publication Critical patent/FR2904169A1/fr
Application granted granted Critical
Publication of FR2904169B1 publication Critical patent/FR2904169B1/fr
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication
    • G06F21/445Program or device authentication by mutual authentication, e.g. between devices or programs
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0869Network architectures or network communication protocols for network security for authentication of entities for achieving mutual authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3234Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0894Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
    • H04L9/0897Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage involving additional devices, e.g. trusted platform module [TPM], smartcard or USB
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • H04L9/3268Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computing Systems (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Storage Device Security (AREA)
  • Hardware Redundancy (AREA)

Abstract

La présente invention concerne un procédé d'association de systèmes de calcul inter-sécurisé basé sur une unité de sécurité matérielle, comprenant les étapes consistant à : configurer des conditions nécessaires d'association pour des unités de sécurité matérielles de systèmes de calcul sécurisés ; échanger des informations d'unités de sécurité matérielles entre les unités de sécurité matérielles des systèmes de calcul sécurisés à associer, et contrôler les validités des dispositifs de l'unité de sécurité matérielle d'homologue ; et si le contrôle de validation réussit, il se poursuit par les étapes suivantes ; sinon, sortir de la procédure d'association ; vérifier respectivement si l'association satisfait les conditions nécessaires d'association respectives par les unités de sécurité matérielles des systèmes de calcul sécurisés à associer ; et si la vérification réussit, il se poursuit par les étapes suivantes ; sinon, sortir de la procédure d'association ; et mémoriser respectivement des informations de plate-forme et des informations d'association des unités de sécurité matérielles par les unités de sécurité matérielles des systèmes de calcul sécurisés. Le présent procédé fournit un mécanisme de traitement basé sur une unité de sécurité matérielle pour déterminer des confiances entre des systèmes informatiques sécurisés.
FR0756146A 2006-07-03 2007-06-29 Procede et application d'association intersysteme bases sur une unite de securite logicielle. Active FR2904169B1 (fr)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2006101005385A CN101102180B (zh) 2006-07-03 2006-07-03 基于硬件安全单元的系统间绑定及平台完整性验证方法

Publications (2)

Publication Number Publication Date
FR2904169A1 FR2904169A1 (fr) 2008-01-25
FR2904169B1 true FR2904169B1 (fr) 2022-06-17

Family

ID=38421117

Family Applications (1)

Application Number Title Priority Date Filing Date
FR0756146A Active FR2904169B1 (fr) 2006-07-03 2007-06-29 Procede et application d'association intersysteme bases sur une unite de securite logicielle.

Country Status (5)

Country Link
US (1) US8090946B2 (fr)
CN (1) CN101102180B (fr)
DE (1) DE102007030622A1 (fr)
FR (1) FR2904169B1 (fr)
GB (1) GB2439838B (fr)

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7600134B2 (en) * 2004-11-08 2009-10-06 Lenovo Singapore Pte. Ltd. Theft deterrence using trusted platform module authorization
US8700893B2 (en) * 2009-10-28 2014-04-15 Microsoft Corporation Key certification in one round trip
US8418259B2 (en) * 2010-01-05 2013-04-09 Microsoft Corporation TPM-based license activation and validation
EP2819057B1 (fr) * 2013-06-24 2017-08-09 Nxp B.V. Système de traitement de données, procédé d'initialisation d'un système de traitement de données et produit de programme informatique
CN103679036A (zh) * 2013-11-13 2014-03-26 安徽云盾信息技术有限公司 一种基于互联网的移动加密设备间建立信任的实现方法
JP6589996B2 (ja) * 2016-01-15 2019-10-16 富士通株式会社 セキュリティ装置および制御方法
CN107196755A (zh) * 2017-03-28 2017-09-22 山东超越数控电子有限公司 一种vpn设备安全启动方法及系统
GB2579884B (en) * 2017-09-05 2020-11-11 Istorage Ltd Methods and systems of securely transferring data
GB2566107B (en) * 2017-09-05 2019-11-27 Istorage Ltd Methods and systems of securely transferring data
GB2578767B (en) * 2018-11-07 2023-01-18 Istorage Ltd Methods and systems of securely transferring data
CN109921902B (zh) * 2019-03-22 2020-10-23 创新先进技术有限公司 一种密钥管理方法、安全芯片、业务服务器及信息系统
GB2589145A (en) 2019-11-25 2021-05-26 Istorage Ltd Protected portable media storage
US11638134B2 (en) * 2021-07-02 2023-04-25 Oracle International Corporation Methods, systems, and computer readable media for resource cleanup in communications networks

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6349338B1 (en) * 1999-03-02 2002-02-19 International Business Machines Corporation Trust negotiation in a client/server data processing network using automatic incremental credential disclosure
US7549048B2 (en) * 2004-03-19 2009-06-16 Microsoft Corporation Efficient and secure authentication of computing systems
US8271783B2 (en) * 2004-04-19 2012-09-18 Hewlett-Packard Development Company, L.P. Subordinate trusted platform module
US20050251857A1 (en) * 2004-05-03 2005-11-10 International Business Machines Corporation Method and device for verifying the security of a computing platform
US20050289343A1 (en) * 2004-06-23 2005-12-29 Sun Microsystems, Inc. Systems and methods for binding a hardware component and a platform
US20060005009A1 (en) * 2004-06-30 2006-01-05 International Business Machines Corporation Method, system and program product for verifying an attribute of a computing device
US7143287B2 (en) * 2004-10-21 2006-11-28 International Business Machines Corporation Method and system for verifying binding of an initial trusted device to a secured processing system
US7784089B2 (en) * 2004-10-29 2010-08-24 Qualcomm Incorporated System and method for providing a multi-credential authentication protocol
US7600134B2 (en) * 2004-11-08 2009-10-06 Lenovo Singapore Pte. Ltd. Theft deterrence using trusted platform module authorization
CN1703004B (zh) * 2005-02-28 2010-08-25 联想(北京)有限公司 一种实现网络接入认证的方法

Also Published As

Publication number Publication date
FR2904169A1 (fr) 2008-01-25
US20080126802A1 (en) 2008-05-29
US8090946B2 (en) 2012-01-03
GB0712864D0 (en) 2007-08-08
GB2439838B (en) 2009-01-28
GB2439838A (en) 2008-01-09
DE102007030622A1 (de) 2008-02-28
CN101102180B (zh) 2010-08-25
CN101102180A (zh) 2008-01-09

Similar Documents

Publication Publication Date Title
FR2904169B1 (fr) Procede et application d'association intersysteme bases sur une unite de securite logicielle.
US11416602B2 (en) Methods and systems for identity creation, verification and management
EP2877954B1 (fr) Procédé de gestion de droits numériques basés sur des rôles dans un système informatique
US8781850B2 (en) System and method for enhancing and authenticating an insurance eligibility transaction
EA201070720A1 (ru) Управление риском счетов и система авторизации для предотвращения несанкционированного использования счетов
ATE347154T1 (de) Sicherheitsmodul für ein kontenverwaltungssystem
KR101463678B1 (ko) 신뢰되지 않는 컴퓨팅 노드들에 의해 수행된 작업의 검증
WO2008027247A3 (fr) Procédé et système d'authentification et de validation d'identités sur la base de modèles biométriques multimodaux et de codes spéciaux dans le cadre d'un processus sensiblement anonyme
BR112018006722A2 (pt) utilizando token aprimorado de autenticação de portador de cartão
BR112017025840A2 (pt) método e sistema para controle de fraude com base na geolocalização
WO2016204572A3 (fr) Système et procédé permettant de vérifier la falsification de pièces justificatives d'institution financière sur la base d'une chaîne de blocs
WO2007011840A3 (fr) Systeme et procede d'execution et de gestion de transactions financieres et de donnees
JP2010518493A5 (fr)
US20180350115A1 (en) Accelerating data-driven scientific discovery
EP4425356A3 (fr) Administration déléguée de permissions à l'aide d'une carte sans contact
Jang et al. High albumin level is a predictor of favorable response to immunotherapy in autoimmune encephalitis
FR2958770B1 (fr) Procede de controle d'un dispositif apte a fonctionner en mode avec ou sans verification de code pour effectuer une transaction
BR112022003940A2 (pt) Sistemas e métodos para troca monetária futura digital móvel
Li et al. International roughness index and a new solution for its calculation
Jalal et al. The ICD-9 to ICD-10 transition has not improved identification of rapidly progressing stage 3 and stage 4 chronic kidney disease patients: a diagnostic test study
WO2009151654A3 (fr) Programmes utilitaires de données pour une gestion de données de comptabilité
BRPI0411961A (pt) identificação segura de um executável a uma entidade de determinação de confiança
Cai et al. Modified score based on revised Tokuhashi score is needed for the determination of surgical intervention in patients with lung cancer metastases to the spine
EA201170309A1 (ru) Способ проверки подлинности документа, компьютерный программный продукт, устройство проверки и система обработки данных
KR101841561B1 (ko) Utxo 기반 프로토콜을 사용하여 전자 바우처를 발행, 사용, 환불, 정산 및 파기하는 방법과 이를 이용한 서버

Legal Events

Date Code Title Description
PLFP Fee payment

Year of fee payment: 9

PLFP Fee payment

Year of fee payment: 10

PLFP Fee payment

Year of fee payment: 11

PLFP Fee payment

Year of fee payment: 12

PLFP Fee payment

Year of fee payment: 13

PLFP Fee payment

Year of fee payment: 14

PLFP Fee payment

Year of fee payment: 15

PLFP Fee payment

Year of fee payment: 16

PLFP Fee payment

Year of fee payment: 17

PLFP Fee payment

Year of fee payment: 18

PLFP Fee payment

Year of fee payment: 19