US2006026423A1PendingUtilityA1

Privacy-protecting integrity attestation of a computing platform

Assignee: IBMPriority: Jul 12, 2004Filed: Jul 11, 2005Published: Feb 2, 2006
Est. expiryJul 12, 2024(expired)· nominal 20-yr term from priority
H04L 9/3234H04L 2209/80H04L 9/3218
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems, apparatus and methods for privacy-protecting integrity attestation of a computing platform. An example method for privacy-protecting integrity attestation of a computing platform (P) has a trusted platform module (TPM), and comprises the following steps. First, the computing platform (P) receives configuration values (PCR 1 . . . PCRn). Then, by means of the trusted platform module (TPM), a configuration value (PCRp) is determined which depends on the configuration of the computing platform (P). In a further step the configuration value (PCRp) is signed by means of the trusted platform module. Finally, in the event that the configuration value (PCRp) is one of the received configuration values (PCR 1 . . . PCRn), the computing platform (P) proves to a verifier (V) that it knows the signature (sign(PCRp)) on one of the received configuration values (PCR 1 . . . PCRn).

Claims

exact text as granted — not AI-modified
1 . A method comprising privacy-protecting integrity attestation of a computing platform having a trusted platform module, the step of privacy-protecting comprising: 
 receiving a plurality of configuration values, determining by means of the trusted platform module a particular configuration value depending on the configuration of the computing platform,    signing by means of the trusted platform module the particular configuration value with a signature, and    in the event that the particular configuration value is one of the plurality of configuration values, the computing platform proving to a verifier that it knows the signature on one of the plurality of configuration values.    
   
   
       2 . A method according to  claim 1 , wherein the proof is carried out by a cryptographic proof.  
   
   
       3 . A method according to  claim 1 , wherein the proof is carried out by a zero-knowledge proof.  
   
   
       4 . A method according to  claim 1 , further comprising: 
 wherein after receiving the plurality of configuration values the computing platform checking whether configurations having the configuration values of the plurality of configuration values actually may exist, and terminating the method if at least one configuration value may not exist.    
   
   
       5 . A method according to  claim 1 , further comprising the computing platform checking whether the number of received configuration values in the plurality of configuration values exceeds a minimum number of configuration values, and terminating the method if the number of received configuration values does not exceed the minimum number.  
   
   
       6 . A computer program comprising program code for performing the steps of the method according to  claim 1 , when loaded in a digital processor of a computer.  
   
   
       7 . A computer program product stored on a computer usable medium, comprising computer readable program code for causing a computer to perform the steps of the method according to  claim 1 .  
   
   
       8 . A computing platform for privacy-protecting integrity attestation, the computing platform being adapted to receive a plurality of configuration values, comprising: 
 a trusted platform module adapted to determine a particular configuration value in dependence on the configuration of the computing platform, and to sign the configuration value with a signature, and    wherein the computing platform comprises the functionality that in the event that the particular configuration value is one of the received plurality of configuration values the computing platform is adapted to prove to a verifier that it knows the signature on one of the received configuration values.    
   
   
       9 . A network for privacy-protecting communication, comprising: 
 a computing platform having a trusted platform module, and    a verifier connected to the computing platform,    wherein the computing platform is adapted to receive a plurality of configuration values,    wherein the trusted platform module is adapted 
 to determine a particular configuration value in dependence on the configuration of the computing platform and  
 to sign the configuration value with a signature, and  
   wherein the computing platform comprises the functionality that in the event that the particular configuration value is one of the received plurality of configuration values the computing platform is adapted to prove to the verifier that it knows the signature on one of the received configuration values.    
   
   
       10 . A method according to  claim 1 , wherein the proof is carried out by both a cryptographic proof and by a zero-knowledge proof, and the method further comprising: 
 after receiving the plurality of configuration values the computing platform checking whether configurations having the configuration values of the plurality of configuration values actually may exist, and terminating the method if at least one configuration value may not exist; and    the computing platform checking whether the number of received configuration values in the plurality of configuration values exceeds a minimum number of configuration values, and terminating the method if the number of received configuration values does not exceed the minimum number.    
   
   
       11 . An article of manufacture comprising a computer usable medium having computer readable program code means embodied therein for causing privacy-protecting integrity attestation, the computer readable program code means in said article of manufacture comprising computer readable program code means for causing a computer to effect the steps of  claim 1 .  
   
   
       12 . A program storage device readable by machine, tangibly embodying a program of instructions executable by the machine to perform method steps for privacy-protecting integrity attestation, said method steps comprising the steps of  claim 1 .  
   
   
       13 . A computer program product comprising a computer usable medium having computer readable program code means embodied therein for causing functions of a computing platform for privacy-protecting integrity attestation, the computer readable program code means in said computer program product comprising computer readable program code means for causing a computer to effect the functions of  claim 8 .  
   
   
       14 . A computer program product comprising a computer usable medium having computer readable program code means embodied therein for causing functions of a network for privacy-protecting communication, the computer readable program code means in said computer program product comprising computer readable program code means for causing a computer to effect the functions of  claim 9 .  
   
   
       15 . An article of manufacture comprising a computer usable medium having computer readable program code means embodied therein for causing privacy-protecting integrity attestation, the computer readable program code means in said article of manufacture comprising computer readable program code means for causing a computer to effect the steps of  claim 4 .  
   
   
       16 . A program storage device readable by machine, tangibly embodying a program of instructions executable by the machine to perform method steps for privacy-protecting integrity attestation, said method steps comprising the steps of  claim 5 .  
   
   
       17 . A computing platform according to  claim 8 , wherein the proof is carried out by at least one of: a cryptographic proof, and a zero-knowledge proof.  
   
   
       18 . A computing platform according to  claim 8 , wherein after it receives the plurality of configuration values the computing platform checks whether configurations having the configuration values of the plurality of configuration values actually may exist, and terminating the method if at least one configuration value may not exist.  
   
   
       19 . A computing platform according to  claim 8 , wherein after it receives the plurality of configuration values the computing platform checks whether the number of received configuration values in the plurality of configuration values exceeds a minimum number of configuration values, and terminating the method if the number of received configuration values does not exceed the minimum number.  
   
   
       20 . A program storage device readable by machine, tangibly embodying a program of instructions executable by the machine to perform method steps for privacy-protecting integrity attestation, said method steps comprising the steps of  claim 4.

Join the waitlist — get patent alerts

Track US2006026423A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.