MX2020009846A - Distribución segura de conjuntos de claves de dispositivo a través de una red. - Google Patents
Distribución segura de conjuntos de claves de dispositivo a través de una red.Info
- Publication number
- MX2020009846A MX2020009846A MX2020009846A MX2020009846A MX2020009846A MX 2020009846 A MX2020009846 A MX 2020009846A MX 2020009846 A MX2020009846 A MX 2020009846A MX 2020009846 A MX2020009846 A MX 2020009846A MX 2020009846 A MX2020009846 A MX 2020009846A
- Authority
- MX
- Mexico
- Prior art keywords
- device key
- provisioning
- network
- key ring
- pse
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0877—Generation of secret information including derivation or calculation of cryptographic keys or passwords using additional device, e.g. trusted platform module [TPM], smartcard, USB or hardware security module [HSM]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0827—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving distinctive intermediate devices or communication paths
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/12—Details relating to cryptographic hardware or logic circuitry
- H04L2209/127—Trusted platform modules [TPM]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Un sistema se proporciona para la distribución de conjuntos de claves de dispositivo a través de una red en un entorno de software protegido (PSE). En el sistema, un dispositivo cliente incluye una interfaz de conexión para recibir un token de hardware criptográfico (CH) perteneciente a un usuario, software no confiable, un enclave de citas y un PSE para generar una solicitud de aprovisionamiento para un conjunto de claves de dispositivo. Un servidor proxy de atestación (APS) recibe el mensaje de aprovisionamiento usando una primera conexión de red, y transmite el mensaje de aprovisionamiento a un servidor de aprovisionamiento en línea (OPS) usando una segunda conexión de red. El OPS construye una respuesta de aprovisionamiento y un conjunto cifrado de claves de dispositivo, y entrega la respuesta de aprovisionamiento al software no confiable usando la primera y segunda conexión de red. El PSE descifra el conjunto cifrado de claves de dispositivo para obtener el conjunto de claves de dispositivo, vuelve a cifrar el conjunto de claves de dispositivo con una clave de chip específico local, y almacena el conjunto de claves de dispositivo vuelto a cifrar.
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/US2019/023071 WO2020190286A1 (en) | 2019-03-20 | 2019-03-20 | Secure distribution of device key sets over a network |
Publications (1)
Publication Number | Publication Date |
---|---|
MX2020009846A true MX2020009846A (es) | 2021-01-08 |
Family
ID=65995909
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
MX2020009846A MX2020009846A (es) | 2019-03-20 | 2019-03-20 | Distribución segura de conjuntos de claves de dispositivo a través de una red. |
Country Status (4)
Country | Link |
---|---|
EP (1) | EP3769462B1 (es) |
CA (1) | CA3094210A1 (es) |
MX (1) | MX2020009846A (es) |
WO (1) | WO2020190286A1 (es) |
-
2019
- 2019-03-20 CA CA3094210A patent/CA3094210A1/en active Pending
- 2019-03-20 MX MX2020009846A patent/MX2020009846A/es unknown
- 2019-03-20 WO PCT/US2019/023071 patent/WO2020190286A1/en unknown
- 2019-03-20 EP EP19714971.9A patent/EP3769462B1/en active Active
Also Published As
Publication number | Publication date |
---|---|
WO2020190286A1 (en) | 2020-09-24 |
EP3769462B1 (en) | 2022-02-16 |
CA3094210A1 (en) | 2020-09-20 |
EP3769462A1 (en) | 2021-01-27 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2016177332A1 (zh) | 云存储方法及系统 | |
US10594472B2 (en) | Hybrid fully homomorphic encryption (F.H.E.) systems | |
US9197410B2 (en) | Key management system | |
US20170170957A1 (en) | Methods and apparatus for migrating keys | |
WO2017133558A1 (zh) | 一种消息加密、解密方法和装置 | |
KR20190109419A (ko) | 암호화키를 사용한 신뢰 실행 환경의 어드레싱 기법 | |
RU2017131640A (ru) | Управление конфиденциальной связью | |
CN106790037B (zh) | 一种用户态加密的即时通讯方法与系统 | |
US20130339726A1 (en) | File server apparatus and file server system | |
JP7160605B2 (ja) | 安全にデータを転送する方法およびシステム | |
JP2017225116A5 (es) | ||
KR20190108580A (ko) | 서명키를 사용한 신뢰 실행 환경의 어드레싱 기법 | |
WO2022202284A1 (ja) | データ共有システム、データ共有方法、およびデータ共有プログラム | |
CN105227566A (zh) | 密钥处理方法、密钥处理装置及密钥处理系统 | |
RU2019117050A (ru) | Управление шифрованием данных посредством множества органов управления | |
US20150350375A1 (en) | Information Processing Method, Trusted Server, and Cloud Server | |
GB2404535B (en) | Secure transmission of data within a distributed computer system | |
JP6671701B1 (ja) | 演算装置、演算方法、演算プログラム、および演算システム | |
US20190109828A1 (en) | Data processing method, device and system, and storage medium | |
JP2013090199A (ja) | 鍵共有システム、鍵生成装置、及びプログラム | |
Aljafer et al. | A brief overview and an experimental evaluation of data confidentiality measures on the cloud | |
US10699021B2 (en) | Method and a device for secure storage of at least one element of digital information, and system comprising such device | |
CN104717213A (zh) | 一种网络数据传输的加密解密方法及系统 | |
CN111480313B (zh) | 通信终端、服务器装置、记录介质 | |
MX2020009846A (es) | Distribución segura de conjuntos de claves de dispositivo a través de una red. |