US20030196085A1

System and method for authenticating an operating system

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A system and method for authenticating an operating system includes, in accordance with one aspect, a method in a computer system having a processor, an operating system (OS), and a software identity register that holds an identity of the operating system, the processor having a private key. The method comprises forming an OS certificate containing the identity from the software identity register and signing the OS certificate using the private key. In accordance with another aspect, the signed identity is submitted to a recipient to prove an identity of the operating system to the recipient.

US20030196085A1, drawing sheet 1
Sheet 1 of 13

Term

Term ended

Projected expiry passed 10 November 2020, 5.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

52 claims: 8 independent, 44 dependent

  1. 1
    Broadest claimClaim Score 85, broad(NHIP)In a computer system having a processor, an operating system (OS), and a software identity register that holds an identity of the operating system, the processor having a private key, a method comprising:forming an OS certificate containing the identity from the software identity register;and signing the OS certificate using the private key.
  2. 9
    In a computer system having a processor and an operating system (OS), the processor having both a private key of a public/private key pair and a software identity register that holds an identity of the operating system, a method comprising:obtaining the identity of the operating system;and signing the identity using the processor private key.
  3. 15
    A system comprising:a client having a processor and an operating system (OS), the processor having a private key, a manufacturer certificate supplied by a manufacturer of the processor, and a software identity register that holds an identity of the operating system, the client being configured to submit a request over a network;a computer system having a server to serve content to the client, the computer system being configured to receive the request over the network, generate a challenge nonce, and return the challenge nonce to the client;and the client being further configured to form an OS certificate containing both the identity from the software identity register and the challenge nonce, and to sign the OS certificate using the private key, the client returning the OS certificate and the processor manufacturer certificate to the computer system for evaluation to determine whether to reject or fulfill the request.
  4. 26
    For execution on a computer system having a processor, an operating system (OS), and a software identity register that holds an identity of the operating system, the processor having a private key, a computer program stored on one or more computer-readable storage media of the computer system; the program comprising:forming an OS certificate containing the identity from the software identity register;and signing the OS certificate using the processor private key.
  5. 33
    In a system having a client and a computer, in which the client has a processor and an operating system (OS) and the processor further includes a private key, a manufacturer certificate supplied by a manufacturer of the processor, and a software identity register that holds an identity of the operating system, a computer program stored on one or more computer-readable storage media resident at the client and computer for establishing a chain of trust between the client and the computer, the program comprising:submitting a request from the client to the computer, the request specifying a particular content;generating, at the computer, a challenge nonce;returning the challenge nonce from the computer to the client;forming, at the client, an OS certificate containing the identity from the software identity register and signing the OS certificate using the private key;passing the OS certificate and the processor manufacturer certificate from the client to the computer;and evaluating, at the computer, the OS certificate and the processor manufacturer to determine whether to reject or fulfill the request.
  6. 37
    In a computer system having a cryptographic mechanism, an operating system (OS), and a software identity register that holds an identity of the operating system, the cryptographic mechanism having a private key of a pair of private and public keys, a method comprising:obtaining the identity of the operating system;and signing the identity using the private key of the cryptographic mechanism.
  7. 44
    One or more computer readable media having stored thereon a plurality of instructions that, when executed in a computer system having a cryptographic mechanism and an operating system (OS), causes the computer system to:form an OS certificate containing an identity of the operating system from a software identity register;and sign the OS certificate using a private key of a pair of private and public keys of the cryptographic mechanism.
  8. 49
    A system comprising:a first processor, wherein the first processor comprises a central processing unit (CPU);and a second processor having a key pair including a private key and a public key, wherein the private key is to be used by the second processor to sign an identity of an operating system being executed by the first processor.