Nova Patents
US20080098107A1

Method for notarizing packet traces

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A system and method for capturing non-forgeable packet traces. Upon start-up of a sniffer, a first quote of Platform Configuration Register (PCR) values in a Trusted Platform Module (TPM) utilized by the sniffer is obtained, wherein the first quote comprises a list of starting values in the PCRs and is signed by the TPM and stored in a packet log. When a packet of interest is intercepted by the sniffer, the sniffer obtains a hash of the packet and instructs the TPM to extend a PCR with the hash value. The packet of interest is then stored in the packet log. When the sniffer is shutdown, a second quote of values in the PCRs is obtained, wherein the second quote comprises a list of current values in the PCRs, and wherein the second quote is signed by the TPM and stored in the packet log.

US20080098107A1, drawing sheet 1
Sheet 1 of 8

Term

Projected expiry 5 June 2033.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

27 claims: 3 independent, 24 dependent

  1. 1
    Broadest claimClaim Score 46, average(NHIP)A computer implemented method in a network sniffer for capturing non-forgeable packet traces, the computer implemented method comprising:responsive to a start-up of a sniffer, obtaining a first quote of values in one or more platform configuration registers in a trusted platform module utilized by the sniffer, wherein the first quote comprises a list of starting values in the one or more platform configuration registers, and wherein the first quote is signed by the trusted platform module and stored in a packet log;responsive to intercepting a packet of interest at the sniffer, obtaining a hash of the packet of interest;instructing the trusted platform module to extend a platform configuration register with the hash of the packet of interest;storing the packet of interest in the packet log;and responsive to a shutdown of the sniffer, obtaining a second quote of values in the platform configuration registers, wherein the second quote comprises a list of current values in the platform configuration registers, and wherein the second quote is signed by the trusted platform module and stored in the packet log.
  2. 10
    A data processing system for capturing non-forgeable packet traces, the data processing system comprising:a bus;a storage device connected to the bus, wherein the storage device contains computer usable code;at least one managed device connected to the bus;a communications unit connected to the bus;and a processing unit connected to the bus, wherein the processing unit executes the computer usable code to obtain a first quote of values in one or more platform configuration registers in a trusted platform module utilized by a sniffer in response to a start-up of the sniffer, wherein the first quote comprises a list of starting values in the one or more platform configuration registers, and wherein the first quote is signed by the trusted platform module and stored in a packet log, obtain a hash of a packet of interest in response to intercepting the packet of interest at the sniffer, instruct the trusted platform module to extend a platform configuration register with the hash of the packet of interest, store the packet of interest in the packet log, and obtain a second quote of values in the platform configuration registers in response to a shutdown of the sniffer, wherein the second quote comprises a list of current values in the platform configuration registers, and wherein the second quote is signed by the trusted platform module and stored in the packet log.
  3. 19
    A computer program product for capturing non-forgeable packet traces, the computer program product comprising:a computer usable medium having computer usable program code tangibly embodied thereon, the computer usable program code comprising: computer usable program code for obtaining a first quote of values in one or more platform configuration registers in a trusted platform module utilized by a sniffer in response to a start-up of the sniffer, wherein the first quote comprises a list of starting values in the one or more platform configuration registers, and wherein the first quote is signed by the trusted platform module and stored in a packet log;computer usable program code for obtaining a hash of the packet of interest in response to intercepting a packet of interest at the sniffer;computer usable program code for instructing the trusted platform module to extend a platform configuration register with the hash of the packet of interest;computer usable program code for storing the packet of interest in the packet log;and computer usable program code for obtaining a second quote of values in the platform configuration registers in response to a shutdown of the sniffer, wherein the second quote comprises a list of current values in the platform configuration registers, and wherein the second quote is signed by the trusted platform module and stored in the packet log.