WO0110076A2

Systems and methods for using cryptography to protect secure and insecure computing environments

Abstract

Computation environments are protected from bogus or rogue load modules, executables, and other data elements through use of digital signatures, seals, and certificates issued by a verifying authority. A verifying authority - which may be a trusted independent third party - tests the load modules and/or other items to verify that their corresponding specifications are accurate and complete, and then digitally signs them based on a tamper resistance work factor classification. Secure computation environments with different tamper resistance work factors use different digital signature authentication techniques (e.g., different signature algorithms and/or signature verification keys), allowing one tamper resistance work factor environment to protect itself against load modules from another tamper resistance work factor environment. The verifying authority can provide an application intended for insecure environments with a credential having multiple elements covering different parts of the application. To verify the application, a trusted element can issue challenges based on different parts of the authenticated credential that the trusted element selects in an unpredictable (e.g., random) way, and deny service (or take other appropriate action) if the responses do not match the authenticated credential.

WO0110076A2, drawing sheet 1
Sheet 1 of 28

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

27 claims: 6 independent, 21 dependent

  1. 1
    WHAT IS CLAIMED IS:1. A method for verifying an electronic item, the method including: (a) presenting a secure credential, the credential comprising predefined plural subsets of the electronic item and corresponding cryptographic hashes;and (b) randomly selecting one of the predefined plural subsets;(c) computing a cryptographic hash of a portion of the electronic item corresponding to the selected predefined subset;and (d) testing whether the computed cryptographic hash corresponds to a corresponding cryptographic hash within the presented credential.
  2. 7
    In a computer system including an insecure computing arrangement for using an application, a trusted element for verifying the application comprising:a decryptor that decrypts a credential associated with the application;a validator that validates at least one digital signature corresponding to the credential;a challenge generator that selects, based at least in part on the credential, at least one predetermined portion of the application, and issues a challenge requesting a response providing a computation of at least one value based on the selected predetermined portion of the application;and a response checker that checks the response against the credential.
  3. 14
    A method for certifying an electronic item comprising:(a) randomly selecting plural portions of the electronic item;(b) computing at least one cryptographic value corresponding to each of the selected plural portions;and (c) specifying a credential defining each of the randomly selected plural portions and the corresponding computed cryptographic values.
  4. 20
    A device for certifying an electronic item comprising:means for randomly selecting plural portions of the electronic item;means for computing at least one cryptographic value corresponding to each of the selected plural portions;and means for specifying a credential defining at least one randomly-selected portion and the corresponding computed cryptographic value.
  5. 21
    A device for certifying an electronic item comprising:a selector that randomly selects plural portions of the electronic item;a computer that computes at least one cryptographic value corresponding to each of the selected plural portions;and a credential formatter that formats one or more credentials defining at least one randomly-selected portion and the corresponding computed cryptographic value.
  6. 27
    A method for tampering with a credential verification process, the method including:predicting portions of a credentialed electronic item specified in repetitive challenges, and supplying corresponding cryptographic hash values based on the predicted portions.