×

SYSTEM AND METHOD FOR COMBINING USER AND PLATFORM AUTHENTICATION IN NEGOTIATED CHANNEL SECURITY PROTOCOLS

  • US 20090307493A1
  • Filed: 05/19/2009
  • Published: 12/10/2009
  • Est. Priority Date: 03/24/2004
  • Status: Active Grant
First Claim
Patent Images

1. A network security handshake exchange method comprising:

  • obtaining a pre-master secret that contains a nonce generated by a server endpoint, the pre-master secret including a server stored measurement log (SML) that stores configuration state measured values for the server endpoint;

    hashing server platform configuration register values (PCRs) representing a configuration state of the of the server endpoint;

    generating at the server endpoint a modified pre-master secret by combining the pre-master secret with the hash of the server PCRs;

    incorporating a handshake state into the server endpoint platform configuration values by storing the modified pre-master secret into a PCR of the server endpoint;

    generating multi-faceted authentication of the server endpoint by digitally signing the modified pre-master secret with a server platform identity key, and digitally signing the modified pre-master secret with a server user identity key to create a server platform-identity-key signed value and a server user-identity-key signed value; and

    sending a first message to a client endpoint, wherein the message includes the pre-master secret, the modified pre-master secret, the server platform-identity-key signed value, and the server user-identity-key signed value.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×