发明授权
- 专利标题: Application-specific secret generation
- 专利标题(中): 特定于应用程序的秘密生成
-
申请号: US11754667申请日: 2007-05-29
-
公开(公告)号: US08422674B2公开(公告)日: 2013-04-16
- 发明人: Masana Murase , Wilfred E. Plouffe, Jr. , Kanna Shimizu , Vladimir Zbarsky
- 申请人: Masana Murase , Wilfred E. Plouffe, Jr. , Kanna Shimizu , Vladimir Zbarsky
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Yudell Isidore Ng Russell PLLC
- 主分类号: H04L9/00
- IPC分类号: H04L9/00 ; H04L29/06 ; H04L9/28 ; G06F9/24 ; G06F12/14 ; G06F7/04 ; G08B29/00 ; H04K1/00
摘要:
A method, computer program product, and data processing system for protecting sensitive program code and data (including persistently stored data) from unauthorized access. Dedicated hardware decrypts an encrypted kernel into memory for execution. When an application is to be executed, the kernel computes one or more secrets by cryptographically combining information contained in the application with secret information contained in the kernel itself. The kernel then deletes its secret information and passes the computed secrets to the application. To store data persistently in memory, the application uses one of the computed secrets to encrypt the data prior to storage. If the kernel starts another instance of the same application, the kernel (which will have been re-decrypted to restore the kernel's secrets) will compute the same one or more secrets, thus allowing the second application instance to access the data encrypted by the first application instance.
公开/授权文献
- US20080298581A1 Application-Specific Secret Generation 公开/授权日:2008-12-04
信息查询