Token binding using trust module protected keys

Binding a security token to a client token binder, such as a trusted platform module, is provided. A bound security token can only be used on the client on which it was obtained. A secret binding key (kbind) is established between the client and an STS. The client derives a key (kmac) from kbind, si...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Aphale, Guruprasad B, Kamel, Tarek B, Rouskov, Yordan, Bharadwaj, Vijay G, Frei, Adrian, Venkataraman, Sankara Narayanan, Su, Xiaohong
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page
container_issue
container_start_page
container_title
container_volume
creator Aphale, Guruprasad B
Kamel, Tarek B
Rouskov, Yordan
Bharadwaj, Vijay G
Frei, Adrian
Venkataraman, Sankara Narayanan
Su, Xiaohong
description Binding a security token to a client token binder, such as a trusted platform module, is provided. A bound security token can only be used on the client on which it was obtained. A secret binding key (kbind) is established between the client and an STS. The client derives a key (kmac) from kbind, signs a security token request with kmac, and instructs the STS to bind the requested security token to kbind. The STS validates the request by deriving kmac using a client-provided nonce and kbind to MAC the message and compare the MAC values. If the request is validated, the STS generates a response comprising the requested security token, derives two keys from kbind: one to sign the response and one to encrypt the response, and sends the response to the client. Only a device comprising kbind is enabled to use the bound security token, providing increased security.
format Patent
fullrecord <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_US10142107B2</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>US10142107B2</sourcerecordid><originalsourceid>FETCH-epo_espacenet_US10142107B23</originalsourceid><addsrcrecordid>eNrjZNAPyc9OzVNIysxLycxLVygtBpElRaXFJQq5-SmlOakKBUX5JanJJakpCtmplcU8DKxpiTnFqbxQmptB0c01xNlDN7UgPz61uCAxOTUvtSQ-NNjQwNDEyNDA3MnImBg1AEeQKzo</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>Token binding using trust module protected keys</title><source>esp@cenet</source><creator>Aphale, Guruprasad B ; Kamel, Tarek B ; Rouskov, Yordan ; Bharadwaj, Vijay G ; Frei, Adrian ; Venkataraman, Sankara Narayanan ; Su, Xiaohong</creator><creatorcontrib>Aphale, Guruprasad B ; Kamel, Tarek B ; Rouskov, Yordan ; Bharadwaj, Vijay G ; Frei, Adrian ; Venkataraman, Sankara Narayanan ; Su, Xiaohong</creatorcontrib><description>Binding a security token to a client token binder, such as a trusted platform module, is provided. A bound security token can only be used on the client on which it was obtained. A secret binding key (kbind) is established between the client and an STS. The client derives a key (kmac) from kbind, signs a security token request with kmac, and instructs the STS to bind the requested security token to kbind. The STS validates the request by deriving kmac using a client-provided nonce and kbind to MAC the message and compare the MAC values. If the request is validated, the STS generates a response comprising the requested security token, derives two keys from kbind: one to sign the response and one to encrypt the response, and sends the response to the client. Only a device comprising kbind is enabled to use the bound security token, providing increased security.</description><language>eng</language><subject>ELECTRIC COMMUNICATION TECHNIQUE ; ELECTRICITY ; TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><creationdate>2018</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20181127&amp;DB=EPODOC&amp;CC=US&amp;NR=10142107B2$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,776,881,25543,76293</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20181127&amp;DB=EPODOC&amp;CC=US&amp;NR=10142107B2$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>Aphale, Guruprasad B</creatorcontrib><creatorcontrib>Kamel, Tarek B</creatorcontrib><creatorcontrib>Rouskov, Yordan</creatorcontrib><creatorcontrib>Bharadwaj, Vijay G</creatorcontrib><creatorcontrib>Frei, Adrian</creatorcontrib><creatorcontrib>Venkataraman, Sankara Narayanan</creatorcontrib><creatorcontrib>Su, Xiaohong</creatorcontrib><title>Token binding using trust module protected keys</title><description>Binding a security token to a client token binder, such as a trusted platform module, is provided. A bound security token can only be used on the client on which it was obtained. A secret binding key (kbind) is established between the client and an STS. The client derives a key (kmac) from kbind, signs a security token request with kmac, and instructs the STS to bind the requested security token to kbind. The STS validates the request by deriving kmac using a client-provided nonce and kbind to MAC the message and compare the MAC values. If the request is validated, the STS generates a response comprising the requested security token, derives two keys from kbind: one to sign the response and one to encrypt the response, and sends the response to the client. Only a device comprising kbind is enabled to use the bound security token, providing increased security.</description><subject>ELECTRIC COMMUNICATION TECHNIQUE</subject><subject>ELECTRICITY</subject><subject>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2018</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNrjZNAPyc9OzVNIysxLycxLVygtBpElRaXFJQq5-SmlOakKBUX5JanJJakpCtmplcU8DKxpiTnFqbxQmptB0c01xNlDN7UgPz61uCAxOTUvtSQ-NNjQwNDEyNDA3MnImBg1AEeQKzo</recordid><startdate>20181127</startdate><enddate>20181127</enddate><creator>Aphale, Guruprasad B</creator><creator>Kamel, Tarek B</creator><creator>Rouskov, Yordan</creator><creator>Bharadwaj, Vijay G</creator><creator>Frei, Adrian</creator><creator>Venkataraman, Sankara Narayanan</creator><creator>Su, Xiaohong</creator><scope>EVB</scope></search><sort><creationdate>20181127</creationdate><title>Token binding using trust module protected keys</title><author>Aphale, Guruprasad B ; Kamel, Tarek B ; Rouskov, Yordan ; Bharadwaj, Vijay G ; Frei, Adrian ; Venkataraman, Sankara Narayanan ; Su, Xiaohong</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_US10142107B23</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>eng</language><creationdate>2018</creationdate><topic>ELECTRIC COMMUNICATION TECHNIQUE</topic><topic>ELECTRICITY</topic><topic>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</topic><toplevel>online_resources</toplevel><creatorcontrib>Aphale, Guruprasad B</creatorcontrib><creatorcontrib>Kamel, Tarek B</creatorcontrib><creatorcontrib>Rouskov, Yordan</creatorcontrib><creatorcontrib>Bharadwaj, Vijay G</creatorcontrib><creatorcontrib>Frei, Adrian</creatorcontrib><creatorcontrib>Venkataraman, Sankara Narayanan</creatorcontrib><creatorcontrib>Su, Xiaohong</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>Aphale, Guruprasad B</au><au>Kamel, Tarek B</au><au>Rouskov, Yordan</au><au>Bharadwaj, Vijay G</au><au>Frei, Adrian</au><au>Venkataraman, Sankara Narayanan</au><au>Su, Xiaohong</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>Token binding using trust module protected keys</title><date>2018-11-27</date><risdate>2018</risdate><abstract>Binding a security token to a client token binder, such as a trusted platform module, is provided. A bound security token can only be used on the client on which it was obtained. A secret binding key (kbind) is established between the client and an STS. The client derives a key (kmac) from kbind, signs a security token request with kmac, and instructs the STS to bind the requested security token to kbind. The STS validates the request by deriving kmac using a client-provided nonce and kbind to MAC the message and compare the MAC values. If the request is validated, the STS generates a response comprising the requested security token, derives two keys from kbind: one to sign the response and one to encrypt the response, and sends the response to the client. Only a device comprising kbind is enabled to use the bound security token, providing increased security.</abstract><oa>free_for_read</oa></addata></record>
fulltext fulltext_linktorsrc
identifier
ispartof
issn
language eng
recordid cdi_epo_espacenet_US10142107B2
source esp@cenet
subjects ELECTRIC COMMUNICATION TECHNIQUE
ELECTRICITY
TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION
title Token binding using trust module protected keys
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-24T12%3A49%3A39IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=Aphale,%20Guruprasad%20B&rft.date=2018-11-27&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3EUS10142107B2%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true