KR100431081B1 - 보안모듈 및 그의 이용 방법 - Google Patents
보안모듈 및 그의 이용 방법 Download PDFInfo
- Publication number
- KR100431081B1 KR100431081B1 KR10-2001-0039242A KR20010039242A KR100431081B1 KR 100431081 B1 KR100431081 B1 KR 100431081B1 KR 20010039242 A KR20010039242 A KR 20010039242A KR 100431081 B1 KR100431081 B1 KR 100431081B1
- Authority
- KR
- South Korea
- Prior art keywords
- security module
- stored
- encrypted
- storage means
- firmware
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3234—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
- H04L9/0618—Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (9)
- 보안모듈 제작시 암호화된 보안모듈의 관리자 아이디와 패스워드, 인증된 보안모듈 관리자에 의해 암호화된 사용자 아이디, 패스워드 및 펌웨어가 저장되는 제 1 저장수단과,상기 인증된 보안모듈 관리자에 의해 입력된 마스터 키가 저장되는 제 2 저장수단과,상기 사용자의 아이디와 패스워드가 인증되면 상기 제 2 저장수단에 저장된 마스터 키를 이용하여 상기 제 1 저장수단으로부터 공급되는 상기 펌웨어를 복호화하는 복호화 수단과,상기 복호화 수단으로부터 출력되는 평문형태의 펌웨어를 저장하기 위한 제 3 저장수단을 포함하는 것을 특징으로 하는 보안모듈.
- 제 1 항에 있어서, 상기 펌웨어는,상기 복호화 수단을 제어하기 위한 제어 프로그램과,소정의 정보 처리를 위한 응용 프로그램 및 데이터와,암호화 과정에 사용되는 다수의 예비키와,각 예비키에 대응하는 인증시 발급되는 인증서 및 인증 티켓을 포함하여 이루어지는 것을 특징으로 하는 보안모듈.
- 제 1 항에 있어서,상기 제 1 저장수단은 부트 프로그램 영역, 프로그램 영역 및 데이터 영역으로 이루어진 것을 특징으로 하는 보안모듈.
- 제 3 항에 있어서,상기 부트 프로그램 영역에는 초기 구동 프로그램을 로드하기 위한 부트 로더, 상기 보안모듈 관리자의 아이디 및 패스워드, 그리고 상기 복호화 수단을 제어하기 위한 제어 프로그램이 암호화되어 저장되고,상기 프로그램 영역에는 소정의 정보 처리를 위한 응용 프로그램이 암호화되어 저장되고,상기 데이터 영역에는 소정의 정보 처리를 위한 데이터, 암호화 과정에 사용되는 다수의 예비키, 각 예비키에 대응하는 인증시 발급되는 인증서 및 인증 티켓이 암호화되어 저장되는 것을 특징으로 하는 보안모듈.
- 제 1 항에 있어서,상기 제 1 및 제 2 저장 수단은 휘발성 메모리 소자로 이루어진 것을 특징으로 하는 보안모듈.
- 제 1 항에 있어서,상기 제 2 저장 수단에는 저장된 마스터 키의 보관을 위해 전원을 공급하는 전원 공급부가 연결된 것을 특징으로 하는 보안모듈.
- 삭제
- 삭제
- 삭제
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR10-2001-0039242A KR100431081B1 (ko) | 2001-07-02 | 2001-07-02 | 보안모듈 및 그의 이용 방법 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR10-2001-0039242A KR100431081B1 (ko) | 2001-07-02 | 2001-07-02 | 보안모듈 및 그의 이용 방법 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| KR20030002932A KR20030002932A (ko) | 2003-01-09 |
| KR100431081B1 true KR100431081B1 (ko) | 2004-05-12 |
Family
ID=27713012
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| KR10-2001-0039242A Expired - Fee Related KR100431081B1 (ko) | 2001-07-02 | 2001-07-02 | 보안모듈 및 그의 이용 방법 |
Country Status (1)
| Country | Link |
|---|---|
| KR (1) | KR100431081B1 (ko) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR101393307B1 (ko) | 2007-07-13 | 2014-05-12 | 삼성전자주식회사 | 보안 부팅 방법 및 그 방법을 사용하는 반도체 메모리시스템 |
| KR101795457B1 (ko) * | 2016-09-27 | 2017-11-10 | 시큐리티플랫폼 주식회사 | 보안 기능이 강화된 디바이스의 초기화 방법 및 디바이스의 펌웨어 업데이트 방법 |
| KR101982917B1 (ko) * | 2017-04-28 | 2019-05-27 | 건국대학교 산학협력단 | Ecu 보안 유지를 위한 인증서 기반 차량 보안 방법 및 장치 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5748740A (en) * | 1995-09-29 | 1998-05-05 | Dallas Semiconductor Corporation | Method, apparatus, system and firmware for secure transactions |
| US5825878A (en) * | 1996-09-20 | 1998-10-20 | Vlsi Technology, Inc. | Secure memory management unit for microprocessor |
| US5999629A (en) * | 1995-10-31 | 1999-12-07 | Lucent Technologies Inc. | Data encryption security module |
| KR20000048718A (ko) * | 1996-09-30 | 2000-07-25 | 피터 엔. 데트킨 | 안전 부팅 |
| US6138236A (en) * | 1996-07-01 | 2000-10-24 | Sun Microsystems, Inc. | Method and apparatus for firmware authentication |
| EP1072975A2 (en) * | 1999-07-27 | 2001-01-31 | Compaq Computer Corporation | Virus resistant and hardware independent method of flashing computer system bios |
-
2001
- 2001-07-02 KR KR10-2001-0039242A patent/KR100431081B1/ko not_active Expired - Fee Related
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5748740A (en) * | 1995-09-29 | 1998-05-05 | Dallas Semiconductor Corporation | Method, apparatus, system and firmware for secure transactions |
| US5999629A (en) * | 1995-10-31 | 1999-12-07 | Lucent Technologies Inc. | Data encryption security module |
| US6138236A (en) * | 1996-07-01 | 2000-10-24 | Sun Microsystems, Inc. | Method and apparatus for firmware authentication |
| US5825878A (en) * | 1996-09-20 | 1998-10-20 | Vlsi Technology, Inc. | Secure memory management unit for microprocessor |
| KR20000048718A (ko) * | 1996-09-30 | 2000-07-25 | 피터 엔. 데트킨 | 안전 부팅 |
| EP1072975A2 (en) * | 1999-07-27 | 2001-01-31 | Compaq Computer Corporation | Virus resistant and hardware independent method of flashing computer system bios |
Also Published As
| Publication number | Publication date |
|---|---|
| KR20030002932A (ko) | 2003-01-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US7697691B2 (en) | Method of delivering Direct Proof private keys to devices using an on-line service | |
| US7058806B2 (en) | Method and apparatus for secure leveled access control | |
| CN102271037B (zh) | 基于在线密钥的密钥保护装置 | |
| EP1500226B1 (en) | System and method for storage and retrieval of a cryptographic secret from a plurality of network enabled clients | |
| RU2147790C1 (ru) | Передача лицензии на программное обеспечение для элемента аппаратного обеспечения | |
| CN108768963B (zh) | 可信应用与安全元件的通信方法和系统 | |
| US20050210241A1 (en) | Method and apparatus for digital rights management using certificate revocation list | |
| US20050193199A1 (en) | Accessing protected data on network storage from multiple devices | |
| US20110040971A1 (en) | Portable system and method for remotely accessing data | |
| JP7617047B2 (ja) | ハードウェアセキュリティモジュールを備えたメッセージ伝送システム | |
| JP2004538584A (ja) | 電子装置における情報の処理方法、システム、電子装置及び処理ブロック | |
| KR20080020621A (ko) | 무결성 보호된 보안 저장의 실행 | |
| EP1501238B1 (en) | Method and system for key distribution comprising a step of authentication and a step of key distribution using a KEK (key encryption key) | |
| EP3292654B1 (en) | A security approach for storing credentials for offline use and copy-protected vault content in devices | |
| CN111191217A (zh) | 一种密码管理方法及相关装置 | |
| CN105247833A (zh) | 自认证设备与方法 | |
| CN115801232A (zh) | 一种私钥保护方法、装置、设备及存储介质 | |
| JP5622668B2 (ja) | アプリケーション認証システム、アプリケーション認証方法 | |
| CN110740036A (zh) | 基于云计算的防攻击数据保密方法 | |
| KR100431081B1 (ko) | 보안모듈 및 그의 이용 방법 | |
| CN115051871B (zh) | 一种鉴权方法及设备、存储介质 | |
| EP2958265B1 (en) | Revocation of a root certificate stored in a device | |
| US20250117778A1 (en) | Access control systems and methods for cryptowallets | |
| WO2001095072A2 (en) | Network agent password storage and retrieval scheme | |
| US20250086291A1 (en) | Method and system for an external cryptoprocessor to communicate with another cryptoprocessor within a computer to ensure the integrity of the computer and to provide content encryption and decryption |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A201 | Request for examination | ||
| PA0109 | Patent application |
St.27 status event code: A-0-1-A10-A12-nap-PA0109 |
|
| PA0201 | Request for examination |
St.27 status event code: A-1-2-D10-D11-exm-PA0201 |
|
| PN2301 | Change of applicant |
St.27 status event code: A-3-3-R10-R13-asn-PN2301 St.27 status event code: A-3-3-R10-R11-asn-PN2301 |
|
| D13-X000 | Search requested |
St.27 status event code: A-1-2-D10-D13-srh-X000 |
|
| PG1501 | Laying open of application |
St.27 status event code: A-1-1-Q10-Q12-nap-PG1501 |
|
| D14-X000 | Search report completed |
St.27 status event code: A-1-2-D10-D14-srh-X000 |
|
| E902 | Notification of reason for refusal | ||
| PE0902 | Notice of grounds for rejection |
St.27 status event code: A-1-2-D10-D21-exm-PE0902 |
|
| T11-X000 | Administrative time limit extension requested |
St.27 status event code: U-3-3-T10-T11-oth-X000 |
|
| T11-X000 | Administrative time limit extension requested |
St.27 status event code: U-3-3-T10-T11-oth-X000 |
|
| T11-X000 | Administrative time limit extension requested |
St.27 status event code: U-3-3-T10-T11-oth-X000 |
|
| T11-X000 | Administrative time limit extension requested |
St.27 status event code: U-3-3-T10-T11-oth-X000 |
|
| T11-X000 | Administrative time limit extension requested |
St.27 status event code: U-3-3-T10-T11-oth-X000 |
|
| E13-X000 | Pre-grant limitation requested |
St.27 status event code: A-2-3-E10-E13-lim-X000 |
|
| P11-X000 | Amendment of application requested |
St.27 status event code: A-2-2-P10-P11-nap-X000 |
|
| P13-X000 | Application amended |
St.27 status event code: A-2-2-P10-P13-nap-X000 |
|
| E701 | Decision to grant or registration of patent right | ||
| PE0701 | Decision of registration |
St.27 status event code: A-1-2-D10-D22-exm-PE0701 |
|
| GRNT | Written decision to grant | ||
| PR0701 | Registration of establishment |
St.27 status event code: A-2-4-F10-F11-exm-PR0701 |
|
| PR1002 | Payment of registration fee |
St.27 status event code: A-2-2-U10-U11-oth-PR1002 Fee payment year number: 1 |
|
| PG1601 | Publication of registration |
St.27 status event code: A-4-4-Q10-Q13-nap-PG1601 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 4 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 5 |
|
| FPAY | Annual fee payment |
Payment date: 20090324 Year of fee payment: 6 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 6 |
|
| PN2301 | Change of applicant |
St.27 status event code: A-5-5-R10-R13-asn-PN2301 St.27 status event code: A-5-5-R10-R11-asn-PN2301 |
|
| LAPS | Lapse due to unpaid annual fee | ||
| PC1903 | Unpaid annual fee |
St.27 status event code: A-4-4-U10-U13-oth-PC1903 Not in force date: 20100430 Payment event data comment text: Termination Category : DEFAULT_OF_REGISTRATION_FEE |
|
| PC1903 | Unpaid annual fee |
St.27 status event code: N-4-6-H10-H13-oth-PC1903 Ip right cessation event data comment text: Termination Category : DEFAULT_OF_REGISTRATION_FEE Not in force date: 20100430 |
|
| PN2301 | Change of applicant |
St.27 status event code: A-5-5-R10-R13-asn-PN2301 St.27 status event code: A-5-5-R10-R11-asn-PN2301 |
|
| P22-X000 | Classification modified |
St.27 status event code: A-4-4-P10-P22-nap-X000 |