| CPC H04L 9/0861 (2013.01) [H04L 9/0894 (2013.01)] | 25 Claims | 

| 
               1. A method for key establishment, the method comprising: 
            during a first cryptographic key derivation: 
                storing a first trusted measurement value associated with a first entity in a first secure storage location; 
                  storing an expected measurement value associated with a second entity in a second secure storage location; and 
                  generating a first instance of a cryptographic key using the first trusted measurement value, the expected measurement value, and a key derivation function; and 
                during a second cryptographic key derivation: 
              obtaining, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second trusted measurement value associated with the second entity; 
                  storing the second trusted measurement value in the second secure storage location; 
                  obtaining the first trusted measurement value as a second expected measurement value; 
                  storing the second expected measurement value in the first secure storage location; and 
                  generating a second instance of the cryptographic key using the second expected measurement value, the second trusted measurement value, and the key derivation function. 
                 |