| CPC H04L 9/0861 (2013.01) [H04L 9/0894 (2013.01)] | 25 Claims |

|
1. A method for key establishment, the method comprising:
during a first cryptographic key derivation:
storing a first trusted measurement value associated with a first entity in a first secure storage location;
storing an expected measurement value associated with a second entity in a second secure storage location; and
generating a first instance of a cryptographic key using the first trusted measurement value, the expected measurement value, and a key derivation function; and
during a second cryptographic key derivation:
obtaining, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second trusted measurement value associated with the second entity;
storing the second trusted measurement value in the second secure storage location;
obtaining the first trusted measurement value as a second expected measurement value;
storing the second expected measurement value in the first secure storage location; and
generating a second instance of the cryptographic key using the second expected measurement value, the second trusted measurement value, and the key derivation function.
|