首页> 外国专利> CRYPTOGRAPHIC KEY-TO-POLICY ASSOCIATION AND ENFORCEMENT FOR SECURE KEY-MANAGEMENT AND POLICY EXECUTION

CRYPTOGRAPHIC KEY-TO-POLICY ASSOCIATION AND ENFORCEMENT FOR SECURE KEY-MANAGEMENT AND POLICY EXECUTION

机译:用于安全密钥管理和策略执行的加密密钥对策略关联和强制执行

摘要

Key-to-policy association and hardware-based policy enforcement for file/folder encryption (FFE) and/or full-disk encryption (FDE) are provided. A CPU independent microprocessor (CIM) is coupled to a platform and provides a secure storage service, secure non-volatile storage, secure policy enforcement engine, and system interface for communication with platform components independent of the CPU. The CIM stores a key and its associated policies by generating a hardware-derived key to wrap the key prior to securely storing it in non-volatile storage on the CIM. Upon receiving a request for key-access by an application, policy status and credentials are verified before the key is returned.
机译:提供了文件/文件夹加密(FFE)和/或全盘加密(FDE)的密钥到策略关联和基于硬件的策略执行。独立于CPU的微处理器(CIM)连接到平台,并提供安全的存储服务,安全的非易失性存储,安全的策略执行引擎以及用于与独立于CPU的平台组件进行通信的系统接口。 CIM通过在安全地将密钥安全存储在CIM上的非易失性存储中之前生成硬件包装的密钥来包装密钥及其相关策略。收到应用程序的密钥访问请求后,将在返回密钥之前验证策略状态和凭据。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号