首页> 外国专利> LOGICAL ACCESS BLOCK PROCESSING PROTOCOL FOR TRANSPARENT SECURE FILE STORAGE

LOGICAL ACCESS BLOCK PROCESSING PROTOCOL FOR TRANSPARENT SECURE FILE STORAGE

机译:透明安全文件存储的逻辑访问块处理协议

摘要

The packet payload of network file data packets corresponds to read and written portions of a file (220) recognized by a file system. Individual packet payload data (222), is preferably processed into a sequence of logical access blocks (224), with each logical access block containing a corresponding portion of the packet payload data (222). The file management header (226) is virutalized for all files associated with a real mount point and locally stored by the platform effectively as part of the policy data held by the policy store. The file management header (226) includes a unique file GUID (228), security parameter index (230), and a security signature (232). The security parameter index (230) is preferably a composite of security information including an encryption key identifier (key) (234), a security options array (236), and file related information (238). The logical access blocks (224) received in the packet payload data are processed (202) to apply error correction, where the error correction field (246) is present, and validate the integrity of the LAB data fields (240), including the LAB compression headers (244) if present, against the digital signature (242) values. The filed management header (226) is read, typically in advance, by the NFS/CIFS state machine process to obtain the encryption key identifier from the field (234) and compression algorithm identity, if applicable from the options index field.
机译:网络文件数据分组的分组有效载荷对应于由文件系统识别的文件(220)的读取和写入部分。各个分组有效载荷数据(222)优选地被处理成一系列逻辑访问块(224),其中每个逻辑访问块包含分组有效载荷数据(222)的相应部分。对于与真实安装点相关联的所有文件而言,文件管理头(226)都是虚拟的,并由平台有效地本地存储为策略存储所保存的策略数据的一部分。文件管理头(226)包括唯一文件GUID(228),安全参数索引(230)和安全签名(232)。安全参数索引(230)优选地是安全信息的组合,该安全信息包括加密密钥标识符(密钥)(234),安全选项阵列(236)和文件相关信息(238)。处理(202)在分组有效载荷数据中接收的逻辑访问块(224)以应用纠错,其中存在纠错字段(246),并验证包括LAB在内的LAB数据字段的完整性(240)。如果存在,则针对数字签名(242)值的压缩报头(244)。 NFS / CIFS状态机进程通常会预先读取已提交的管理标头(226),以从字段(234)获得加密密钥标识符和压缩算法身份(如果适用)从选项索引字段获得。

著录项

  • 公开/公告号IN2005CN00045A

    专利类型

  • 公开/公告日2008-04-25

    原文格式PDF

  • 申请/专利权人

    申请/专利号IN45/CHENP/2005

  • 发明设计人 PHAM DUC;LO MINGCHEN;NGUYEN TIEN;ZHANG PU;

    申请日2005-01-20

  • 分类号H04L9/00;

  • 国家 IN

  • 入库时间 2022-08-21 20:07:47

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号