发明申请
- 专利标题: CRYPTOGRAPHIC KEY-TO-POLICY ASSOCIATION AND ENFORCEMENT FOR SECURE KEY-MANAGEMENT AND POLICY EXECUTION
- 专利标题(中): 关键管理和政策执行的关键政策协调和执行力
-
申请号: US11962991申请日: 2007-12-21
-
公开(公告)号: US20100023782A1公开(公告)日: 2010-01-28
- 发明人: Gyan Prakash , Selim Aissi , Jasmeet Chhabra , Tobias Kohlenberg
- 申请人: Gyan Prakash , Selim Aissi , Jasmeet Chhabra , Tobias Kohlenberg
- 专利权人: Intel Corporation
- 当前专利权人: Intel Corporation
- 主分类号: G06F12/14
- IPC分类号: G06F12/14 ; G06F21/24
摘要:
Key-to-policy association and hardware-based policy enforcement for file/folder encryption (FFE) and/or full-disk encryption (FDE) are provided. A CPU independent microprocessor (CIM) is coupled to a platform and provides a secure storage service, secure non-volatile storage, secure policy enforcement engine, and system interface for communication with platform components independent of the CPU. The CIM stores a key and its associated policies by generating a hardware-derived key to wrap the key prior to securely storing it in non-volatile storage on the CIM. Upon receiving a request for key-access by an application, policy status and credentials are verified before the key is returned.
信息查询