发明授权
- 专利标题: Method for protecting sensitive data during execution
- 专利标题(中): 在执行期间保护敏感数据的方法
-
申请号: US11065657申请日: 2005-02-24
-
公开(公告)号: US07895124B2公开(公告)日: 2011-02-22
- 发明人: Paolo Baratti , Alice Guidotti
- 申请人: Paolo Baratti , Alice Guidotti
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Garg Law Firm, PLLC
- 代理商 Rakesh Garg; Jeffrey S. LaBaw
- 优先权: EP04106935 20041223
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A method for protecting sensitive data during execution time. The sensitive data are normally stored on permanent storage devices (e.g. a hard disk). The method, according to the present invention is based on the creation at system boot of a runtime process and a corresponding runtime memory space. The sensitive data are then moved to the runtime memory space and the copy on the storage device is deleted or made unusable by users. At shutdown time the sensitive data are copied back to the storage device according to the uptodate version on the runtime memory. In particular the present invention is applied to a license management system which allows nodelocked licenses on client system even if the client is disconnected from the network. License information are considered sensitive data which should be protected during execution. A device driver is created at system boot time and a kernel cache memory is allocated to the driver. Sensitive data are then transferred to the kernel cache memory and deleted (or made non-accessible) on the permanent storage. Queries to the license information are made by means of driver I/O control codes. Sensitive data are then saved back to the permanent storage at shutdown time.
公开/授权文献
- US20060143131A1 Method for protecting sensitive data during execution 公开/授权日:2006-06-29
信息查询