Trusted Storage
    1.
    发明申请
    Trusted Storage 有权
    可信存储

    公开(公告)号:US20140129847A1

    公开(公告)日:2014-05-08

    申请号:US13669273

    申请日:2012-11-05

    IPC分类号: G06F21/24

    CPC分类号: G06F21/10 H04L9/0844

    摘要: In one embodiment, a method for authenticating access to encrypted content on a storage medium, wherein the encrypted content is encrypted according to a full disk encryption (FDE) key, the storage medium including an encrypted version of the FDE key and an encrypted version of a protected storage area (PSA) key, and wherein the encrypted version of the FDE key is encrypted according to the PSA key, the method comprising: providing an authenticated communication channel between a host and a storage engine associated with the storage medium; at the storage engine, receiving a pass code from the host over the authenticated communication channel; hashing the pass code to form a derived key, wherein the encrypted version of the PSA key is encrypted according to the derived key; verifying an authenticity of the pass code; if the pass code is authentic, decrypting the encrypted version of the PSA key to recover the PSA key; decrypting the encrypted FDE key using the recovered PSA key to recover the FDE key; and decrypting the encrypted content using the FDE key.

    摘要翻译: 在一个实施例中,一种用于认证对存储介质上的加密内容的访问的方法,其中根据全盘加密(FDE)密钥对加密的内容进行加密,该存储介质包括FDE密钥的加密版本和加密版本的 保护存储区域(PSA)密钥,并且其中根据PSA密钥加密FDE密钥的加密版本,该方法包括:在与存储介质相关联的主机和存储引擎之间提供经认证的通信信道; 在存储引擎处,通过认证通信信道从主机接收密码; 散列所述密码以形成导出密钥,其中所述PSA密钥的加密版本根据导出的密钥被加密; 验证密码的真实性; 如果密码是真实的,解密PSA密钥的加密版本以恢复PSA密钥; 使用恢复的PSA密钥解密加密的FDE密钥来恢复FDE密钥; 并使用FDE密钥解密加密的内容。

    Trusted storage
    2.
    发明授权
    Trusted storage 有权
    可信存储

    公开(公告)号:US08307217B2

    公开(公告)日:2012-11-06

    申请号:US12025777

    申请日:2008-02-05

    IPC分类号: G06F12/14 H04L9/08

    摘要: In one embodiment, a method for authenticating access to encrypted content on a storage medium, wherein the encrypted content is encrypted according to a full disk encryption (FDE) key, the storage medium including an encrypted version of the FDE key and an encrypted version of a protected storage area (PSA) key, and wherein the encrypted version of the FDE key is encrypted according to the PSA key, the method comprising: providing an authenticated communication channel between a host and a storage engine associated with the storage medium; at the storage engine, receiving a pass code from the host over the authenticated communication channel; hashing the pass code to form a derived key, wherein the encrypted version of the PSA key is encrypted according to the derived key; verifying an authenticity of the pass code; if the pass code is authentic, decrypting the encrypted version of the PSA key to recover the PSA key; decrypting the encrypted FDE key using the recovered PSA key to recover the FDE key; and decrypting the encrypted content using the FDE key.

    摘要翻译: 在一个实施例中,一种用于认证对存储介质上的加密内容的访问的方法,其中根据全盘加密(FDE)密钥对加密的内容进行加密,该存储介质包括FDE密钥的加密版本和加密版本的 保护存储区域(PSA)密钥,并且其中根据PSA密钥加密FDE密钥的加密版本,该方法包括:在与存储介质相关联的主机和存储引擎之间提供经认证的通信信道; 在存储引擎处,通过认证通信信道从主机接收密码; 散列所述密码以形成导出密钥,其中所述PSA密钥的加密版本根据导出的密钥被加密; 验证密码的真实性; 如果密码是真实的,解密PSA密钥的加密版本以恢复PSA密钥; 使用恢复的PSA密钥解密加密的FDE密钥来恢复FDE密钥; 并使用FDE密钥解密加密的内容。

    Trusted storage
    3.
    发明申请
    Trusted storage 有权
    可信存储

    公开(公告)号:US20080294914A1

    公开(公告)日:2008-11-27

    申请号:US12025777

    申请日:2008-02-05

    IPC分类号: G06F12/14 H04L9/32

    摘要: In one embodiment, a method for authenticating access to encrypted content on a storage medium, wherein the encrypted content is encrypted according to a full disk encryption (FDE) key, the storage medium including an encrypted version of the FDE key and an encrypted version of a protected storage area (PSA) key, and wherein the encrypted version of the FDE key is encrypted according to the PSA key, the method comprising: providing an authenticated communication channel between a host and a storage engine associated with the storage medium; at the storage engine, receiving a pass code from the host over the authenticated communication channel; hashing the pass code to form a derived key, wherein the encrypted version of the PSA key is encrypted according to the derived key; verifying an authenticity of the pass code; if the pass code is authentic, decrypting the encrypted version of the PSA key to recover the PSA key; decrypting the encrypted FDE key using the recovered PSA key to recover the FDE key; and decrypting the encrypted content using the FDE key.

    摘要翻译: 在一个实施例中,一种用于认证对存储介质上的加密内容的访问的方法,其中根据全盘加密(FDE)密钥对加密的内容进行加密,该存储介质包括FDE密钥的加密版本和加密版本的 保护存储区域(PSA)密钥,并且其中根据PSA密钥加密FDE密钥的加密版本,该方法包括:在与存储介质相关联的主机和存储引擎之间提供经认证的通信信道; 在存储引擎处,通过认证通信信道从主机接收密码; 散列所述密码以形成导出密钥,其中所述PSA密钥的加密版本根据导出的密钥被加密; 验证密码的真实性; 如果密码是真实的,解密PSA密钥的加密版本以恢复PSA密钥; 使用恢复的PSA密钥解密加密的FDE密钥来恢复FDE密钥; 并使用FDE密钥解密加密的内容。