METHOD AND APPARATUS FOR RESTORING ENCRYPTED FILES TO AN ENCRYPTING FILE SYSTEM BASED ON DEPRECATED KEYSTORES
    1.
    发明申请
    METHOD AND APPARATUS FOR RESTORING ENCRYPTED FILES TO AN ENCRYPTING FILE SYSTEM BASED ON DEPRECATED KEYSTORES 失效
    将加密文件恢复到基于删除键盘的加密文件系统的方法和装置

    公开(公告)号:US20090110198A1

    公开(公告)日:2009-04-30

    申请号:US11929103

    申请日:2007-10-30

    IPC分类号: H04L9/00

    CPC分类号: G06F21/6218 G06F21/6209

    摘要: The present invention provides a computer implemented method, data processing system, and computer program product to restore an encrypted file. A computer receives a command to restore an encrypted file, wherein the encrypted file was previously backed up. The computer identifies a user associated with the encrypted file. The computer looks up a first keystore of the user based on the user, the first keystore having an active private key. The computer determines that a public key of the encrypted file fails to match an active public key of the first keystore. The computer restores a second keystore of the user to form a restored private key, wherein the second keystore was previously backed up. The computer responsive to a determination that the public key of the encrypted file fails to match the active public key of the first keystore, decrypts the encrypted file encryption key based on the restored private key to form a file encryption key. The computer encrypts the file encryption key with the active private key of the first keystore.

    摘要翻译: 本发明提供了一种计算机实现的方法,数据处理系统和用于恢复加密文件的计算机程序产品。 计算机接收恢复加密文件的命令,其中先前备份了加密文件。 计算机识别与加密文件相关联的用户。 计算机基于用户查找用户的第一密钥库,第一密钥库具有活动的私钥。 计算机确定加密文件的公钥不能匹配第一密钥库的活动公钥。 计算机恢复用户的第二密钥库以形成恢复的私钥,其中先前备份了第二密钥库。 该计算机响应于确定加密文件的公开密钥与第一密钥库的活动公钥匹配的确定,基于恢复的私钥对加密的文件加密密钥进行解密以形成文件加密密钥。 计算机使用第一个密钥库的活动私钥对文件加密密钥进行加密。

    Method and apparatus for restoring encrypted files to an encrypting file system based on deprecated keystores
    2.
    发明授权
    Method and apparatus for restoring encrypted files to an encrypting file system based on deprecated keystores 失效
    基于不推荐的密钥库将加密文件恢复到加密文件系统的方法和装置

    公开(公告)号:US08494167B2

    公开(公告)日:2013-07-23

    申请号:US11929103

    申请日:2007-10-30

    IPC分类号: H04K1/04 H04K1/10

    CPC分类号: G06F21/6218 G06F21/6209

    摘要: The present invention provides a computer implemented method, data processing system, and computer program product to restore an encrypted file. A computer receives a command to restore an encrypted file, wherein the encrypted file was previously backed up. The computer identifies a user associated with the encrypted file. The computer looks up a first keystore of the user based on the user, the first keystore having an active private key. The computer determines that a public key of the encrypted file fails to match an active public key of the first keystore. The computer restores a second keystore of the user to form a restored private key, wherein the second keystore was previously backed up. The computer responsive to a determination that the public key of the encrypted file fails to match the active public key of the first keystore, decrypts the encrypted file encryption key based on the restored private key to form a file encryption key. The computer encrypts the file encryption key with the active private key of the first keystore.

    摘要翻译: 本发明提供了一种计算机实现的方法,数据处理系统和用于恢复加密文件的计算机程序产品。 计算机接收恢复加密文件的命令,其中先前备份了加密文件。 计算机识别与加密文件相关联的用户。 计算机基于用户查找用户的第一密钥库,第一密钥库具有活动的私钥。 计算机确定加密文件的公钥不能匹配第一密钥库的活动公钥。 计算机恢复用户的第二密钥库以形成恢复的私钥,其中先前备份了第二密钥库。 该计算机响应于确定加密文件的公开密钥与第一密钥库的活动公钥匹配的确定,基于恢复的私钥对加密的文件加密密钥进行解密以形成文件加密密钥。 计算机使用第一个密钥库的活动私钥对文件加密密钥进行加密。

    Encryption apparatus and method for providing an encrypted file system
    3.
    发明授权
    Encryption apparatus and method for providing an encrypted file system 失效
    用于提供加密文件系统的加密装置和方法

    公开(公告)号:US07428306B2

    公开(公告)日:2008-09-23

    申请号:US11406184

    申请日:2006-04-18

    IPC分类号: H04L9/14

    摘要: An encryption apparatus and method for providing an encrypted file system are provided. The encryption apparatus and method of the illustrative embodiments uses a combination of encryption methodologies so as to reduce the amount of decryption and re-encryption that is necessary to a file in the Encrypted File System in the event that the file needs to be modified. The encryption methodologies are interleaved, or alternated, with regard to each block of plaintext. In one illustrative embodiment, Plaintext Block Chaining (PBC) and Cipher Block Chaining (CBC) encryption methodologies are alternated for encrypting a sequence of blocks of data. The encryption of a block of plaintext is dependent upon the plaintext or a cipher generated for the plaintext of a previous block of data in the sequence of blocks of data so that the encryption is more secure than known Electronic Code Book encryption methodologies.

    摘要翻译: 提供了一种用于提供加密文件系统的加密装置和方法。 说明性实施例的加密装置和方法使用加密方法的组合,以便在需要修改文件的情况下减少加密文件系统中的文件所必需的解密和重新加密的量。 关于每个明文块,加密方法被交织或交替。 在一个说明性实施例中,替代了明文块链接(PBC)和密码块链接(CBC)加密方法来加密数据块序列。 明文块的加密取决于明文或为数据块序列中的先前数据块的明文生成的密码,使得加密比已知的电子代码簿加密方法更安全。

    Encryption Apparatus and Method for Providing an Encrypted File System
    4.
    发明申请
    Encryption Apparatus and Method for Providing an Encrypted File System 有权
    加密装置和提供加密文件系统的方法

    公开(公告)号:US20080310624A1

    公开(公告)日:2008-12-18

    申请号:US12194610

    申请日:2008-08-20

    IPC分类号: H04L9/06

    摘要: An encryption apparatus and method for providing an encrypted file system are provided. The encryption apparatus and method of the illustrative embodiments uses a combination of encryption methodologies so as to reduce the amount of decryption and re-encryption that is necessary to a file in the Encrypted File System in the event that the file needs to be modified. The encryption methodologies are interleaved, or alternated, with regard to each block of plaintext. In one illustrative embodiment, Plaintext Block Chaining (PBC) and Cipher Block Chaining (CBC) encryption methodologies are alternated for encrypting a sequence of blocks of data. The encryption of a block of plaintext is dependent upon the plaintext or a cipher generated for the plaintext of a previous block of data in the sequence of blocks of data so that the encryption is more secure than known Electronic Code Book encryption methodologies.

    摘要翻译: 提供了一种用于提供加密文件系统的加密装置和方法。 说明性实施例的加密装置和方法使用加密方法的组合,以便在需要修改文件的情况下减少加密文件系统中的文件所需的解密和重新加密的量。 关于每个明文块,加密方法被交织或交替。 在一个说明性实施例中,替代了明文块链接(PBC)和密码块链接(CBC)加密方法来加密数据块序列。 明文块的加密取决于明文或为数据块序列中的先前数据块的明文生成的密码,使得加密比已知的电子代码簿加密方法更安全。

    Encrypted file system mechanisms
    5.
    发明授权
    Encrypted file system mechanisms 有权
    加密文件系统机制

    公开(公告)号:US08107621B2

    公开(公告)日:2012-01-31

    申请号:US12194610

    申请日:2008-08-20

    IPC分类号: H04L9/14

    摘要: Mechanisms for providing an encrypted file system are provided. The mechanisms use a combination of encryption methodologies so as to reduce the amount of decryption and re-encryption that is necessary to a file in the Encrypted File System in the event that the file needs to be modified. The encryption methodologies are interleaved, or alternated, with regard to each block of plaintext. In one illustrative embodiment, Plaintext Block Chaining (PBC) and Cipher Block Chaining (CBC) encryption methodologies are alternated for encrypting a sequence of blocks of data. The encryption of a block of plaintext is dependent upon the plaintext or a cipher generated for the plaintext of a previous block of data in the sequence of blocks of data so that the encryption is more secure than known Electronic Code Book encryption methodologies.

    摘要翻译: 提供了提供加密文件系统的机制。 这些机制使用加密方法的组合,以便在需要修改文件的情况下减少加密文件系统中的文件所需的解密和重新加密的数量。 关于每个明文块,加密方法被交织或交替。 在一个说明性实施例中,替代了明文块链接(PBC)和密码块链接(CBC)加密方法来加密数据块序列。 明文块的加密取决于明文或为数据块序列中的先前数据块的明文生成的密码,使得加密比已知的电子代码簿加密方法更安全。

    MIGRATION OF VIRTUAL MACHINES
    7.
    发明申请
    MIGRATION OF VIRTUAL MACHINES 有权
    虚拟机的迁移

    公开(公告)号:US20120192182A1

    公开(公告)日:2012-07-26

    申请号:US13356782

    申请日:2012-01-24

    IPC分类号: G06F9/455

    摘要: To migrate two or more virtual machines in a source hypervisor to a target hypervisor, a list of active and connected virtual machines in the source hypervisor is acquired. Connections between the source virtual machines are rerouted to a buffer so that data flowing between the source virtual machines is captured. The source virtual machines are migrated to a target hypervisor and are connected in the same manner as in the source hypervisor. The buffered data is migrated to the respective migrated virtual machines, and the target virtual machines are activated. The virtual machines can be migrated in order of data flow dependency such that the least dependent virtual machine is migrated first.

    摘要翻译: 要将源虚拟机管理程序中的两个或多个虚拟机迁移到目标虚拟机管理程序,将获取源虚拟机管理程序中的活动和连接的虚拟机列表。 源虚拟机之间的连接被重新路由到缓冲区,以便捕获在源虚拟机之间流动的数据。 源虚拟机将迁移到目标管理程序,并以与源虚拟机管理程序相同的方式进行连接。 缓冲的数据将迁移到相应的已迁移虚拟机,并激活目标虚拟机。 可以按照数据流依赖关系的顺序迁移虚拟机,以便首先迁移最不相关的虚拟机。

    Performance Tuning for Software as a Performance Level Service
    8.
    发明申请
    Performance Tuning for Software as a Performance Level Service 有权
    软件性能优化服务的性能调优

    公开(公告)号:US20120047240A1

    公开(公告)日:2012-02-23

    申请号:US12859891

    申请日:2010-08-20

    IPC分类号: G06F15/177 G06F15/173

    CPC分类号: G06F9/5072 G06F11/3409

    摘要: A mechanism is provided for performance tuning for software as a performance level service. At the request of a customer, a cloud provider may use a performance tuning component to determine performance parameters to increase performance of an application running on a given hardware platform. The cloud provider may then generate a tuning configuration and associate the tuning configuration with the customer such that when the cloud provider deploys a customer's software to a partition in a host system, the cloud provider sends the tuning configuration with the deployment package. The performance tuning component at the host system then applies the performance parameters in the tuning configuration to increase performance.

    摘要翻译: 提供了一种机制,用于将性能调整为软件作为性能级别服务。 应客户的要求,云提供商可以使用性能调整组件来确定性能参数,以提高在给定硬件平台上运行的应用程序的性能。 然后,云提供商可以生成调整配置并将调整配置与客户相关联,使得当云提供商将客户的软件部署到主机系统中的分区时,云提供商使用部署包发送调整配置。 主机系统的性能调整组件然后在调谐配置中应用性能参数以提高性能。

    PERSONAL UNIQUE URL ACCESS PROCESSING SYSTEM
    9.
    发明申请
    PERSONAL UNIQUE URL ACCESS PROCESSING SYSTEM 审中-公开
    个人唯一网址访问处理系统

    公开(公告)号:US20110282946A1

    公开(公告)日:2011-11-17

    申请号:US12779971

    申请日:2010-05-14

    IPC分类号: G06F15/16

    CPC分类号: G06Q30/02 G06Q30/00

    摘要: A method, programmed medium and system are provided for sending notice to a website representative whenever a specific and unique website is being accessed by an inquiring party seeking information regarding the website content. Contact information is exchanged between an inquiring party and a website representative and whenever the inquiring party views the unique URL which was provided by the website representative, the website representative is contacted with the inquiring party's phone number in real-time with the information that the inquiring party is now viewing the website.

    摘要翻译: 提供一种方法,编程媒体和系统,用于在寻求有关网站内容的信息的查询方访问特定唯一网站时向网站代表发送通知。 联系方式在询问方和网站代表之间交换,当查询方查看网站代表提供的唯一URL时,网站代理与查询方的电话号码实时联系,询问信息 派对正在浏览网站。

    Write protection of subroutine return addresses
    10.
    发明授权
    Write protection of subroutine return addresses 失效
    写子保护子程序返回地址

    公开(公告)号:US07809911B2

    公开(公告)日:2010-10-05

    申请号:US12263802

    申请日:2008-11-03

    IPC分类号: G06F12/14

    CPC分类号: G06F12/1466

    摘要: Exemplary methods, systems, and products are described that operate generally by moving subroutine return address protection to the processor itself, in effect proving atomic locks for subroutine return addresses stored in a stack, subject to application control. More particularly, exemplary methods, systems, and products are described that write protect subroutine return addresses by calling a subroutine, including storing in a stack memory address a subroutine return address and locking, by a computer processor, the stack memory address against write access. Calling a subroutine may include receiving in the computer processor an instruction to lock the stack memory address. Locking the stack memory address may be carried out by storing the stack memory address in a protected memory lockword. A protected memory lockword may be implemented as a portion of a protected content addressable memory.

    摘要翻译: 描述了通常通过将子程序返回地址保护移动到处理器本身的示例性方法,系统和产品,实际上证明了存储在堆栈中的子程序返回地址的原子锁,在应用程序控制下。 更具体地,描述了示例性方法,系统和产品,其通过调用子程序来写入保护子程序返回地址,包括存储堆栈存储器地址子程序返回地址并由计算机处理器锁定堆栈存储器地址以防写入访问。 调用子程序可以包括在计算机处理器中接收锁定堆栈存储器地址的指令。 锁定堆栈存储器地址可以通过将堆栈存储器地址存储在受保护的存储器锁定字中来执行。 受保护的存储器锁字可以被实现为受保护内容可寻址存储器的一部分。