-
公开(公告)号:US09891969B2
公开(公告)日:2018-02-13
申请号:US15054699
申请日:2016-02-26
发明人: Kwanghwan Moon , Peng Ning , Geng Chen , Sangwoo Ryu , S J Oh , Sami Orava , KyungBae Park
CPC分类号: G06F9/545 , G06F21/44 , G06F21/602 , G06F21/6281 , G06F21/72 , G06F21/73 , H04L9/0819 , H04L9/088 , H04L9/0894 , H04L2209/80
摘要: An apparatus and a method for encrypting and decrypting data in a device are provided. The apparatus includes a processor and a memory. The processor is configured to transmit a data command from an application to an encryption driver that executes in a kernel space, determine if the application is authenticated to perform the data command based on an access policy, transmit, when the application is authenticated, a first key to a cryptographic library that executes in an application space, and perform the data command based on the first key after receiving a response via the cryptographic library. The first key is stored in an encryption driver in the kernel space and is not available to applications in the application space.