会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • System and method for securely initializing and booting a security appliance
    • 用于安全地初始化和引导安全设备的系统和方法
    • US08116455B1
    • 2012-02-14
    • US11540300
    • 2006-09-29
    • Robert Jan SusslandAnanthan SubramanianLawrence Wen-Hao Chang
    • Robert Jan SusslandAnanthan SubramanianLawrence Wen-Hao Chang
    • H04L9/00H04L9/08H04L9/14H04L29/06
    • H04L9/0822G06F21/575H04L9/3234H04L63/06
    • A system and method provides for secure initialization and booting of a security appliance. The security appliance cooperates with a “smart” system card to provide cryptographic information needed to boot the security appliance in accordance with a secure boot procedure. The initialization procedure commences once the security appliance detects the presence of the smart card. The smart card and an encryption processor perform an authentication and key exchange procedure to establish a secure communication channel between them. The system card then loads a twice wrapped master key from a configuration database and decrypts the master key using a key associated with the system card. The wrapped master key is then forwarded via the secure communication channel to the encryption processor, which decrypts the wrapped key using a key associated therewith and enters an operating state using the decrypted master key.
    • 系统和方法提供安全设备的安全初始化和启动。 安全设备与“智能”系统卡协同工作,以根据安全启动过程提供引导安全设备所需的加密信息。 一旦安全设备检测到智能卡的存在,则初始化过程开始。 智能卡和加密处理器执行认证和密钥交换过程以在它们之间建立安全的通信信道。 然后,系统卡从配置数据库加载两次包装的主密钥,并使用与系统卡相关联的密钥解密主密钥。 然后将包裹的主密钥通过安全通信信道转发到加密处理器,加密处理器使用与之相关联的密钥对包裹的密钥进行解密,并使用解密的主密钥进入操作状态。
    • 2. 发明授权
    • System and method for efficiently deleting a file from secure storage served by a storage system
    • 用于从存储系统服务的安全存储中有效地删除文件的系统和方法
    • US08397083B1
    • 2013-03-12
    • US11508430
    • 2006-08-23
    • Robert Jan SusslandLawrence Wen-Hao ChangAnanthan Subramanian
    • Robert Jan SusslandLawrence Wen-Hao ChangAnanthan Subramanian
    • H04L29/06
    • H04L67/1097H04L9/0894H04L63/0478H04L63/062H04L63/102H04L2463/062
    • A system and method efficiently deletes a file from secure storage, i.e., a cryptainer, served by a storage system. The cryptainer is configured to store a plurality of files, each of which stores an associated file key within a special metadata portion of the file. Notably, special metadata is created by a security appliance coupled to the storage system and attached to each file to thereby create two portions of the file: the special metadata portion and the main, “file data” portion. The security appliance then stores the file key within the specially-created metadata portion of the file. A cryptainer key is associated with the cryptainer. Each file key is used to encrypt the file data portion within its associated file and the cryptainer key is used to encrypt the part of the special metadata portion of each file. To delete the file from the cryptainer, the file key of the file is deleted and the special metadata portions of all other files stored in the cryptainer are re-keyed using a new cryptainer key. Thereafter, the “old” cryptainer key is deleted.
    • 系统和方法从存储系统服务的安全存储(即,密码器)中有效地删除文件。 密码器被配置为存储多个文件,每个文件在文件的特殊元数据部分内存储相关联的文件密钥。 值得注意的是,由耦合到存储系统并附着到每个文件的安全设备创建特殊元数据,从而创建文件的两个部分:特殊元数据部分和主文件数据部分。 然后,安全设备将文件密钥存储在文件的特殊创建的元数据部分中。 一个密码密钥与密码子相关联。 每个文件密钥用于加密其关联文件中的文件数据部分,并且密码密钥用于加密每个文件的特殊元数据部分的一部分。 要从cryptainer中删除文件,文件的文件密钥将被删除,并且使用新的密码密钥重新键入存储在cryptainer中的所有其他文件的特殊元数据部分。 此后,旧的密码键被删除。
    • 3. 发明授权
    • System and method for establishing a shared secret among nodes of a security appliance
    • 在安全设备的节点之间建立共享密钥的系统和方法
    • US07958356B1
    • 2011-06-07
    • US11540441
    • 2006-09-29
    • Ananthan SubramanianRobert Jan SusslandLawrence Wen-Hao Chang
    • Ananthan SubramanianRobert Jan SusslandLawrence Wen-Hao Chang
    • H04L9/32H04L9/00H04L9/08H04L9/12
    • H04L9/0841
    • A system and method securely establishes a shared secret among nodes of a security appliance. The shared secret is established by distributing private keys among the nodes in accordance with a node ring protocol that uses a predetermined encryption algorithm to generate messages containing the keys. Briefly, each node is initially notified as to the number of nodes participating in the shared secret establishment. Each node generates a public-private key-pair, as well as a first message that includes the generated public key and an indication of the source of the generated public key (hereinafter “source generated public key”). The node then sends the first message to an adjacent node of the appliance. Upon receiving the first message, each node extracts the source generated public key from the message and stores the extracted information into a data structure of “partner” public keys. The protocol then continues with each node generating additional messages equal to the number of participating nodes minus one. At that point, each node combines its private key with its partner public keys stored in the data structure to generate a value that is common among all of the participating nodes. This common value is then used to derive the shared secret.
    • 系统和方法在安全设备的节点之间安全地建立共享秘密。 通过根据使用预定加密算法的节点环协议来分发节点之间的私钥以生成包含密钥的消息来建立共享秘密。 简而言之,每个节点最初被通知参与共享秘密机构的节点数量。 每个节点生成公共 - 私人密钥对,以及包括生成的公钥的第一消息和所生成的公钥的源的指示(以下称为“源生成的公钥”)。 节点然后将第一个消息发送到设备的相邻节点。 在接收到第一消息时,每个节点从消息中提取源生成的公钥,并将提取的信息存储到“伙伴”公钥的数据结构中。 然后,该协议继续,每个节点产生等于参与节点数减去1的附加消息。 此时,每个节点将其私有密钥与存储在数据结构中的伙伴公钥相结合,以生成在所有参与节点中共同的值。 然后使用这个常用值来导出共享密钥。