会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • Method and system for providing data security in a file system monitor with stack positioning
    • 用于在堆栈定位的文件系统监视器中提供数据安全性的方法和系统
    • US07103783B1
    • 2006-09-05
    • US09701201
    • 2000-09-29
    • George FriedmanRobert Phillip StarekCarlos A. Murdock
    • George FriedmanRobert Phillip StarekCarlos A. Murdock
    • H04L9/00G06F11/30G06F13/28G06F3/02G06F15/173G06F15/16
    • G06F21/6281
    • A System for providing data security in a first device driver operably installed in a computer operating system having a layered plurality of device drivers (81, 82, 83, 84) for accessing data in a data storage device. The first device driver detects an I/O request, and determines whether the first device driver is functionally uppermost in the layered plurality of device drivers. If the first device driver is functionally uppermost in the layered plurality of device drivers, the method performs the I/O request (80) in the first device driver. If the device driver is not functionally uppermost in the layered plurality of device drivers, the method denies the I/O request in the first device driver, and allows the I/O request to be performed by the next lowest-level driver in the layered plurality of device drivers.
    • 一种用于在可操作地安装在具有用于访问数据存储设备中的数据的分层多个设备驱动器(81,82,83,84)的计算机操作系统中的第一设备驱动器中提供数据安全性的系统。 第一设备驱动程序检测I / O请求,并且确定第一设备驱动程序在分层的多个设备驱动程序中是否在功能上最上方。 如果第一设备驱动器在分层的多个设备驱动器中在功能上最上方,则该方法在第一设备驱动器中执行I / O请求(80)。 如果设备驱动程序在分层多个设备驱动程序中功能上不是最上方,则该方法拒绝第一设备驱动程序中的I / O请求,并允许I / O请求由分层的下一级驱动程序执行 多个设备驱动程序。
    • 5. 发明授权
    • Shared memory blocking method and system
    • 共享内存阻塞方法和系统
    • US06553466B1
    • 2003-04-22
    • US09701202
    • 2000-11-27
    • George FriedmanRobert Phillip StarekCarlos A. Murdock
    • George FriedmanRobert Phillip StarekCarlos A. Murdock
    • G06F1214
    • G06F9/5016G06F12/109G06F12/1458G06F21/6281Y10S707/99938
    • A shared memory blocking method and particularly applicable to a system in which protected data is transmitted to a recipient computer. The method comprises reserving a memory page for a requesting application, committing a memory page to the requesting application's address space, which call may be made by the process providing the page reserve call or by a subsequent process, and providing security checks to complete the requests. The security checks include determining whether the process is secured by consulting a secured process list and determining whether the page is shared by consulting a shared memory list. Further disclosed are a computer readable medium and computer programmed to block shared memory, shared memory blocking system and secured data transmission system.
    • 一种共享存储器阻塞方法,特别适用于将受保护数据传输到接收计算机的系统。 该方法包括为请求应用预留存储器页面,将存储器页面提交给请求应用程序的地址空间,可以由提供页面预留调用的处理或通过后续处理进行哪个调用,并提供安全检查以完成请求 。 安全检查包括通过咨询安全的进程列表来确定进程是否被保护,并且通过咨询共享的存储器列表来确定页面是否被共享。 还公开了一种计算机可读介质和被编程为阻止共享存储器,共享存储器阻塞系统和安全数据传输系统的计算机。
    • 8. 发明授权
    • Method and apparatus for real-time secure file deletion
    • 用于实时安全文件删除的方法和装置
    • US06314437B1
    • 2001-11-06
    • US09576518
    • 2000-05-23
    • Robert Phillip StarekGeorge FriedmanDavid Earl MarshallJason Lee ChambersMichael J. MoormanTerry S. Newgard
    • Robert Phillip StarekGeorge FriedmanDavid Earl MarshallJason Lee ChambersMichael J. MoormanTerry S. Newgard
    • G06F1730
    • G06F17/30117G06F2221/2143Y10S707/99953Y10S707/99957
    • A method and apparatus are provided that enhance file system calls to a file system structure of an operating system. In particular, file system calls can be enhanced to provide real-time secure file deletion on an ongoing basis. A file system call that is intended to perform a function with respect to data stored on a storage device is intercepted. It is then determined whether the file system call is of a type that should be processed. If not, the original file system call is passed on through the file system. If the file system call should be processed, supplemental processing is performed to enhance the original file system call and the file system call is transparently returned to the calling system application. In embodiment, real-time secure file deletion is implemented using a vendor supplied driver (VSD) executing within the installable file system (IFS) of WINDOWS 95. Further, a method and system are disclosed for real-time secure data deletion in a system having an NTFS file system. Read calls are monitored using a read filter and pointers to NTFS metafiles and page files are recognized and stored. Write calls are monitored using a write filter and real-time secure data deletion of buffers is performed. File creation operations are monitored and real-time secure data deletion of user files is performed when the file is to be overwritten. Further, set information operations are monitored and real-time secure data deletion is performed for truncated, shrunk or deleted user files.
    • 提供了一种增强对操作系统的文件系统结构的文件系统调用的方法和装置。 特别地,可以增强文件系统调用以持续提供实时安全文件删除。 用于执行关于存储在存储设备上的数据的功能的文件系统调用被截取。 然后确定文件系统调用是否是应该被处理的类型。 如果没有,原始文件系统调用将通过文件系统传递。 如果要处理文件系统调用,则执行补充处理以增强原始文件系统调用,并且将文件系统调用透明地返回给调用系统应用程序。 在实施例中,使用在WINDOWS 95的可安装文件系统(IFS)内执行的供应商提供的驱动程序(VSD)来实现实时安全文件删除。此外,公开了一种用于系统中的实时安全数据删除的方法和系统 具有NTFS文件系统。 使用读取过滤器监视读取调用,并指向NTFS元文件,并识别和存储页面文件。 使用写入过滤器监视写入呼叫,并执行缓冲区的实时安全数据删除。 监视文件创建操作,并在文件被覆盖时执行用户文件的实时安全数据删除。 此外,监视设置信息操作,并对被截断,缩小或删除的用户文件执行实时安全数据删除。
    • 10. 发明授权
    • Method and apparatus for real-time secure file deletion
    • 用于实时安全文件删除的方法和装置
    • US6070174A
    • 2000-05-30
    • US114756
    • 1998-07-13
    • Robert Phillip StarekGeorge FriedmanDavid Earl MarshallJason Lee ChambersMichael J. MoormanTerry S. Newgard
    • Robert Phillip StarekGeorge FriedmanDavid Earl MarshallJason Lee ChambersMichael J. MoormanTerry S. Newgard
    • G06F17/30
    • G06F17/30117G06F2221/2143Y10S707/99953Y10S707/99957
    • A method and apparatus are provided that enhance file system calls to a file system structure of an operating system. In particular, file system calls can be enhanced to provide real-time secure file deletion on an ongoing basis. A file system call that is intended to perform a function with respect to data stored on a storage device is intercepted. It is then determined whether the file system call is of a type that should be processed. If not, the original file system call is passed on through the file system. If the file system call should be processed, supplemental processing is performed to enhance the original file system call and the file system call is transparently returned to the calling system application. In embodiment, real-time secure file deletion is implemented using a vendor supplied driver (VSD) executing within the installable file system (IFS) of WINDOWS 95. Further, a method and system are disclosed for real-time secure data deletion in a system having an NTFS file system. Read calls are monitored using a read filter and pointers to NTFS metafiles and page files are recognized and stored. Write calls are monitored using a write filter and real-time secure data deletion of buffers is performed. File creation operations are monitored and real-time secure data deletion of user files is performed when the file is to be overwritten. Further, set information operations are monitored and real-time secure data deletion is performed for truncated, shrunk or deleted user files.
    • 提供了一种增强对操作系统的文件系统结构的文件系统调用的方法和装置。 特别地,可以增强文件系统调用以持续提供实时安全文件删除。 用于执行关于存储在存储设备上的数据的功能的文件系统调用被截取。 然后确定文件系统调用是否是应该被处理的类型。 如果没有,原始文件系统调用将通过文件系统传递。 如果要处理文件系统调用,则执行补充处理以增强原始文件系统调用,并且将文件系统调用透明地返回给调用系统应用程序。 在实施例中,使用在WINDOWS 95的可安装文件系统(IFS)内执行的供应商提供的驱动程序(VSD)实现实时安全文件删除。此外,公开了一种用于系统中的实时安全数据删除的方法和系统 具有NTFS文件系统。 使用读取过滤器监视读取调用,并指向NTFS元文件,并识别和存储页面文件。 使用写入过滤器监视写入呼叫,并执行缓冲区的实时安全数据删除。 监视文件创建操作,并在文件被覆盖时执行用户文件的实时安全数据删除。 此外,监视设置信息操作,并对被截断,缩小或删除的用户文件执行实时安全数据删除。