System and method for safeguarding data between a device driver and a device
Abstract
A data safeguarding system, method, and article for safeguarding an encrypted data-stream transmitting on a first channel from a first system to a second system. The data-stream can be intertwined with other data-streams. The data-stream is arranged in fixed length sequential blocks, each block including a header portion and a payload portion. The first system places a flag marking in the header portion indicating that the payload includes a tag having at least one identifier for selecting the decryption keys from the first system. The second system reads the flag, and if the flag indicates a tag portion, reads the tag portion. The second system transmits the identifier to the first system on a second channel. The first system reads the identifier, retrieves the keys, and transmits the decryption keys to the second system on the second channel. The second system receives the decryption keys and decrypts the data block using the decryption keys.
Claims
exact text as granted — not AI-modified1 . A method comprising:
receiving a data stream from a source device, by a sending system, the data stream comprising a sequence of data blocks, wherein each data block comprises a header and a payload; the sending system negotiating with each of at least one application decoder to generate a session key shared between the sending system and the at least one application decoder, each session key to encrypt at least a decryption key; for each data block, encrypting a payload by the sending system, the payload corresponding to the each data block, the encryption using at least one key; the sending system storing a portion of the encrypted payload to be transmitted later to the application decoder, wherein the stored portion is one of an encrypted portion and an unencrypted portion; the sending system replacing the stored portion of the encrypted payload with a tag, the tag identifying the data stream and a source of the data stream; the sending system setting a flag in a header of the data block corresponding to the encrypted payload, the flag indicating that (a) at least one of said payload is encrypted and (b) said payload includes the tag; and transmitting by the sending system each of the data blocks to an appropriate one of the at least one application decoder.
2 . The method as recited in claim 1 , wherein the sending system comprises a protected content exchange (PCX) module having at least one decryptor, a protocol specific registration engine, at least one encryptor, and a negotiator.
3 . The method as recited in claim 1 , wherein each of the at least one application decoders use a different session key.
4 . The method as recited in claim 1 , wherein the data stream identifier references an encryption key and the saved portion of the payload.
5 . The method as recited in claim 1 , wherein each of the data blocks is transmitted via a first transmission channel and negotiating is via at least one separate second transmission channel.
6 . The method as recited in claim 5 , wherein negotiating from said sending system to said receiving system, comprises transmitting of non-data block information including (a) at least one key selected from the group of session keys, encryption keys and decryption keys, (b) the portion of the encrypted payload to be transmitted later from the sending system to said receiving system, and (c) a datum that identifies a data-stream that includes the data block.
7 . The method as recited in claim 1 , further comprising determining, for each data block, by a device specific driver, to which of the at least one application decoders the data block should be sent based on a protocol specific to the data block.
8 . A machine readable medium having instructions that when executed cause the machine to:
receive a data stream from a source device the data stream comprising a sequence of data blocks, wherein each data block comprises a header and a payload; negotiate with each of at least one application decoder to generate a session key shared between the sending system and the at least one application decoder, each session key to encrypt at least a decryption key; for each data block, encrypt a payload, the payload corresponding to the each data block, the encryption using at least one key; store a portion of the encrypted payload to be transmitted later to the application decoder, wherein the stored portion is one of an encrypted portion and an unencrypted portion; replace the stored portion of the encrypted payload with a tag, the tag identifying the data stream and a source of the data stream; set a flag in a header of the data block corresponding to the encrypted payload, the flag indicating that (a) at least one of said payload is encrypted and (b) said payload includes the tag; and transmit each of the data blocks to an appropriate one of the at least one application decoder.
9 . The medium as recited in claim 8 , wherein the machine comprises a protected content exchange (PCX) module having at least one decryptor, a protocol specific registration engine, at least one encryptor, and a negotiator.
10 . The medium as recited in claim 8 , wherein each of the at least one application decoders use a different session key.
11 . The medium as recited in claim 8 , wherein the data stream identifier references an encryption key and the saved portion of the payload.
12 . The medium as recited in claim 8 , wherein each of the data blocks is transmitted via a first transmission channel and negotiating is via at least one separate second transmission channel.
13 . The medium as recited in claim 12 , wherein negotiating from said machine to said receiving system, comprises transmitting of non-data block information including (a) at least one key selected from the group of session keys, encryption keys and decryption keys, (b) the portion of the encrypted payload to be transmitted later from the sending system to said receiving system, and (c) a datum that identifies a data-stream that includes the data block.
14 . The medium as recited in claim 8 , further comprising instructions that when executed cause a device specific driver to determine, for each data block, to which of the at least one application decoders the data block should be sent based on a protocol specific to the data block.
15 . A system for safeguarding protocol-specific data within a device, comprising:
a first transmission channel to transmit at least one protocol specific encrypted data stream; at least one protected content exchange (PCX) device configured to translate the at least one protocol specific encrypted data stream into a PCX encrypted data stream; and at least one application decoder configured to decode the PCX encrypted data stream, the decoded PCX data stream comprising a plurality of data blocks each data block having a header and a payload, wherein the at least one PCX device comprises:
at least one protocol specific registration engine configured to register the at least one application decoder,
at least one negotiator configured to negotiate at least one content decoder key for the at least one application decoder, the negotiator using a second transmission channel to communicate non-data block data between the PCX device and the at least one application decoder,
at least one decryptor configured to decrypt the at least one protocol specific encrypted data stream,
at least one encryptor configured to encrypt at least a portion of the decrypted data stream using the at least one decoder key to produce at least one re-encrypted data stream,
a payload replacement module to replace a portion of a payload of the data block with a tag data that indicates at least one key for the data block in the PCX device,
a header flag setting module that sets a flag in a header of the data block when the data block includes the tag, and
a data-stream sending module that sends a data-stream, the data stream including the data block, to the at least one application decoder after the header flag setting module sets the flag and the encryptor encrypts the data stream and the payload replacement module replaces the portion of a payload.
16 . The system as recited in claim 15 , the negotiator further configured to negotiate with each of at least one application decoder to generate a session key shared between the PCX device and the at least one application decoder, each session key to encrypt at least a content decoder key; wherein each of the at least one application decoders use a different session key.
17 . The system as recited in claim 16 , the negotiator further configured to negotiate at least one content channel encryption key with at least one protocol specific device, the at least one protocol specific device to send the at least one protocol specific data stream, the content channel encryption key to be used by the decryptor to decrypt the at least one protocol specific encrypted data stream.Join the waitlist — get patent alerts
Track US2005254645A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.