US2015019881A1PendingUtilityA1

Accelerated cryptography with an encryption attribute

Assignee: INTEL CORPPriority: Sep 4, 2008Filed: Sep 30, 2014Published: Jan 15, 2015
Est. expirySep 4, 2028(~2.1 yrs left)· nominal 20-yr term from priority
Inventors:Yen Hsiang Chew
G06F 21/62H04L 9/0825G06F 21/6209G06F 9/06G06F 21/00H04L 9/14
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and systems for encrypting and decrypting are presented. In one embodiment, the method comprises encrypting one or more segments of a data with a key. The data is associated with at least one encryption attribute and having a plurality of segments. The encryption attribute includes information to identify one or more segments of the data to encrypt. The method further comprises encrypting the encryption attribute and storing the data including the partly encrypted data and the encrypted encryption attribute.

Claims

exact text as granted — not AI-modified
1 - 54 . (canceled) 
     
     
         55 . A method comprising:
 encrypting one or more segments of first data with a first key, and lowering overall encryption time by selectively encrypting the one or more segments of a plurality of segments of the first data associated with an encryption attribute, wherein the encryption attribute to identify the one or more segments of the plurality of segments based on one or more rules describing each of the one or more segments as candidates for encryption;   encrypting the encryption attribute with a second key to create an encrypted encryption attribute; and   storing at least a part of second data, wherein the second data includes partly encrypted data and the encrypted encryption attribute.   
     
     
         56 . The method of  claim 55 , further comprising encrypting the first key via the second key, wherein the second data further includes an encrypted version of the first key, wherein the first key includes a symmetric encryption key, and the second key includes a public key. 
     
     
         57 . The method of  claim 55 , wherein the one or more segments of the plurality of segments are further based on a set of numbers corresponding to the one or more segments, an identifier corresponding to the one or more rules, and a pointer to a location storing the one or more rules. 
     
     
         58 . The method of  claim 55 , wherein the encryption attribute is based on a file type of the data or a categorization of the data, and wherein the encryption attribute comprises a user-defined attribute or a default setting that is modifiable by a user, wherein the encryption attribute is associated with a file to identify the two or more segments of the file that are to be subsequently encrypted during the encryption process, wherein the encryption attribute is set to a setting based on a category or a file type to protect unauthorized usages such that the two or more segments include one or more of headers of the file, segments of important parts of the file, and alternate N segments of the file. 
     
     
         59 . The method of  claim 55 , wherein each segment of the plurality of segments is M-bit in length such that the length is equal to one of block sizes of an M-bit encryption engine, and wherein each segment is processed by the M-bit encryption engine. 
     
     
         60 . At least one machine-readable medium comprising instructions which, when accessed by a processing device, causes the processing device to perform one or more operations comprising:
 encrypting one or more segments of first data with a first key, and lowering overall encryption time by selectively encrypting the one or more segments of a plurality of segments of the first data associated with an encryption attribute, wherein the encryption attribute to identify the one or more segments of the plurality of segments based on one or more rules describing each of the one or more segments as candidates for encryption;   encrypting the encryption attribute with a second key to create an encrypted encryption attribute; and   storing at least a part of second data, wherein the second data includes partly encrypted data and the encrypted encryption attribute.   
     
     
         61 . The machine-readable medium of  claim 60 , wherein the one or more operations further comprise encrypting the first key via the second key, wherein the second data further includes an encrypted version of the first key, wherein the first key includes a symmetric encryption key, and the second key includes a public key. 
     
     
         62 . The machine-readable medium of  claim 60 , wherein the one or more segments of the plurality of segments are further based on a set of numbers corresponding to the one or more segments, an identifier corresponding to the one or more rules, and a pointer to a location storing the one or more rules. 
     
     
         63 . The machine-readable medium of  claim 60 , wherein the encryption attribute is based on a file type of the data or a categorization of the data, and wherein the encryption attribute comprises a user-defined attribute or a default setting that is modifiable by a user, wherein the encryption attribute is associated with a file to identify the two or more segments of the file that are to be subsequently encrypted during the encryption process, 
     
     
         64 . The machine-readable medium of  claim 63 , wherein the encryption attribute is set to a setting based on a category or a file type to protect unauthorized usages such that the two or more segments include one or more of headers of the file, segments of important parts of the file, and alternate N segments of the file. 
     
     
         65 . The machine-readable medium of  claim 60 , wherein each segment of the plurality of segments is M-bit in length such that the length is equal to one of block sizes of an M-bit encryption engine, and wherein each segment is processed by the M-bit encryption engine, and
 wherein the one or more segments comprise at least one segment of N segments of partly encrypted data, wherein N represents a positive integer.   
     
     
         66 . The machine-readable medium of  claim 60 , wherein the one or more operations further comprise receiving a request to encrypt the first data, wherein the first data includes the plurality of segments. 
     
     
         67 . A system comprising:
 a first encryption engine to encrypt one or more segments of first data with a first key, and lowering overall encryption time by selectively encrypting the one or more segments of a plurality of segments of the first data associated with an encryption attribute, wherein the encryption attribute to identify the one or more segments of the plurality of segments based on one or more rules describing each of the one or more segments as candidates for encryption;   a second encryption engine to encrypt the encryption attribute with a second key to create an encrypted encryption attribute; and   a storage medium to store at least a part of second data, wherein the second data includes partly encrypted data and the encrypted encryption attribute.   
     
     
         68 . The system of  claim 67 , further comprises a third encryption engine to encrypt the first key via the second key, wherein the second data further includes an encrypted version of the first key, wherein the first key includes a symmetric encryption key, and the second key includes a public key. 
     
     
         69 . The system of  claim 67 , wherein the one or more segments of the plurality of segments are further based on a set of numbers corresponding to the one or more segments, an identifier corresponding to the one or more rules, and a pointer to a location storing the one or more rules. 
     
     
         70 . The system of  claim 67 , wherein the encryption attribute is based on a file type of the data or a categorization of the data, and wherein the encryption attribute comprises a user-defined attribute or a default setting that is modifiable by a user, wherein the encryption attribute is associated with a file to identify the two or more segments of the file that are to be subsequently encrypted during the encryption process, 
     
     
         71 . The system of  claim 70 , wherein the encryption attribute is set to a setting based on a category or a file type to protect unauthorized usages such that the two or more segments include one or more of headers of the file, segments of important parts of the file, and alternate N segments of the file. 
     
     
         72 . The system of  claim 67 , wherein each segment of the plurality of segments is M-bit in length such that the length is equal to one of block sizes of an M-bit encryption engine, and wherein each segment is processed by the M-bit encryption engine, and
 wherein the one or more segments comprise at least one segment of N segments of partly encrypted data, wherein N represents a positive integer.   
     
     
         73 . The system of  claim 67 , further comprising a controller to receive a request to encrypt the first data, wherein the first data includes the plurality of segments. 
     
     
         74 . A system comprising:
 a first decryption engine to decrypt one or more segments of first data with a first key, the first data including an encrypted encryption attribute, wherein the encryption attribute to identify the one or more segments of the plurality of segments based on one or more rules describing each of the one or more segments as candidates for encryption; and   a second decryption engine to decrypt the encryption attribute with a second key to create an encrypted encryption attribute.   
     
     
         75 . The system of  claim 74 , further comprising a controller to access the first data with the first key, the first data including a plurality of segments having the one or more segments. 
     
     
         76 . The system of  claim 74 , further comprising a third decryption engine to decrypt an encryption version of a second key with the first key, wherein the first data further includes the second key, wherein the second key includes a symmetric encryption key, and the first key includes a private key. 
     
     
         77 . The system of  claim 74 , wherein the one or more segments comprise at least one segment of N segments of partly encrypted data, wherein N represents a positive integer.

Join the waitlist — get patent alerts

Track US2015019881A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.