Encrypting operating system
Abstract
A method of and system for encrypting and decrypting data on a computer system is disclosed. In one embodiment, the system comprises an encrypting operating system (EOS), which is a modified UNIX operating system. The EOS is configured to use a symmetric encryption algorithm and an encryption key to encrypt data transferred from physical memory to secondary devices, such as disks, swap devices, network file systems, network buffers, pseudo file systems, or any other structures external to the physical memory and on which can data can be stored. The EOS further uses the symmetric encryption algorithm and the encryption key to decrypt data transferred from the secondary devices back to physical memory. In other embodiments, the EOS adds an extra layer of security by also encrypting the directory structure used to locate the encrypted data. In a further embodiment a user or process is authenticated and its credentials checked before a file can be accessed, using a key management facility that controls access to one or more keys for encrypting and decrypting data.
Claims
exact text as granted — not AI-modified1 . A kernel within a computer operating system, the kernel to use a unique hardware address to verify a user to control access to an encrypted data file, the kernel comprising a virtual node to decrypt an encrypted directory entry to determine a location of the encrypted data file and to decrypt the encrypted data file.
2 . The kernel of claim 1 , further comprising an encryption engine to encrypt clear data files to generate cipher data files, the encryption engine also to decrypt the cipher data files to generate the clear data files.
3 . (canceled)
4 . The kernel of claim 2 , wherein the encryption engine is to encrypt the clear data files and decrypt the cipher data files according to a symmetric key encryption algorithm.
5 . The kernel of claim 4 , wherein the symmetric key encryption algorithm is based on a block cipher.
6 . The kernel of claim 5 , wherein the symmetric key encryption algorithm comprises Rijndael algorithm.
7 . (canceled)
8 . (canceled)
9 . The kernel of claim 5 , wherein the symmetric key encryption algorithm comprises a DES algorithm.
10 . The kernel of claim 5 , wherein the symmetric key encryption algorithm comprises a Triple-DES algorithm.
11 . The kernel of claim 5 , wherein the symmetric key encryption algorithm comprises an algorithm selected from the group consisting of IDEA, Blowfish, Twofish, and CAST-128.
12 . The kernel of claim 1 , wherein the kernel computer operating system comprises a UNIX operating system.
13 . The kernel of claim 12 , wherein the UNIX operating system is a System V-Revision.
14 . (canceled)
15 . The kernel of claim 14 , further comprising an encryption key management system, the encryption key management system controls access to the encrypted data file.
16 . (canceled)
17 . The kernel of claim 15 , wherein the encryption key management system to stores an encrypted data file name, wherein the data file name is associated with encrypted file contents.
18 . The kernel of claim 17 , wherein the encryption key management system also grants access to a data file if a corresponding access permission of the data file is a predetermined value.
19 - 24 . (canceled)
25 . The kernel of claim 17 , wherein the encryption key management system also encrypts a pathname to the encrypted data file, and decrypts the pathname to the encrypted data file when retrieving the encrypted data file.
26 . A computer system comprising:
a. a first device having an operating system kernel to encrypt clear data using an encryption key to generate cipher data, and to decrypt the cipher data using the encryption key to generate the clear data; b. a key generator to generate one or more encryption keys usable for encrypting and decrypting data on the computer system; and c. a second device coupled to the first device to exchange cipher data with the first device.
27 . The computer system of claim 26 , wherein the operating system kernel encrypts the clear data and decrypts the cipher data using a symmetric algorithm.
28 . The computer system of claim 27 , wherein the symmetric algorithm comprises a block cipher.
29 . The computer system of claim 28 , wherein the block cipher comprises a Rijndael algorithm.
30 . (canceled)
31 . The computer system of claim 26 , wherein the second device comprises a backing store.
32 . The computer system of claim 26 , wherein the second device comprises a swap device.
33 . The computer system of claim 26 , wherein the second device forms part of a communications channel.
34 . The computer system of claim 33 , wherein the communications channel comprises a network.
35 . The computer system of claim 34 , wherein the network comprises the Internet.
36 - 58 . (canceled)
59 . A method comprising:
using, within a kernel of a computer operating system, a unique hardware address to verify a user to control access to an encrypted data file; decrypting an encrypted directory entry to determine a location of the encrypted data file; and decrypting the encrypted data file.Join the waitlist — get patent alerts
Track US2015372806A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.