Systems, methods, and devices for encrypted data management
Abstract
Key management for and automount of encrypted files, including recovering a master vault key file from an encoded vault key file, storing the vault key file within a previously mounted crypto key management virtual drive so as to provide a secure scratch pad area for temporary storage of the master vault key file. An open and mount module may then invoke a file mounting procedure by providing the vault key file name and a path corresponding to the crypto key management virtual drive to a virtual drive mounting module. The method of passing the vault key file to the file mounting utility module may comprise passing command line arguments equal to a pathname and filename to the file mounting utility.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A method comprising:
recovering a vault key file from an encoded vault key file; storing the vault key file within a crypto-key-management virtual drive; executing an encrypted virtual drive file mounting utility and passing the vault key file to the file mounting utility via the crypto-key-management virtual drive.
2 . The method of claim 1 wherein the encoded vault key file is obtained from a personal key device.
3 . The method of claim 1 wherein recovering a vault key file comprises:
obtaining a password;
generating a hash value from the password; and,
obtaining the vault key file by decoding the encoded vault key file using the hash value.
4 . The method of claim 3 wherein the password is obtained from the crypto-key management virtual drive.
5 . The method of claim 1 wherein passing the vault key file to the file mounting utility comprises passing an argument equal to a pathname and filename to the file mounting utility, wherein the pathname includes the crypto-key management virtual drive.
6 . A method comprising:
initiating, on a computer system, generation of a personal key file for storage on a portable cryptographic key storage device in communication with the computer system; obtaining a vault key file corresponding to an encrypted virtual drive file; receiving personal password data; generating an encoded vault key file by encoding the vault key file with the personal password data; storing the encoded vault key on a portable cryptographic key storage device.
7 . The method of claim 6 wherein the cryptographic key storage device is a USB drive, a mobile phone, or a biometric authentication device;
8 . The method of claim 6 wherein generating an encoded vault key file is done by generating a hash value from the personal password data and encrypting the vault key file using the hash value.
9 . The method of claim 6 wherein the vault key file is also encoded with a serial number of the cryptographic key storage device.
10 . The method of claim 6 wherein the vault key file is also encoded with a read-write indicator parameter.
11 . The method of claim 6 wherein the encoded vault key file is stored in a directory corresponding to a read-write parameter value.
12 . The method of claim 6 wherein obtaining a vault key file comprises identifying a master cryptographic key storage device, and reading the vault key file from the master device.
13 . An apparatus comprising:
a key-management module configured to obtain an encoded vault key file from a personal key device and to generate a vault key file from the encoded vault key file and to store the vault key file within a crypto-key-management virtual drive; a drive-mounting module configured to generate virtual drive mounting parameters and to pass the virtual drive mounting parameters to an encrypted virtual drive file mounting utility wherein the virtual drive mounting parameters include a filename of the vault key file stored in the crypto-key-management virtual drive.
14 . The apparatus of claim 13 further wherein the key-management module is configured to obtain the encoded vault key file from a personal key device.
15 . The apparatus of claim 13 wherein the key-management module is further configured to:
obtain a password;
generate a hash value from the password; and,
obtain the vault key file by decoding the encoded vault key file using the hash value.
16 . The apparatus of claim 15 wherein key-management module is configured to obtain the password from the crypto-key management virtual drive.Join the waitlist — get patent alerts
Track US2016041929A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.