US2016342798A1PendingUtilityA1
Protected device management
Est. expiryDec 21, 2029(~3.4 yrs left)· nominal 20-yr term from priority
G06F 21/602G06F 3/0671G06F 3/0623G06F 3/0632H04L 63/083H04L 63/18H04L 63/08G06F 2221/2149H04L 63/0807G06F 2221/2147G06F 21/85G06F 21/305H04L 9/0894G06F 21/78H04L 9/321H04L 9/32G06F 21/74
54
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method, apparatus, system, and computer program product for management of storage devices protected by encryption, user authentication, and password protection and auditing schemes in virtualized and non-virtualized environments.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method comprising:
identifying an auditable event being performed in a secure partition of a system, wherein the secure partition is isolated from a host operating system of the system; generating an audit event record for the auditable event; and writing the audit event record to an audit log, wherein the audit log is isolated from the host operating system.
2 . The method of claim 2 wherein
the audit log is a first audit log of a plurality of audit logs,
the plurality of audit logs is accessible only from within the secure partition, and
each audit log of the plurality of audit logs is isolated from the host operating system; and the method further comprises:
determining whether the first audit log is available;
sending the audit event record to a first audit subsystem associated with the first audit log if the first audit log is available, wherein the first audit subsystem performs writing the audit event record to the first audit log; and
sending the audit event record to a second audit subsystem associated with a second audit log of the plurality of audit logs if the first audit log is not available, wherein the second audit subsystem performs writing the audit event record to the second audit log.
3 . The method of claim 1 , further comprising:
authenticating first credentials of a user of the system before access is allowed to any device of a plurality of devices attached to the system; intercepting an event indicating attachment of a new device to the system, wherein the intercepting is performed by the secure partition of the system; requesting second credentials to access the new device, wherein the second credentials are requested without booting the system; authenticating the second credentials; enabling access to the new device after authenticating the second credentials; and
delivering a hot plug event for the new device to the host operating system.
4 . The method of claim 3 , wherein
requesting the second credentials to access the new device comprises using trusted path connections to a display device to display a request for the second credentials and a user input device to receive the second credentials.
5 . The method of claim 3 , wherein enabling access to the new device comprises using a native command for the device to enable decryption of the new device.
6 . The method of claim 3 , wherein:
the second credentials comprise a password for the new device; and
enabling access to the new device comprises using the password to unlock the new device.
7 . The method of claim 3 , wherein:
the second credentials comprise a user identifier; and enabling access to the new device comprises providing the user identifier to a trusted third party and enabling access to the new device if the trusted third party authenticates the user identifier.
8 . A computer-implemented method comprising:
receiving a request to service an audit log from a secure partition of a requesting system, wherein the secure partition is isolated from a host operating system of the requesting system, the audit log contains an audit event record of an auditable event performed in the secure partition, and the audit log is isolated from the host operating system of the requesting system; establishing a secure communication channel with the secure partition; and servicing the audit log via the secure communication channel.
9 . The method of claim 8 , wherein the secure communication channel is established between a trusted remote console and the secure partition, and the method further comprises:
receiving a request to unlock an encrypted device coupled to the requesting system, wherein the request is received by the secure partition via the secure communication channel; and unlocking the encrypted device with the secure partition in response to the request to unlock, without involvement of the host operating system.
10 . The method of claim 9 , further comprising:
receiving, with the secure partition, a token from the trusted remote console; and using the token to unwrap a key used to encrypt blocks of the encrypted device.
11 . The method of claim 10 , further comprising:
obtaining the key from a secure storage area of the encrypted device, wherein the secure storage area is hidden from the host operating system.
12 . The method of claim 9 , further comprising confirming that the request to unlock originated with the trusted remote console prior to unlocking the encrypted device.
13 . The method of claim 9 , further comprising:
performing a management operation after the encrypted device is unlocked, wherein the request to unlock specifies the management operation to be performed; and booting the host operating system after the management operation is performed.
14 . The method of claim 9 , wherein unlocking the encrypted device is performed when the host operating system of the system is malfunctioning.
15 . The method of claim 9 , wherein unlocking the encrypted device is performed without involvement of a user of the system.
16 . The method of claim 9 , wherein:
the request to unlock comprises a password for the encrypted device; and unlocking the encrypted device comprises using the password to unlock the encrypted device.Join the waitlist — get patent alerts
Track US2016342798A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.