US2019190958A1PendingUtilityA1

Independent Encryption Compliance Verification System

Assignee: ALERTSEC INCPriority: Aug 24, 2016Filed: Feb 25, 2019Published: Jun 20, 2019
Est. expiryAug 24, 2036(~10.1 yrs left)· nominal 20-yr term from priority
G06F 21/602H04L 63/20H04L 63/10
60
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A compliance checker to verify that a device complies with a policy is described. In one embodiment, the compliance checker comprises a compliance checker agent, to initiate the compliance check, in response to receiving the request, and an encryption checker to obtain an original data and a data stored on the storage. The system further comprising a comparator to determine whether known data read from the upper driver is identical to known data read from the lower driver. The compliance checker plug-in in one embodiment verifies the compliance status of the device, based on the data from the comparator.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A compliance checker to provide drive encryption validation that is device type and encryption application independent, the compliance checker comprising:
 a compliance checker plug-in on a device to be validated, the compliance checker plug-in receiving a request for compliance validation;   a compliance checker agent, to initiate the compliance check, in response to receiving the request, and further to obtain an original file created to be written to a drive and a copy of the file from the drive;   a comparator to determine whether the original file and the copy of the file are identical;   the compliance checker plug-in verifying the compliance status of the device, based on data from the comparator.   
     
     
         2 . The compliance checker of  claim 1 , further comprising:
 a memory to store a cookie holding result data after the compliance checker plug-in verifies compliance with the policy, such that a subsequent request for compliance validation is responded to using the cookie.   
     
     
         3 . The compliance checker of  claim 1 , further comprising:
 additional compliance checkers for compliance with other policies which may include one or more of installing current updates, having a password for access to the device, and other policies.   
     
     
         4 . The compliance checker of  claim 1 , further comprising:
 a connection to couple the device to a compliance checking server when the device does not have the compliance checker plug-in, the compliance checking server to install the plug-in on the device.   
     
     
         5 . The compliance checker of  claim 1 , further comprising:
 an encryption installer to install an encryption system compliant with the policy, when the compliance checker plug-in determines that the device is not compliant.   
     
     
         6 . The compliance checker of  claim 1 , further comprising:
 a browser on the device, the browser used to access a portal including an enforcement checker, which triggers the compliance checker plug-in.   
     
     
         7 . The compliance checker of  claim 1 , wherein the compliance checker agent reads the copy of the file directly from a drive location, using a low level driver. 
     
     
         8 . The compliance checker of  claim 7 , further comprising:
 a buffer to pass the drive location, and to store the original file.   
     
     
         9 . The compliance checker of  claim 1 , further comprising:
 the compliance checker to analyze the encryption to determine that it meets security guidelines.   
     
     
         10 . A method of providing device type and encryption application independent compliance checking for a device, the method comprising:
 installing a compliance checker plug-in on a device to be validated;   receiving a request for compliance validation;   initiating the compliance validation in response to receiving the request;   obtaining an original file to be written to a drive of the device;   obtaining a copy of the file from the drive of the device, after storage;   determining whether the original file and the copy of the file are identical;   verifying the compliance status of the device, based on data from the comparator.   
     
     
         11 . The method of  claim 10 , further comprising:
 storing a cookie holding result data after the compliance checker plug-in verifies compliance with the policy, such that a subsequent request for compliance validation is responded to using the cookie.   
     
     
         12 . The method of  claim 10 , further comprising:
 verifying compliance with other policies which may include one or more of installing current updates, having a password for access to the device, and other policies.   
     
     
         13 . The method of  claim 10 , further comprising:
 coupling the device to a compliance checking server when the device does not have the compliance checker plug-in, the compliance checking server to install the plug-in on the device.   
     
     
         14 . The method of  claim 10 , further comprising:
 automatically installing an encryption system compliant with the policy, when the compliance checker plug-in determines that the device is not compliant.   
     
     
         15 . The method of  claim 10 , further comprising:
 triggering the compliance checking by accessing a portal including an enforcement checker.   
     
     
         16 . The method of  claim 10 , wherein the copy of the file is read directly from a drive location, using a low level driver. 
     
     
         17 . The method of  claim 16 , wherein the drive location is retrieved from a buffer. 
     
     
         18 . The method of  claim 10 , further comprising:
 testing the copy of the file to verify that an encryption meets security guidelines.   
     
     
         19 . A device type and encryption application independent compliance checker to validate drive encryption of a device prior to providing access to privileged data for that device, the compliance checker comprising:
 a compliance checker plug-in on the device, the compliance checker plug-in receiving a request for compliance validation when the device attempts to access a secured resource;   a compliance checker agent to initiate the compliance check in response to receiving the request, and further to obtain an original file and a copy of the file from the drive;   a comparator to determine whether the original file and the copy of the file are identical;   the compliance checker agent to verify that an encryption of the copy of the file meets encryption standards; and   the compliance checker plug-in verifying the compliance status of the device, based on data from the comparator and the compliance checker agent.   
     
     
         20 . The compliance checker of  claim 19 , further comprising:
 the device accessing the secured resource through a landing page, the landing page to trigger the compliance checker agent, and to redirect the device to download the compliance checker plug-in when it is not present on the device.

Join the waitlist — get patent alerts

Track US2019190958A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.