Storing and using multipurpose secret data
Abstract
A system and method improves operational performance of a computer by enhancing digital security with an added electronic circuit. The electronic circuit stores sensitive data in an un-erasable state such that the sensitive data may not be altered. The electronic circuit limits transfer of the sensitive data only once after each power-up or after each reset of the computer. The electronic circuit prevents access to the sensitive data by an authorized program. The electronic circuit utilizes its own storage medium and a random access memory, the latter of which can receive and store the sensitive data from the non-transitory computer storage medium. The method uses a software driver and a copy-of-copy of first security key obtained from the sensitive data stored on the electronic circuit. The software driver installs a software module on the computer using the copy-of-copy of first security key to encrypt each installed file.
Claims
exact text as granted — not AI-modified1 - 13 : (canceled)
14 . A method of improving operational performance of a computer and protecting the computer using confirmatory predefined encrypted value stored in metadata of computer files, the method comprising:
providing a device holding a digital security key, the digital security key configured for encrypting and decrypting data on the computer, the device configured for connection to the computer; configuring the device so that it is not necessary for operation of the computer to which said device is connected; storing on the computer an encrypted security key; integrating a kernel software driver into an operating system on the computer, the kernel software driver operable to control input and output access to a computer file stored in a non-transitory computer storage medium of the computer; including in the kernel software driver, programming code operable for implementing steps of: using the digital security key to decrypt the encrypted security key deriving a decrypted security key; using the decrypted security key to encrypt a confirmatory predefined value to produce a confirmatory predefined encrypted value; saving the confirmatory predefined encrypted value as metadata in a plurality of computer files stored in the non-transitory computer storage medium of the computer; defining as a non-authorized computer file, any computer file that lacks the confirmatory predefined encrypted value or has an invalid confirmatory predefined encrypted value; receiving at the kernel software driver each request received by the computer to access a computer file; reading the metadata of the computer file to determine a presence or absence of the confirmatory predefined encrypted value; when the confirmatory predefined encrypted value does not exist within the metadata, disallowing access to the computer file; when the confirmatory predefined encrypted value is found in the metadata, using the decrypted security key to decrypt the confirmatory predefined encrypted value and derive a confirmatory predefined decrypted value; using the kernel software driver to determine whether or not the confirmatory predefined decrypted value matches a known value; when the confirmatory predefined decrypted value matches the known value, then allowing access pursuant to each such request for access to the computer file; and when the confirmatory predefined decrypted value does not match the known value, then disallowing access to the computer file.
15 - 21 : (canceled)Join the waitlist — get patent alerts
Track US2021320787A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.