发明名称 Key management to protect encrypted data of an endpoint computing device
摘要 Methods and apparatus involve protecting encrypted data of endpoint computing assets by managing decryption keys. The endpoint has both a traditional operating system for applications, and the like, and another operating system during a pre-boot phase of operation. During use, the pre-boot operating system prevents users of the endpoint from accessing the encrypted data and the key. Upon determining the encrypted data has been compromised, the key is disassociated from the encrypted data. Disassociation can occur in a variety of ways including deleting or scrambling the key and/or data or re-encrypting the encrypted data with a new key. Key escrowing and updating through the pre-boot is further contemplated. The pre-boot phase also contemplates a limited computing connection between the endpoint and a specified authentication server and approved networking ports, USB devices and biometric equipment. Security policies and enforcement modules are also disclosed as are computer program products, computing arrangements, etc.
申请公布号 US8588422(B2) 申请公布日期 2013.11.19
申请号 US20090473480 申请日期 2009.05.28
申请人 BEACHEM BRENT R.;SMITH MERRILL K.;NOVELL, INC. 发明人 BEACHEM BRENT R.;SMITH MERRILL K.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址