发明名称 Trusted storage
摘要 In one embodiment, a method for authenticating access to encrypted content on a storage medium, wherein the encrypted content is encrypted according to a full disk encryption (FDE) key, the storage medium including an encrypted version of the FDE key and an encrypted version of a protected storage area (PSA) key, and wherein the encrypted version of the FDE key is encrypted according to the PSA key, the method comprising: providing an authenticated communication channel between a host and a storage engine associated with the storage medium; at the storage engine, receiving a pass code from the host over the authenticated communication channel; hashing the pass code to form a derived key, wherein the encrypted version of the PSA key is encrypted according to the derived key; verifying an authenticity of the pass code; if the pass code is authentic, decrypting the encrypted version of the PSA key to recover the PSA key; decrypting the encrypted FDE key using the recovered PSA key to recover the FDE key; and decrypting the encrypted content using the FDE key.
申请公布号 US8307217(B2) 申请公布日期 2012.11.06
申请号 US20080025777 申请日期 2008.02.05
申请人 LEE LANE W.;GURKOWSKI MARK J.;HINES RANDAL 发明人 LEE LANE W.;GURKOWSKI MARK J.;HINES RANDAL
分类号 G06F12/14;H04L9/08 主分类号 G06F12/14
代理机构 代理人
主权项
地址