发明名称 Key management to protect encrypted data of an endpoint computing device
摘要 <p>Methods and apparatus involve protecting encrypted data of endpoint computing assets (201) by managing decryption keys. The endpoint has both a traditional operating system (375) for applications, and the like, and another operating system during a pre-boot phase of operation. During use, the pre-boot operating system prevents users of the endpoint from accessing the encrypted data and the key. Upon determining (406) the encrypted data has been compromised, the key is disassociated (414) from the encrypted data. Disassociation can occur in a variety of ways including deleting or scrambling the key and/or data or re-encrypting the encrypted data with a new key. Key escrowing and updating through the pre-boot is further contemplated. The pre-boot phase also contemplates a limited computing connection between the endpoint and a specified authentication server and approved networking ports, USB devices and biometric equipment. Security policies and enforcement modules are also disclosed as are computer program products, computing arrangements, etc.</p>
申请公布号 EP2256656(A1) 申请公布日期 2010.12.01
申请号 EP20100161224 申请日期 2010.04.27
申请人 NOVELL, INC. 发明人 BEACHEM, BRENT R;SMITH, MERRILL K
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址