发明名称 System for optimized key management with file groups
摘要 A group manager module may provide the capability to segregate or associate files into file encryption groups. A file may be placed into a file encryption group based on the attributes of the file. The attributes may be characteristics/parameters that describe who has access to a file such as UNIX permission/mode bits (group-read/write/executable bit, owner-read/write/executable bits, users-read/write/executable bits) or other system for access control lists (ACLs). Once associated with a file encryption group, the file may be encrypted with the encryption (or write) key of the selected file encryption group, and thus, decrypted with the decryption (or read) key of the file encryption group. A user may have membership into multiple file encryption groups as long as the user possesses the appropriate read/write key pairs. Membership of a file in a file encryption group is determined automatically by the system based on the permission attributes assigned by the system-groups are not explicitly created by administrators or other centralized authority. It is not users that belong to groups based on their access rights, but files which belong to groups based on their permission attributes.
申请公布号 US7171557(B2) 申请公布日期 2007.01.30
申请号 US20010984928 申请日期 2001.10.31
申请人 HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P. 发明人 KALLAHALLA MAHESH;RIEDEL ERIK;SWAMINATHAN RAM
分类号 H04L9/00;G06F21/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址