Theft and tamper resistant data protection

Systems and methods are provided for adding security to client data by maintaining a key that provides access to the client data remote from the client data. In some cases, the system encrypts a data cluster using an encryption key, associates the encrypted data cluster with a unique identifier, and...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: FIELD SCOTT A, ZHOU DAYI, WALTON JOHN MICHAEL, SEMENKO ALEX M, SOLAM ARAVIND N, BEN-MENAHEM AVRAHAM MICHAEL
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Systems and methods are provided for adding security to client data by maintaining a key that provides access to the client data remote from the client data. In some cases, the system encrypts a data cluster using an encryption key, associates the encrypted data cluster with a unique identifier, and sends the unique identifier and a decryption key to a server for storage. A decryption key is then received from the server and used to decrypt the encrypted data cluster. The server may also perform policy checks or trigger additional authentication, such as SMS, phone or email notifications, prior to allowing access to the key. Further, in some examples, the server may also block access to the stored keys in response to anomalies, such as deactivation and other asset management events. 提供了用于通过维持密钥来向客户端数据添加安全性的系统和方法,该密钥提供了远离客户端数据对该客户端数据的访问。在一些情况下,系统使用加密密钥对数据集群进行加密,将加密的数据集群与唯一标识符相关联,并将唯一标识符和解密密钥发送到服务器进行存储。然后解密密钥从服务器被接收,并被用于对加密的数据集群进行解密。在允许访问密钥之前,服务器还可以执行策略检查或触发附加认证,诸如SMS、电话或电子邮件通知。此外,在一些实例中,服务器还可以响应异常(诸如停用和其他资产管理事