Method and apparatus for protecting digital data by double re-encryption
Abstract
Method and an apparatus for ensuring protection of digital data are provided. Embodiments may include double re-encrypting decrypted data using multiple keys (e.g., an unchangeable key, and a changeable key). In various embodiments, the re-encrypting may be performed using hardware, software, or a combination of hardware and software (e.g., re-encrypting in hardware using an unchangeable key and re-encrypting in software using a changeable key). In some embodiments, encryption/decryption is performed with RTOS using a HAL and a device driver (e.g., a filter driver, a disk driver and a network driver, in an I/O manager).
Claims
exact text as granted — not AI-modified1 - 86 . (canceled)
87 . A method, comprising:
receiving double-encrypted data at a computer system; decrypting, the double-encrypted data to produce decrypted data, wherein the decrypting the double-encrypted data includes the computer system using a changeable key and using a non-changeable key.
88 . The method of claim 87 , wherein the decrypting the double-encrypted data to produce the decrypted data includes:
decrypting the double-encrypted data using the non-changeable key to produce single-encrypted data; and decrypting the single-encrypted data using the changeable key to produce the decrypted data.
89 . The method of claim 88 ,
wherein the decrypting the double-encrypted data using the non-changeable key includes decrypting using a hardware decryption unit.
90 . The method of claim 88 ,
wherein the decrypting the double-encrypted data using the non-changeable key includes using software-implemented decryption.
91 . The method of claim 88 ,
wherein the decrypting the single-encrypted data using the changeable key includes decrypting using a hardware decryption unit.
92 . The method of claim 88 ,
wherein the decrypting the single-encrypted data using the changeable key includes decrypting using software-implemented decryption.
93 . The method of claim 87 ,
wherein the non-changeable key is specific to the computer system.
94 . The method of claim 87 , further comprising:
generating the changeable key at the computer system.
95 . The method of claim 87 , further comprising:
receiving the changeable key at the computer system.
96 . The method of claim 87 , wherein the decrypting the double-encrypted data to produce the decrypted data includes:
decrypting the double-encrypted data using the changeable key to produce single-encrypted data; and decrypting the single-encrypted data using the non-changeable key to produce the decrypted data.
97 . The method of claim 96 ,
wherein the non-changeable key is specific to the computer system.
98 . An apparatus, comprising:
a processor; memory, coupled to the processor, having instructions stored thereon that are executable by the apparatus to cause the apparatus to encrypt, using a first key and a second key, unencrypted data to produce double-encrypted data; wherein the first key is configured to be updatable, and wherein the second key is configured to be static.
99 . The apparatus of claim 98 , wherein the apparatus encrypting the unencrypted data to produce the double-encrypted data includes:
encrypting the unencrypted data using the first key to produce single-encrypted data; and encrypting the single-encrypted data using the second key to produce the double-encrypted data.
100 . The apparatus of claim 98 , wherein the apparatus encrypting the unencrypted data to produce the double-encrypted data includes:
encrypting the unencrypted data using the second key to produce single-encrypted data; and encrypting the single-encrypted data using the first key to produce the double-encrypted data.
101 . The apparatus of claim 98 , further comprising:
a hardware decryption portion; wherein the using the second key includes using the hardware decryption portion.
102 . The apparatus of claim 98 ,
wherein the using the second key includes using software-implemented decryption.
103 . The apparatus of claim 98 ,
wherein the first key is generated by the apparatus.
104 . The apparatus of claim 98 ,
wherein the first key is received by the apparatus.
105 . A method, comprising:
encrypting unencrypted data to produce double-encrypted data, wherein the encrypting the unencrypted data includes a computer system using a changeable key and a non-changeable key, the changeable key being updatable, and the non-changeable key being static; decrypting the double-encrypted data to produce decrypted data, wherein the decrypting the double-encrypted data includes the computer system using the changeable key and the non-changeable key.
106 . The method of claim 105 ,
wherein the encrypting the unencrypted data to produce double-encrypted data includes:
encrypting the unencrypted data using the changeable key to produce single-encrypted data; and
encrypting the single-encrypted data using the non-changeable key to produce the double-encrypted data; and
wherein the decrypting the double-encrypted data to produce decrypted data includes:
decrypting the double-encrypted data using the non-changeable key to produce single-encrypted data; and
decrypting the single-encrypted data using the changeable key to produce the decrypted data.Join the waitlist — get patent alerts
Track US2012093319A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.