Invention Grant
US08549278B2 Rights management services-based file encryption system and method
有权
基于权限管理服务的文件加密系统和方法
- Patent Title: Rights management services-based file encryption system and method
- Patent Title (中): 基于权限管理服务的文件加密系统和方法
-
Application No.: US12202027Application Date: 2008-08-29
-
Publication No.: US08549278B2Publication Date: 2013-10-01
- Inventor: Ahmed Mohamed
- Applicant: Ahmed Mohamed
- Applicant Address: US WA Sammamish
- Assignee: Blackout, Inc.
- Current Assignee: Blackout, Inc.
- Current Assignee Address: US WA Sammamish
- Agency: Knobbe, Martens, Olson & Bear, LLP
- Main IPC: H04L9/00
- IPC: H04L9/00

Abstract:
Windows Rights Management Services (RMS) are leveraged to provide protection and sharing of encryption keys to file systems. An encrypting file system (EFS) delegates key sharing, management and recovery to the RMS system. User rights to file encryption keys (FEKs) are derived from files' security descriptor information or as explicitly specified by users. Whenever an encrypted file is created, its FEK is protected using RMS, as a byte stream stored in file encryption metadata information. When a user with access tries to access an encrypted file without having a private key to decrypt the FEK, the EFS transparently extracts the RMS protected byte stream from the file encryption metadata information and uses RMS to access the FEK stored in the bytes stream using the user security context. The FEK is protected with the user master key, encryption certificate or password and cached for the next user file access.
Public/Granted literature
- US20090106552A1 RIGHTS MANAGEMENT SERVICES-BASED FILE ENCRYPTION SYSTEM AND METHOD Public/Granted day:2009-04-23
Information query