IP Library Granted Patent US 7,036,020
Granted Patent B2
US 7,036,020 · App. 09/912,931 · Granted Apr 25, 2006

Methods and systems for promoting security in a computer system employing attached storage devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,036,020
App. No.
09/912,931
Granted
Apr 25, 2006
Kind
B2
Abstract

The present methods and systems use specially isolated techniques for promoting security in a computer system. In one embodiment of these methods and systems, a simple file system is concealed in the storage of the computer system and is managed with a processor and simple non-writeable code operating on the storage device. Strong cryptographic design permits the present computer security methods and systems to secure data on the storage device. In one method embodiment, a computer system is provided with an operating system in operative association with at least one storage device, wherein the storage device includes firmware and a processor for processing data and instructions stored on the storage device. The method includes creating at least one security partition in, and restricting access to, at least a portion of the storage device by the operating system. The method also includes creating at least one security partition in the storage device. The method also includes providing at least one authority record and data associated with the authority record in the storage device. System and computer-readable medium embodiments structured in accordance with the method embodiments discussed herein are also provided.

Claims (27)

1. A storage device for promoting security in a computer system, the storage device comprising:

a storage medium for storing data;

firmware for reading data from and writing data to the storage medium; and

a partition defined on the storage medium for dividing the storage medium into a data partition and a secure data partition, the secure data partition for storing secure data and one or more authority records, wherein the one or more authority records define access permissions relating to the secure data partition and the secure data;

wherein the secure data partition contains a master authority record, wherein the one or more authority records can be created and deleted as required by a user having access permissions according to the master authority record; and

wherein only the firmware is permitted to access the secure data and the one or more authority records.

2. The storage device of claim 1 wherein the storage device is in communication with a computer system having an operating system.

3. The storage device of claim 2 , wherein secure data stored in the secure data partition is invisible to the operating system.

4. The storage device of claim 1 wherein each of the one or more authority records contains one public-private key pair for authenticating data that originates from the security partition.

5. The storage device of claim 1 , wherein the storage device further comprises:

cryptographic operations embedded in the firmware of the storage device.

6. The storage device of claim 5 , wherein cryptographic code is authenticated with a root assurance in the firmware of the device, wherein the firmware is non-writable.

7. A method for promoting security in a computer system having an operating system in operative connection with a storage device, wherein said storage device includes a processor and firmware for processing data stored on the storage device, the method comprising:

partitioning a storage medium of the storage device into a data partition and a secure data partition, the data partition being accessible to a user and the secure data partition being invisible to the user, the secure data partition for storing secure data and one or more authority records, wherein the secure data is encrypted and a cryptographic code is embedded in the firmware;

restricting access to the secure data partition such that only the firmware may access the secure data and the one or more authority records; and

authenticating the cryptographic code with a root assurance in the storage device.

8. The method of claim 7 , further comprising:

prohibiting access to the secure data partition by the operating system of the computer system.

9. The method of claim 8 , wherein a portion of the firmware is non-writable.

10. The method of claim 7 , further comprising:

writing data to the secure data partition by executing of a portion of the firmware of the storage device; and

associating the data with a particular record of the one or more authority records.

11. The storage device of claim 1 , wherein the secure data is accessed by the firmware using a security partition open call internal to the storage device and hidden from a user.

12. A storage device comprising: a storage medium having a security partition containing one or more authority records and at least one data set associated with each of the one or more authority records; and

a mechanism within the storage device adapted to limit access to the security partition based on the one or more authority records, wherein the mechanism comprises a processor disposed within the storage device adapted to limit access to the security partition by an operating system of a computer system, and firmware disposed within the storage device adapted to limit access to the security partition by an operating system of a computer system.

13. The storage device of claim 12 wherein the one or more authority records comprises a master authority record including instructions for governing the one or more authority records in said storage device.

14. The storage device of claim 12 wherein each of the one or more authority records comprises a plurality of fields, wherein a first field of the plurality of fields contains access rights governing access to the at least one data set.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2018
From: WAVE SYSTEMS CORP.
To: WAVE SYSTEMS DISTRIBUTION TRUST
Reel/Frame 047411/0455 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2018
From: WAVE SYSTEMS DISTRIBUTION TRUST
To: WI-LAN TECHNOLOGIES INC.
Reel/Frame 046616/0473 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2018
From: WI-LAN TECHNOLOGIES INC.
To: SECUREWAVE STORAGE SOLUTIONS INC.
Reel/Frame 046616/0625 →
SECURITY INTEREST Recorded Dec 7, 2015
From: WAVE SYSTEMS CORP.
To: MARBLE BRIDGE FUNDING GROUP, INC.
Reel/Frame 037222/0703 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RE-RECORD DUE TO CORRECTION TO ASSIGNEE NAME FROM WAVE SYSTEMS, CORP. TO WAVE SYSTEMS CORP. PREVIOUSLY RECORDED ON REEL 024838 FRAME 0888. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 22, 2010
From: ANTIQUE BOOKS, INC.
To: WAVE SYSTEMS CORP.
Reel/Frame 025026/0082 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2010
From: ANTIQUE BOOKS, INC.
To: WAVE SYSTEMS, CORP.
Reel/Frame 024838/0888 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2002
From: THIBADEAU, ROBERT H.
To: ANTIQUE BOOKS, INC.
Reel/Frame 013159/0386 →