IP Library Patent Application 12328213
Patent Application
App. No. 12/328,213

ENCRYPTION MANAGEMENT IN AN INFORMATION HANDLING SYSTEM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/328,213
Abstract

A method of enforcing an encryption policy in an information handling system for receiving a request for access to data, automatically identifying from a plurality of encryption policies a particular encryption policy associated with the requested data, selecting an available encryption implementation module capable of enforcing the identified encryption policy, and initiating an encryption or decryption of the requested data using the selected encryption implementation module.

Claims (54)

1 . A method of enforcing an encryption policy in an information handling system comprising steps of:

receiving a request for access to data;

automatically identifying from a plurality of encryption policies a particular encryption policy associated with the requested data;

selecting an available encryption implementation module capable of enforcing the identified encryption policy; and

initiating an encryption or decryption of the requested data using the selected encryption implementation module.

2 . The method of claim 1 wherein selecting an available encryption implementation module comprises:

determining a performance characteristic of each of multiple available encryption implementation modules capable of enforcing the identified encryption policy; and

selecting an encryption implementation module based at least on a comparison of the determined performance characteristics.

3 . The method of claim 1 wherein the encryption policy specifies an encryption algorithm and key source, the method further comprising:

accessing an encryption key from the key source specified by the policy for use by the selected encryption implementation module.

4 . The method of claim 3 wherein the key source is located remote from the information handling system.

5 . The method of claim 1 wherein:

each encryption policy specifies an encryption algorithm; and

the encryption algorithm specified by a first encryption policy is different from the encryption algorithm specified by a second encryption policy.

6 . The method of claim 1 wherein the key source specified in a first encryption policy is different from the key source specified in a second encryption policy.

7 . The method of claim 1 further comprising:

providing a user interface for setting one of the plurality of encryption policies by a user on a second information handling system; and

communicating this set encryption policy to the first information handling system.

8 . Software embodied in tangible computer-readable media and, when executed by a processor, operable to:

receive a request for access to data;

automatically identify from a plurality of encryption policies a particular encryption policy associated with the requested data;

select an available encryption implementation module capable of enforcing the identified encryption policy; and

initiate an encryption or decryption of the requested data using the selected encryption implementation module.

9 . The software of claim 8 wherein:

each of a plurality of encryption implementation modules provides a data interface; and

an abstraction layer provides a standardized interface to receive the request and initiate the encryption or decryption of the requested data independent of the data interface provided by the selected encryption implementation module.

10 . The software of claim 8 wherein the encryption policy specifies an encryption algorithm and key source, the method further comprising:

accessing an encryption key from the key source specified by the policy for use by the selected encryption implementation module.

11 . The software of claim 10 wherein the key source is located remote from the information handling system.

12 . The software of claim 8 wherein:

each encryption policy specifies an encryption algorithm; and

the encryption algorithm specified by a first encryption policy is different from the encryption algorithm specified by a second encryption policy.

13 . The software of claim 8 wherein the key source specified in a first encryption policy is different from the key source specified in a second encryption policy.

14 . The software of claim 8 further operable to:

provide a user interface for setting one of the plurality of encryption policies by a user on a second information handling system; and

communicate this set encryption policy to the first information handling system.

15 . An information handling system comprising:

a processor;

a memory coupled to the processor; and

a security policy enforcement subsystem enabled to:

receive a request for access to data;

automatically identify from a plurality of encryption policies a particular encryption policy associated with the requested data;

select an available encryption implementation module capable of enforcing the identified encryption policy; and

initiate an encryption or decryption of the requested data using the selected encryption implementation module.

16 . The information handling system of claim 15 wherein the security policy enforcement system comprises:

a security policy manager; and

an encryption services module configured to provide services to the security policy manager and to discover and request services of the encryption implementation module.

17 . The information handling system of claim 15 wherein the encryption policy specifies that the encryption implementation module utilize encryption specific hardware that protects the encryption key from unauthorized access.

18 . The information handling system of claim 15 wherein the encryption policy specifies an encryption algorithm and key source, the security policy enforcement subsystem further enabled to:

access an encryption key from the key source specified by the policy for use by the selected encryption implementation module.

19 . The information handling system of claim 18 wherein the key source is located remote from the information handling system.

20 . The information handling system of claim 15 wherein:

each encryption policy specifies an encryption algorithm; and

the encryption algorithm specified by a first encryption policy is different from the encryption algorithm specified by a second encryption policy.

Assignments (8)
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2008
From: JABER, MUHAMMED; KONETSKI, DAVID; MCCALL, DON C.; MOLSBERRY, FRANK H.; STUFFLEBEAM, KENNETH WADE, JR.; KOPP, MICHELE A.
To: DELL PRODUCTS L.P.
Reel/Frame 021948/0201 →