IP Library Granted Patent US 9,135,446
Granted Patent B2
US 9,135,446 · App. 13/630,043 · Granted Sep 15, 2015

Systems and methods to provide secure storage

Inventors: Nicholas D. Triantafillou (Portland, OR); Paritosh Saxena (Portland, OR); Paul J. Thadikaran (Ranch Cordova, CA); David Michael Durham (Beaverton, OR)
Assignee: INTEL CORPORATION
G06F21/57G06F21/10H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,135,446
App. No.
13/630,043
Granted
Sep 15, 2015
Kind
B2
Abstract

Systems and method to provide secure storage are disclosed. An example method includes establishing a secure tunnel between a storage device and an agent, transferring first data from the storage device to the agent via the secure tunnel, the secure tunnel to prevent software executing in an operating system from modifying the data, and identifying a data modification by comparing the first data to second data.

Claims (26)

1. A method, comprising:

establishing a secure tunnel between a storage device and an agent;

obtaining first data from the storage device at the agent via the secure tunnel, the secure tunnel preventing software executing in an operating system from modifying the first data; and

identifying, at the agent, a data modification by comparing the first data to second data, the first data including trusted data and the second data including untrusted data, or, the first data including a hash of the trusted data and the second data including a hash of the untrusted data.

2. A method as defined in claim 1 , further including obtaining the second data from the storage device at the agent via the secure tunnel, the second data including the hash of the untrusted data.

3. A method as defined in claim 2 , further including generating the second data at the agent and transferring the second data from the agent to the storage device via the secure tunnel, the transferring of the second data from the agent to the storage device via the secure tunnel occurring before the obtaining of the second data from the storage device to the agent via the secure tunnel.

4. A method as defined in claim 1 , further including transferring the second data from the storage device to the agent via the secure tunnel, the second data including the untrusted data.

5. A method as defined in claim 1 , further including identifying a presence of a software application on a platform based on the comparison.

6. A system, comprising:

a storage device including a secure storage area and a processor; and

an agent to:

establish a secure tunnel to the storage device;

obtain first data via the secure tunnel, the secure tunnel to prevent software executing in an operating system from modifying the first data prior to the agent obtaining the first data; and

identify a data modification by comparing the first data to second data, the first data including trusted data and the second data including untrusted data, or, the first data including a hash of the trusted data and the second data including a hash of the untrusted data.

7. A system as defined in claim 6 , wherein the storage device is to provide the second data to the agent via the secure tunnel, the second data including the hash of the untrusted data.

8. A system as defined in claim 7 , wherein the agent is to generate the second data and provide the second data to the storage device via the secure tunnel, the storage device to provide the second data to the agent via the secure tunnel after the agent provides the second data to the storage device via the secure tunnel.

9. A system as defined in claim 6 , wherein the storage device is to store the trusted data in the secure storage area.

10. A system as defined in claim 6 , wherein the agent is to access a trusted application programming interface exposed by the storage device to establish the secure tunnel.

11. A system as defined in claim 6 , wherein the agent is to obtain the second data from the storage device.

12. A system as defined in claim 6 , wherein the agent includes a file integrity checker to apply a rule to the comparison to determine whether the comparison is representative of malware.

13. A tangible computer readable storage medium comprising computer readable instructions which, when executed, cause a processor to at least:

establish a secure tunnel between a storage device and an agent;

access first data from the storage device at the agent via the secure tunnel while the secure tunnel prevents software executing in an operating system from modifying the first data; and

identify a data modification by comparing the first data to second data, the first data including trusted data and the second data including untrusted data, or, the first data including a hash of the trusted data and the second data including a hash of the untrusted data.

14. A storage medium as defined in claim 13 , wherein the instructions further cause the processor to apply a rule to the data modification to detect malware.

15. A storage medium as defined in claim 13 , wherein identifying the data modification includes identifying a modification to untrusted data stored on the storage device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2023
From: INTEL CORPORATION
To: SK HYNIX NAND PRODUCT SOLUTIONS CORP.
Reel/Frame 062437/0255 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2013
From: TRIANTAFILLOU, NICHOLAS D.; SAXENA, PARITOSH; THADIKARAN, PAUL J.; DURHAM, DAVID M.
To: INTEL CORPORATION
Reel/Frame 029562/0234 →
Continuity (1)
Related Publication 20140096260A1 · Apr 3, 2014