IP Library Granted Patent US 9,817,675
Granted Patent B1
US 9,817,675 · App. 15/421,291 · Granted Nov 14, 2017

Methods and systems for attaching an encrypted data partition during the startup of an operating system

Inventors: Babu Katchapalayam (Cupertino, CA); Stephen D. Pate (Livermore, CA)
Assignee: HYTRUST, INC.
G06F9/4418G06F9/44G06F9/4406H04L9/083G06F1/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,817,675
App. No.
15/421,291
Granted
Nov 14, 2017
Kind
B1
Abstract

During the startup of an operating system of a computing system, a monitoring process of the operating system is used to detect an entry point of a daemon manager process. In response to detecting the entry point, the startup process is paused, and an early attach process is launched so as to attach one or more encrypted data partitions to the operating system. As part of the early attach process, the network stack of the computing system may be initialized, which allows the early attach process to retrieve one or more decryption keys corresponding to the one or more encrypted data partitions from an external key management server. The one or more decryption keys may be transmitted to a disk filter driver of the operating system, which provides the operating system with access to the one or more encrypted data partitions. Upon the conclusion of the early attach process, the operating system startup process resumes with the one or more encrypted data partitions now accessible to the operating system.

Claims (30)

1. A method for attaching one or more encrypted data partitions of a data storage device during a startup of an operating system of a computing system, the computing system comprising a processor, a memory and the data storage device, the method comprising:

monitoring the startup of the operating system;

after execution of a windows initialization process (wininit.exe) but prior to execution of a service control manager process (services.exe), pausing the startup of the operating system, and attaching the one or more encrypted data partitions to the operating system by (i) retrieving one or more decryption keys corresponding to the one or more encrypted data partitions from a key management server communicatively coupled to the computing system, and (ii) transmitting the one or more retrieved decryption keys to a disk filter driver of the operating system, the disk filter driver providing the operating system with access to the one or more encrypted data partitions; and

resuming the startup of the operating system with the one or more encrypted data partitions attached to the operating system.

2. The method of claim 1 , wherein monitoring the startup of the operating system comprises monitoring execution of a session manager process (smss.exe), a client/server runtime subsystem process (csrss.exe) and the windows initialization process (wininit.exe).

3. The method of claim 1 , wherein the pausing of the startup of the operating system comprises delaying execution of the service control manager process (services.exe), a local security authority subsystem server process (lsass.exe) and a windows logon process (winlogon.exe) until the one or more encrypted data partitions have been attached to the operating system.

4. The method of claim 1 , wherein retrieving the one or more decryption keys from the key management server comprises:

gaining access to a network that communicatively couples the computing system to the key management server;

converting a domain name of the key management server into an Internet protocol (IP) address of the key management server;

transmitting a request from the computing system to the IP address of the key management server, the request requesting the one or more decryption keys from the key management server; and

receiving by the computing system the one or more decryption keys from the key management server.

5. The method of claim 4 , wherein gaining access to the network comprises:

requesting a dynamic IP address of a network interface of the computing system from a dynamic host configuration protocol (DHCP) server; and

initializing a transmission control protocol (TCP)/IP network stack using the dynamic IP address of the network interface of the computing system.

6. The method of claim 4 , wherein gaining access to the network comprises:

determining a static IP address of a network interface of the computing system from the operating system; and

initializing a transmission control protocol (TCP)/IP network stack using the static IP address of the network interface of the computing system.

7. The method of claim 1 , wherein the disk filter driver communicatively couples a file system driver of the operating system with a disk driver of the operating system.

8. A computing system comprising a processor, a memory and a data storage device, the data storage device comprising instructions that, when executed by the processor, cause the processor to:

monitor a startup of the operating system;

after execution of a windows initialization process (wininit.exe) but prior to execution of a service control manager process (services.exe), pause the startup of the operating system, and attach one or more encrypted data partitions of the data storage device to the operating system by (i) retrieving one or more decryption keys corresponding to the one or more encrypted data partitions from a key management server communicatively coupled to the computing system, and (ii) transmitting the one or more retrieved decryption keys to a disk filter driver of the operating system, the disk filter driver providing the operating system with access to the one or more encrypted data partitions; and

resume the startup of the operating system with the one or more encrypted data partitions attached to the operating system.

9. The computing system of claim 8 , wherein monitoring the startup of the operating system comprises monitoring execution of a session manager process (smss.exe), a client/server runtime subsystem process (csrss.exe) and the windows initialization process (wininit.exe).

10. The computing system of claim 8 , wherein the pausing of the startup of the operating system comprises delaying execution of the service control manager process (services.exe), a local security authority subsystem server process (lsass.exe) and a windows logon process (winlogon.exe) until the one or more encrypted data partitions have been attached to the operating system.

11. A non-transitory machine-readable storage medium comprising software instructions that, when executed by a processor of a computing system, cause the processor to:

monitor a startup of the operating system;

after execution of a windows initialization process (wininit.exe) but prior to execution of a service control manager process (services.exe), pause the startup of the operating system, and attach one or more encrypted data partitions of a data storage device of the computing system to the operating system by (i) retrieving one or more decryption keys corresponding to the one or more encrypted data partitions from a key management server communicatively coupled to the computing system, and (ii) transmitting the retrieved one or more decryption keys to a disk filter driver of the operating system, the disk filter driver providing the operating system with access to the one or more encrypted data partitions; and

resume the startup of the operating system with the one or more encrypted data partitions attached to the operating system.

12. The non-transitory machine-readable storage medium of claim 11 , wherein monitoring the startup of the operating system comprises monitoring execution of a session manager process (smss.exe), a client/server runtime subsystem process (csrss.exe) and the windows initialization process (wininit.exe).

13. The non-transitory machine-readable storage medium of claim 11 , wherein the pausing of the startup of the operating system comprises delaying execution of the service control manager process (services.exe), a local security authority subsystem server process (lsass.exe) and a windows logon process (winlogon.exe) until the one or more encrypted data partitions have been attached to the operating system.

Assignments (9)
SECURITY INTEREST Recorded Mar 27, 2024
From: ENTRUST CORPORATION
To: BMO BANK N.A., AS COLLATERAL AGENT
Reel/Frame 066917/0024 →
MERGER Recorded Mar 18, 2024
From: HYTRUST, INC.
To: ENTRUST CORPORATION
Reel/Frame 066806/0262 →
SECURITY AGREEMENT Recorded Feb 1, 2021
From: HYTRUST, INC.
To: BMO HARRIS BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 055190/0660 →
TERMINATION OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 7, 2021
From: SILICON VALLEY BANK
To: HYTRUST, INC.
Reel/Frame 054925/0059 →
SECURITY INTEREST Recorded Sep 24, 2019
From: HYTRUST, INC.
To: SILICON VALLEY BANK
Reel/Frame 050474/0933 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY ADDRESS PREVIOUSLY RECORDED AT REEL: 041138 FRAME: 0907. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 27, 2017
From: PATE, STEPHEN D.
To: HYTRUST, INC.
Reel/Frame 044308/0418 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY ADDRESS PREVIOUSLY RECORDED AT REEL: 041138 FRAME: 0875. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 27, 2017
From: KATCHAPALAYAM, BABU
To: HYTRUST, INC.
Reel/Frame 044308/0239 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2017
From: PATE, STEPHEN D.
To: HYTRUST, INC.
Reel/Frame 041138/0907 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2017
From: KATCHAPALAYAM, BABU
To: HYTRUST, INC.
Reel/Frame 041138/0875 →