IP Library › Granted Patent US 10,204,241
Granted Patent B2
US 10,204,241 · App. 15/639,613 · Granted Feb 12, 2019

Theft and tamper resistant data protection

Inventors: Scott A. Field (Redmond, WA); Aravind N. Thoram (Sammamish, WA); John Michael Walton (Redmond, WA); Dayi Zhou (Redmond, WA); Alex M. Semenko (Issaquah, WA); Avraham Michael Ben-Menahem (Sammamish, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/86G06F21/126G06F21/40G06F21/575H04L9/14H04L9/3213H04L29/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,204,241
App. No.
15/639,613
Granted
Feb 12, 2019
Kind
B2
Abstract

Systems and methods are provided for adding security to client data by maintaining keys providing access to the client data remotely from the client data. In some circumstances, the systems encrypt a cluster of data using an encryption key, associate the cluster of encrypted data with a unique identifier and send the unique identifier and the decryption key to a server for storage. The decryption key is then received from the server and is used to decrypt the cluster of encrypted data. A server can also perform policy checks or trigger additional authentication such as SMS, phone, or email notification before allowing access to a key. Furthermore, in some instances, the server can also prevent access to the stored keys in response to anomalies, such as decommissioning and other asset management events.

Claims (30)

1. A client computing system for keeping encrypted data tamper resistant, comprising:

one or more processors; and

one or more storage media having stored computer-executable instructions that are executable by the one or more processors for implementing a method for keeping encrypted data tamper resistant, the method comprising:

associating a cluster of data with a unique key identifier;

encrypting the cluster of data using an encryption key;

sending the unique key identifier and a decryption key to a server that has access to a key ID database that stores the unique key identifier and the decryption key, wherein the decryption key is interrelated to the encryption key and configured to decrypt the cluster of data that is encrypted using the encryption key;

storing the unique key identifier in the cluster of encrypted data as metadata without storing the encryption key;

initiating boot of a client system;

sending a communication request to a server that has access to the key ID database;

receiving a communication response from the server;

sending the unique key identifier to the server;

receiving a decryption key from the server; and

decrypting the cluster of encrypted data using the decryption key.

2. The computing system of claim 1 , wherein the encryption key and the decryption key are a symmetric key.

3. The computing system of claim 1 , wherein the server is a Pre-boot Execution Environment (PXE) server, wherein the communication request is a PXE discover, and wherein the communication response is a response to the PXE discover.

4. The computing system of claim 1 , wherein the request for boot code is a request for boot code via Trivial File Transfer Protocol (TFTP).

5. A method implemented by a client system for keeping encrypted data tamper resistant, comprising:

associating a cluster of data with a unique key identifier;

encrypting the cluster of data using an encryption key;

sending the unique key identifier and a decryption key to a server that has access to a key ID database that stores the unique key identifier and the decryption key, wherein the decryption key is interrelated to the encryption key and configured to decrypt the cluster of data that is encrypted using the encryption key;

storing the unique key identifier in the cluster of encrypted data as metadata without storing the encryption key;

initiating boot of a client system;

sending a communication request to a server that has access to the key ID database;

receiving a communication response from the server;

sending the unique key identifier to the server;

receiving a decryption key from the server; and

decrypting the cluster of encrypted data using the decryption key.

6. The method of claim 5 , wherein the encryption key and the decryption key are a symmetric key.

7. The method of claim 5 , wherein the server is a Pre-boot Execution Environment (PXE) server, wherein the communication request is a PXE discover, and wherein the communication response is a response to the PXE discover.

8. The method of claim 5 , wherein the request for boot code is a request for boot code via Trivial File Transfer Protocol (TFTP).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2017
From: FIELD, SCOTT A.; THORAM, ARAVIND N.; WALTON, JOHN MICHAEL; ZHOU, DAYI; SEMENKO, ALEX M.; BEN-MENAHEM, AVRAHAM MICHAEL
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 042927/0070 →
Continuity (1)
Related Publication 20190005274A1 · Jan 3, 2019