IP Library Granted Patent US 10,229,069
Granted Patent B2
US 10,229,069 · App. 16/009,512 · Granted Mar 12, 2019

Determining whether a data storage is encrypted

Inventors: Benjamin Czarny (San Francisco, CA); Jianpeng Mo (Burlingame, CA); Boris Dynin (Menlo Park, CA)
Assignee: OPSWAT, Inc.
G06F12/1408G06F3/0623G06F3/0635G06F3/0673G06F7/02G06F17/3007G06F17/30135G06F17/30312G06F17/30371G06F17/30386G06F17/30864G06F21/60G06F21/602G06F21/6209G06F21/6218G06F21/85G06F3/1226G06F21/00G06F21/62G06F2212/1052G06F2221/2107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,229,069
App. No.
16/009,512
Granted
Mar 12, 2019
Kind
B2
Abstract

A method, program and/or system reads first data through a first path from a location in a data storage. Second data is read through a second path from the same location in the data storage. The first data is compared to the second data. A match between the first data and the second data indicates that the first path did not encrypt the first data. A mismatch between the first data and the second data indicates that the first path encrypted the first data.

Claims (42)

1. A method comprising:

writing, by a computer via an application, a first data to a data storage coupled to the computer, wherein the application is not part of an operating system of the computer;

reading, by the computer via a device driver that has access to the data storage, a second data from the data storage, wherein the device driver bypasses the application;

comparing, by the computer, the first data to the second data to determine whether the first data matches the second data;

upon determining that the first data matches the second data, determining, by the computer, that the application did not encrypt the first data; and

upon determining that the first data does not match the second data, determining, by the computer, that the application encrypted the first data.

2. The method of claim 1 , wherein:

the device driver also bypasses an operating system file system driver of the computer.

3. The method of claim 1 , wherein:

the first data and the second data are a same portion of a same file stored in the data storage.

4. The method of claim 1 , further comprising:

requesting, by the computer via the device driver, a starting location of the first data in the data storage; and

reading, by the computer via the device driver, the second data at the starting location in the data storage.

5. The method of claim 4 , wherein:

the requesting requests a starting disk sector location of the first data using system and defrag APIs.

6. The method of claim 4 , wherein:

successfully receiving the starting location indicates that the data storage is a physical volume.

7. The method of claim 1 , further comprising:

requesting, by the computer via the device driver, a starting location of the first data in the data storage, the requesting of the starting location not resulting in the computer successfully receiving the starting location; and

requesting, by the computer via the device driver, a name of a device driver for the data storage.

8. The method of claim 7 , wherein:

the requesting of the starting location not resulting in the computer successfully receiving the starting location indicates that the data storage is a virtual volume.

9. A method comprising:

writing, by a computer via an operating system call of an operating system, a first data to a data storage coupled to the computer;

reading, by the computer via a device driver, a second data from the data storage, wherein the device driver bypasses the operating system;

comparing, by the computer, the first data to the second data to determine whether the first data matches the second data;

upon determining that the first data matches the second data, determining, by the computer, that the operating system call did not encrypt the first data; and

upon determining that the first data does not match the second data, determining, by the computer, that the operating system call encrypted the first data.

10. The method of claim 9 , wherein:

the first data and the second data are a same portion of a same file stored in the data storage.

11. The method of claim 9 , further comprising:

requesting, by the computer via the device driver, a starting location of the first data in the data storage; and

reading, by the computer via the device driver, the second data at the starting location in the data storage.

12. The method of claim 11 , wherein:

the requesting requests a starting disk sector location of the first data using system and defrag APIs.

13. The method of claim 11 , wherein:

successfully receiving the starting location indicates that the data storage is a physical volume.

14. The method of claim 9 , further comprising:

requesting, by the computer via the device driver, a starting location of the first data in the data storage, the requesting of the starting location not resulting in the computer successfully receiving the starting location; and

requesting, by the computer via the device driver, a name of a device driver for the data storage.

15. The method of claim 14 , wherein:

the requesting of the starting location not resulting in the computer successfully receiving the starting location indicates that the data storage is a virtual volume.

Assignments (2)
SECURITY INTEREST Recorded Dec 29, 2022
From: OPSWAT INC.
To: CITIBANK, N.A.
Reel/Frame 062236/0124 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2018
From: CZARNY, BENJAMIN; MO, JIANPENG; DYNIN, BORIS
To: OPSWAT, INC.
Reel/Frame 046250/0401 →
Continuity (6)
Continuation 15636520 · Jun 28, 2017
Continuation 15294861 · Oct 17, 2016
Continuation 15015084 · Feb 3, 2016
Continuation 14696228 · Apr 24, 2015
Continuation 14255829 · Apr 17, 2014
Related Publication 20180293180A1 · Oct 11, 2018