Encryption compliance verification system
A compliance checker to verify that a device complies with a policy is described. In one embodiment, the compliance checker comprises a compliance checker agent, to initiate the compliance check, in response to receiving the request, and an encryption checker upper driver above a level of a disk encryption driver, and an encryption checker lower driver, below the level of the disk encryption driver with a comparator to determine whether known data read from the upper driver is identical to known data read from the lower driver. The compliance checker plug-in in one embodiment verifies the compliance status of the device, based on the data from the comparator.
1. A compliance checker to verify a device complies with a policy, the compliance checker comprising:
a compliance checker plug-in installed on the device, the compliance checker plug-in receiving a request for compliance validation;
a compliance checker agent, to initiate the compliance validation, in response to receiving the request;
an encryption checker to verify that the device stores data in an encrypted format, the encryption checker comprising:
an encryption checker upper driver above a level of an encryption driver in a storage driver stack, to read data as it is sent to a storage medium from above the encryption driver, and
an encryption checker lower driver, below the level of the encryption driver to read the data after it was written to the storage medium, below the encryption driver; and
a comparator to determine whether the data read from the upper driver is identical to data read from the lower driver;
the compliance checker plug-in verifying the compliance status of the device, based on the data from the comparator to report a compliance result.
2. The compliance checker of claim 1 , further comprising:
a memory to store a cookie holding result data after the compliance checker plug-in verifies compliance with the policy, such that a subsequent request for compliance validation is responded to using the cookie.
3. The compliance checker of claim 1 , further comprising:
additional compliance checkers for compliance with other policies which may include one or more of installing current updates, having a password for access to the device, and other policies.
4. The compliance checker of claim 1 , further comprising:
a connection to couple the device to a compliance checking server when the device does not have the compliance checker plug-in, the compliance checking server to install the plug-in on the device.
5. The compliance checker of claim 1 , further comprising:
an encryption installer to install an encryption system compliant with the policy, when the compliance checker plug-in determines that the device is not compliant.
6. The compliance checker of claim 1 , further comprising:
a browser on the device, the browser used to access a portal including an enforcement checker, which triggers the compliance checker plug-in.
7. A compliance checker stored on a non-transitory computer readable medium for verifying that a user computer device complies with a corporate policy comprising:
a compliance checker plug-in installed on the user device, to receive a request for determining compliance, the compliance checker plug-in to determine whether the user device has a functioning encryption driver by writing test data to a storage medium, and using an encryption checker upper driver reading the data from a storage stack as it is sent to a storage medium, and second using an encryption checker lower driver reading the data from the storage stack after it was written to the storage medium, and comparing the first reading of the data to the second reading of the data, the compliance checker being application agnostic;
a cookie added to the user device, when the compliance checker determines that the user device is compliant with the corporate policy; and
the compliance checker utilizing the cookie in a subsequent request for determining compliance.
8. The compliance checker of claim 7 , further comprising:
an encryption checker upper driver above the level of a encryption driver, and an encryption checker lower driver, below the level of the device encryption driver; and
a comparator to determine whether data read from the upper driver is identical to data received by and read from the lower driver.
9. The compliance checker of claim 7 , further comprising:
additional compliance checkers for compliance with other policies which may include one or more of the user device having all security updates, the user device requiring a log-on password for access, and other policies.
10. The compliance checker of claim 7 , further comprising:
a connection to couple the device to a compliance checking server when the device does not have the compliance checker plug-in, the compliance checking server to install the plug-in on the device.
11. The compliance checker of claim 7 , further comprising:
an encryption installer to install an encryption system compliant with the policy, when the compliance checker plug-in determines that the device is not compliant.
12. The compliance checker of claim 7 , further comprising:
a browser on the device, the browser used to access a portal including an enforcement checker, which triggers a compliance checker plug-in.
13. A method of compliance checking to verify that a user computer device complies with a policy, the method comprising:
receiving a request for compliance validation of the user computer device from a partner site;
initiating a compliance checker plug-in in response to the request;
sending test data to the user computer device;
first, reading the test data from a first encryption checker upper driver above where an encryption driver would be in a storage stack on the user computer device;
second, reading the test data from an encryption checker lower driver below where the encryption driver would be on the user computer device;
comparing the first reading of the data and the second reading of the data, to determine whether the data is identical; and
verifying a compliance status of the device, based on the comparing and taking an action based on the compliance status of the device.
14. The method of claim 13 , further comprising: storing a cookie holding the compliance status after verifying the compliance status, such that a subsequent request for compliance validation is responded to using the cookie.
15. The method of claim 13 , further comprising:
utilizing one or more additional compliance checkers for compliance with other policies which may include one or more of installing current updates, having a password for access to the device, and other policies.
16. The method of claim 13 , further comprising:
coupling the device to a compliance checking server when the device does not have the compliance checker plug-in, the compliance checking server to install the plug-in on the device.
17. The method of claim 16 , further comprising:
installing an encryption system compliant with the policy on the device, when the compliance checker plug-in determines that the device is not compliant.
18. The method of claim 13 , wherein the partner site is accessed via a browser on the device, the browser used to access a portal including an enforcement checker, which triggers a compliance checker plug-in.
19. The compliance checker of claim 1 , further comprising:
the comparator further to perform cryptographic analysis on the data to verify a quality of the encryption.
20. The method of claim 13 , further comprising:
after the comparing determines that the data from below the encryption driver is encrypted, performing cryptographic analysis on the data read from below the encryption driver, to verify a quality of the encryption.