IP Library › Granted Patent US 12,197,583
Granted Patent B2
US 12,197,583 · App. 17/867,451 · Granted Jan 14, 2025

Key management system for disk encryption

Inventor: Jason Lee Wolfe (Gilbert, AZ)
Assignee: Netskope, Inc.
G06F21/575G06F9/4401G06F21/62H04L9/0877H04L9/0897H04L63/126G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,583
App. No.
17/867,451
Granted
Jan 14, 2025
Kind
B2
Abstract

A key management system for providing encryption of a disk in a client device is provided. The system comprises a trusted platform module (TPM) having a first fragment of a key, a remote storage having a second fragment of the key, and a processing unit to partially boot instructions relating to booting of the client device, send a request for validation to the TPM, receive the first fragment of the key from the TPM on successful validation, request for the second fragment of the key with credentials to access the remote storage. The credentials and a network of the request are verified, the second fragment of the key is transmitted on successful validation. The first fragment and the second fragment of the key are combined to generate an encryption key for booting the client device. The first fragment of the key and the second fragment of the key are rotatable.

Claims (59)

1. A system for providing encryption of a disk in a client device, the system comprising:

a trusted platform module (TPM) comprising a first fragment of a key;

a remote storage connected with the TPM, wherein the remote storage comprises a second fragment of the key; and

the client device configured to:

partially boot a plurality of instructions in the client device from the disk;

send a request for validation of the plurality of instructions to the TPM;

receive the first fragment of the key from the TPM in response to the validation of the plurality of instructions; and

send a request for the second fragment of the key to the remote storage along with credentials, wherein:

the credentials are used to access the remote storage;

a network is verified; and

verification of the network includes checking Internet Protocol (IP) address;

receive the second fragment of the key if the credentials are verified by the remote storage and the network is checked;

combine the first fragment of the key and the second fragment of the key to generate an encryption key;

complete the booting of the plurality of instructions from the disk by decrypting data on the disk using the encryption key, and

access data stored on the client device in response to the completion of the booting of the plurality of instructions from the disk,

wherein the first fragment of the key and the second fragment of the key are rotated when: stealing of sensitive data in the client device, malware attack in the client device, or a leakage of the first fragment of the key or the second fragment of the key is detected, and after the first fragment of the key and the second fragment of the key are rotated, the first fragment of the key is updated in the TPM.

2. The system for providing encryption of a disk in the client device, as recited in claim 1 , wherein the client device is configured to prevent booting of the plurality of instructions if the verification of the credentials fails and/or the verification of the network fails.

3. The system for providing encryption of a disk in the client device, as recited in claim 1 , wherein the client device-is configured to prevent accessing of the data if the verification of the credentials fails and/or the verification of the network fails.

4. The system for providing encryption of a disk in the client device, as recited in claim 1 , wherein the client device is configured to prevent booting of the plurality of the instructions if the disk is unmounted from the client device.

5. The system for providing encryption of a disk in the client device, as recited in claim 1 , wherein the client device is configured to prevent booting of the plurality of the instructions if a connection of the client device with the network fails.

6. The system for providing encryption of a disk in the client device, as recited in claim 1 , wherein the credentials include a username and a password.

7. The system for providing encryption of a disk in the client device, as recited in claim 1 , wherein the remote storage comprises a secure vault.

8. A method for providing encryption of a disk in a client device, the method comprising:

partially booting a plurality of instructions from a non-volatile memory;

sending a request for validation of the plurality of instructions to a Trusted Platform Module (TPM);

receiving a first fragment of a key from the TPM in response to the validation of the plurality of instructions;

sending a request for a second fragment of the key to a remote storage along with credentials, wherein:

the credentials are used to access the remote storage;

the remote storage is configured to verify a network; and

verification of the network includes checking Internet Protocol (IP) address;

receiving the second fragment of the key if the credentials are verified by the remote storage and the network is checked;

combining the first fragment of the key and the second fragment of the key to generate an encryption key;

completing the booting of the plurality of instructions from the disk by decrypting data on the disk using the encryption key; and

accessing data stored on the client device in response to the completion of the booting of the plurality of instructions from the disk,

wherein the first fragment of the key and the second fragment of the key are rotated when: stealing of sensitive data in the client device, malware attack in the client device, or a leakage of the first fragment of the key or the second fragment of the key is detected, and after the first fragment of the key and the second fragment of the key are rotated, the first fragment of the key is updated in the TPM.

9. The method for providing encryption of a disk in the client device, as recited in claim 8 , further comprising preventing booting of the plurality of instructions if the verification of the credentials fails and/or the verification of the network fails.

10. The method for providing encryption of a disk in the client device, as recited in claim 8 , further comprising preventing accessing of the data if the verification of the credentials fails and/or the verification of the network fails.

11. The method for providing encryption of a disk in the client device, as recited in claim 8 , further comprising preventing booting of the plurality of the instructions if the disk is unmounted from the client device.

12. The method for providing encryption of a disk in the client device, as recited in claim 8 , further comprising preventing booting of the plurality of the instructions if a connection of the client device with the network fails.

13. The method for providing encryption of a disk in the client device, as recited in claim 8 , wherein the credentials include a username and a password.

14. The method for providing encryption of a disk in the client device, as recited in claim 8 , wherein the remote storage comprises a secure vault.

15. A computer-program product tangibly embodied in a non-transitory machine-readable storage medium, including instructions configured to cause a client device to perform operations including:

partially booting a plurality of instructions from a non-volatile memory;

sending a request for validation of the plurality of instructions to a Trusted Platform Module (TPM);

receiving a first fragment of a key from the TPM in response to the validation of the plurality of instructions;

sending a request for a second fragment of the key to a remote storage along with credentials, wherein:

the credentials are used to access the remote storage;

the remote storage is configured to verify a network; and

verification of the network includes checking Internet Protocol (IP) address;

receiving the second fragment of the key if the credentials are verified by the remote storage and the network is checked;

combining the first fragment of the key and the second fragment of the key to generate an encryption key;

completing the booting of the plurality of instructions from a disk by decrypting data on the disk using the encryption key; and

accessing data stored on the client device in response to the completion of the booting of the plurality of instructions from the disk,

wherein the first fragment of the key and the second fragment of the key are rotated when: stealing of sensitive data in the client device, malware attack in the client device, or a leakage of the first fragment of the key or the second fragment of the key is detected, and after the first fragment of the key and the second fragment of the key are rotated, the first fragment of the key is updated in the TPM.

16. The computer-program product for providing encryption of a disk in the client device, as recited in claim 15 , further comprising preventing booting of the plurality of instructions if the verification of the credentials fails and/or the verification of the network fails.

17. The computer-program product for providing encryption of a disk in the client device, as recited in claim 15 , further comprising preventing accessing of the data if the verification of the credentials fails and/or the verification of the network fails.

18. The computer-program product for providing encryption of a disk in the client device, as recited in claim 15 , further comprising preventing booting of the plurality of the instructions if the disk is unmounted from the client device.

19. The computer-program product for providing encryption of a disk in the client device, as recited in claim 15 , further comprising preventing booting of the plurality of the instructions if a connection of the client device with the network fails.

20. The computer-program product for providing encryption of a disk in the client device, as recited in claim 15 , wherein the credentials include a username and a password.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2022
From: WOLFE, JASON LEE
To: NETSKOPE, INC.
Reel/Frame 060538/0859 →
Continuity (2)
Continuation 17389053 · Jul 29, 2021
Related Publication 20230041769A1 · Feb 9, 2023
References Cited (159)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7313679B2 · Ranganathan · 2007 [imported from a related ]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7752428B2 · Datta · 2010 [imported from a related ]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 7984286B2 · Zimmer · 2011 [imported from a related ]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8176336B1 · Mao · 2012 [imported from a related ]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8462955B2 · Ureche · 2013 [imported from a related ]
US 8566574B2 · Shriver · 2013 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8832457B2 · Kumar et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9154299B2 · Beachem · 2015 [imported from a related ]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9735960B2 · Hagiwara et al. · 2017 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10013565B2 · Martinez et al. · 2018 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10181037B2 · Novak et al. · 2019 [cited by applicant]
US 10192056B1 · Goel et al. · 2019 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10313121B2 · Young et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20060161790A1 · Hunter et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090204803A1 · Cox et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090276617A1 · Grell et al. · 2009 [cited by applicant]
US 20090276620A1 · Mccarron et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20090328195A1 · Smith · 2009 [imported from a related ]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20100303230A1 · Taveau · 2010 [imported from a related ]
US 20100313011A1 · Laffey · 2010 [imported from a related ]
US 20110072266A1 · Takayama et al. · 2011 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140108786A1 · Kreft · 2014 [cited by examiner]
US 20140164753A1 · Lee · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150288514A1 · Pahl · 2015 [imported from a related ]
US 20160070932A1 · Zimmer · 2016 [imported from a related ]
US 20160149912A1 · Scott-Nash · 2016 [cited by examiner]
US 20160283937A1 · Reese · 2016 [imported from a related ]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170097830A1 · Ehrenberg · 2017 [cited by examiner]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20170277897A1 · Jang et al. · 2017 [cited by applicant]
US 20180144146A1 · Juriasingani · 2018 [imported from a related ]
US 20180183590A1 · Kuo et al. · 2018 [cited by applicant]
US 20190045358A1 · Ahmed · 2019 [imported from a related ]
US 20190108347A1 · Ghetie · 2019 [cited by examiner]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200065496A1 · Smith · 2020 [imported from a related ]
US 20200089889A1 · Kim · 2020 [cited by examiner]
US 20200175170A1 · Diamant · 2020 [imported from a related ]
US 20200184078A1 · Hinrichs et al. · 2020 [cited by applicant]
US 20210216476A1 · Sawan · 2021 [imported from a related ]
US 20210312055A1 · Kloth · 2021 [cited by examiner]
US 20220180005A1 · Kwok Kwong Heng · 2022 [cited by examiner]
US 20220188421A1 · Flett · 2022 [cited by examiner]
US 20230237155A1 · Jacquin · 2023 [cited by examiner]
US 20240005316A1 · Doney · 2024 [cited by examiner]
CN 101038556 · 2010 [imported from a related ]
CN 101576944 · 2011 [imported from a related ]
CN 114286141A · 2022 [cited by examiner]
CN 116541891A · 2023 [cited by examiner]
EP 1063833A2 · 2000 [cited by applicant]
EP 3479283 · 2020 [imported from a related ]
EP 4354792A1 · 2024 [cited by examiner]
JP 2019016370A · 2019 [imported from a related ]
JP 2019153330 · 2019 [imported from a related ]
WO WO2022266490A1 · 2022 [cited by examiner]
Lebedev et al, “Secure Boot and Remote Attestation in the Sanctum Processor”, 2018, IEEE 31st Computer Security Foundations Symposium, p. 46-60. [imported from a related ]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff Ending Clear Text Protocols, Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Nevvton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al. “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., Farsite: Federated, available, and reliable storage for an incompletely trusted environment, SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al. , Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html# :˜: text=mode of communication.-,What are the different email proto… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” Tech Target, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?% 20Off… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1 , Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet,FortiOS- Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/%2010.1007/978-3-319… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. no date provided. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al. “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs no date provided. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs,. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]