IP Library Granted Patent US 9,384,353
Granted Patent B2
US 9,384,353 · App. 14/657,005 · Granted Jul 5, 2016

System and method for encryption of disk based on pre-boot compatibility testing

Inventor: Evgeny A. Yakovlev (Moscow, RU)
Assignee: AO Kaspersky Lab
G06F21/575G06F11/1417G06F21/78G06F2221/2107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,384,353
App. No.
14/657,005
Granted
Jul 5, 2016
Kind
B2
Abstract

Disclosed are systems, methods and computer program products for encryption of disk based on pre-boot compatibility testing. An example method includes upon determining, by a processor, no test booting of the computer, performing one or more pre-boot compatibility tests to boot an operating system of the computer; upon detecting a successful test booting, performing booting the operating system of the computer or performing the one or more pre-boot compatibility tests again; upon detecting an unsuccessful test booting, restoring a process of ordinary booting of the operating system and performing an ordinary booting of the operating system; determining one or more encryption policies applicable to a pre-boot execution stage of the computer; and comparing results of the one or more pre-boot compatibility tests with the encryption policies to determine whether to apply a full disk encryption to the boot disk.

Claims (50)

1. A method of full disk encryption of a boot disk of a computer, comprising:

upon determining, by a processor, no test booting of the computer, performing one or more pre-boot compatibility tests to boot an operating system of the computer;

upon detecting a successful test booting, performing booting the operating system of the computer or performing the one or more pre-boot compatibility tests again;

upon detecting an unsuccessful test booting, restoring a process of ordinary booting of the operating system and performing an ordinary booting of the operating system;

determining one or more encryption policies applicable to a pre-boot execution stage of the computer; and

comparing results of the one or more pre-boot compatibility tests with the encryption policies to determine whether to apply a full disk encryption to the boot disk.

2. The method of claim 1 , further comprising:

prior to performing the one or more pre-boot compatibility tests, changing a booting process of the computer to enable the one or more pre-boot compatibility tests; and

rebooting the computer.

3. The method of claim 1 , further comprising:

upon determining to apply the full disk encryption:

detecting that the full disk encryption cannot be performed on the computer, wherein the computer is part of a corporate network; and

alerting a network administrator of the corporate network that the full disk encryption cannot be performed.

4. The method of claim 1 , further comprising comparing the encryption policies with the pre-boot compatibility tests after starting the operating system of the computer.

5. The method of claim 1 , further comprising the encryption policies with the one or more pre-boot compatibility tests by one or more of: the computer, a network security server, and a pre-boot agent.

6. The method of claim 1 , further comprising performing the one or more pre-boot compatibility tests on demand and without following by the full disk encryption.

7. The method of claim 1 , further comprising using a flag to indicate a status of the test booting.

8. A system of full disk encryption of a boot disk of a computer, comprising:

a processor configured to:

upon determine, by a processor, no test booting of the computer, performing one or more pre-boot compatibility tests to boot an operating system of the computer;

upon detecting a successful test booting, perform booting the operating system of the computer or perform the one or more pre-boot compatibility tests again;

upon detecting an unsuccessful test booting, restore a process of ordinary booting of the operating system and perform an ordinary booting of the operating system;

determine one or more encryption policies applicable to a pre-boot execution stage of the computer; and

compare results of the one or more pre-boot compatibility tests with the encryption policies to determine whether to apply a full disk encryption to the boot disk.

9. The system of claim 8 , wherein the processor is further configured to:

prior to performing the one or more pre-boot compatibility tests, change a booting process of the computer to enable the one or more pre-boot compatibility tests; and

reboot the computer.

10. The system of claim 8 , wherein, upon determining to apply the full disk encryption, the processor is further configured to:

determine that the full disk encryption cannot be performed on the computer, wherein the computer is part of a corporate network; and

alert a network administrator of the corporate network that the full disk encryption cannot be performed.

11. The system of claim 8 , wherein the processor is further configured to compare the encryption policies with the one or more pre-boot compatibility tests after starting the operating system of the computer.

12. The system of claim 8 , wherein the processor is further configured to compare the encryption policies with the one or more pre-boot compatibility tests by one or more of: the computer, a network security server, and a pre-boot agent.

13. The system of claim 8 , wherein the processor is further configured to perform the one or more pre-boot compatibility tests on demand and without following by the full disk encryption.

14. The system of claim 8 , wherein the processor is further configured to use a flag to indicate a status of the test booting.

15. A computer program product stored on a non-transitory computer-readable storage medium, the computer program product comprising computer-executable instructions for full disk encryption of a boot disk of a computer, including instructions for:

upon determining no test booting of the computer, performing one or more pre-boot compatibility tests to boot an operating system of the computer;

upon detecting a successful test booting, performing booting the operating system of the computer or performing the one or more pre-boot compatibility tests again;

upon detecting an unsuccessful test booting, restoring a process of ordinary booting of the operating system and performing an ordinary booting of the operating system;

determining one or more encryption policies applicable to a pre-boot execution stage of the computer; and

comparing results of the one or more pre-boot compatibility tests with the encryption policies to determine whether to apply a full disk encryption to the boot disk.

16. The computer program product of claim 15 , further comprising instructions for:

prior to performing the one or more pre-boot compatibility tests, changing a booting process of the computer to enable the one or more pre-boot compatibility tests; and

rebooting the computer.

17. The computer program product of claim 15 , further comprising instructions for:

upon determining to apply the full disk encryption:

determining that the full disk encryption cannot be performed on the computer, wherein the computer is part of a corporate network; and

alerting a network administrator of the corporate network that the full disk encryption cannot be performed.

18. The computer program product of claim 15 , further comprising instructions for comparing encryption policies with the one or more pre-boot compatibility tests after starting the operating system of the computer by one or more of: the computer, a network security server, and a pre-boot agent.

19. The computer program product of claim 15 , further comprising instructions for performing the one or more pre-boot compatibility tests on demand and without following by the full disk encryption.

20. The computer program product of claim 15 , further comprising instructions for using a flag to indicate a status of the test booting.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2015
From: YAKOVLEV, EVGENY A.
To: KASPERSKY LAB ZAO
Reel/Frame 035160/0945 →
Continuity (2)
Continuation 14294311 · Jun 3, 2014
Related Publication 20150347757A1 · Dec 3, 2015