EP1964019A2

Method, apparatus and system for performing access control and intrusion detection on encrypted data

Abstract

This record has no abstract on file.

Term

Projected expiry 14 December 2026.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

21 claims: 3 independent, 18 dependent

  1. 1
    Claims of equivalent WO 2007111662 A2 CLAIMS What is claimed is:1. A method comprising: identifying from a first partition a memory location of an application in a memory of a host operating system ("OS"), the host OS residing in a second partition;identifying a session key within the memory location of the application in the host OS utilizing Direct Memory Access ("DMA");copying the session key into a memory in the first partition;utilizing the session key in the first partition to decrypt encrypted data received in the first partition from the application;and examining decrypted data.
  2. 2
    The method according to Claim 1 wherein the first partition is one of an Active Management Technologies ("AMT") partition, a Manageability Engine ("ME") partition, a Platform Resource Layer ("PRL") platform and a virtual machine ("VM").
  3. 3
    The method according to Claim 3 wherein the AMT partition is a virtualized partition.
  4. 4
    The method according to Claim 1 further comprising one of:preventing transmission of the encrypted data from the application if the encrypted data is compromised;and sending the data to a network interface card ("NIC") to be transmitted from the node if the data is uncompromised.
  5. 5
    The method according to Claim 1 further comprising establishing a connection between the first partition and the second partition.
  6. 6
    The method according to Claim 5 wherein establishing the connection further comprises:sending a request for a connection from the second partition to the first partition, the request including information pertaining to the connection;storing the information pertaining to the connection;generating the session key in the second partition;and making available to the first partition the information pertaining to the session key.
  7. 7
    The method according to Claim 6 wherein sending the request for the connection further comprises automatically establishing the connection from the second partition to the first partition.
  8. 8
    A node, comprising:a host partition running a host operating system and an application, the application capable of running in a portion of memory of the host operating system, the application further capable of generating a session key in the portion of the memory running the application, the application further capable of utilizing the session key to encrypt data;and a monitoring partition capable of receiving the encrypted data from the application in the host partition, the monitoring partition further capable of utilizing direct memory access ("DMA") to locate and copy the session key from the portion of memory running the application, the monitoring partition additionally capable of utilizing the session key copied from the portion of memory running the application to decrypt the encrypted data.
  9. 9
    The node according to Claim 8 further comprising:a network interface card ("NIC") capable of establishing a connection between the host partition and the monitoring partition.
  10. 10
    .The node according to Claim 9 wherein the NIC is further capable of routing a request for the connection from the host partition to the monitoring partition.
  11. 11
    The node according to Claim 10 wherein routing the request for the connection from the host partition to the monitoring partition further comprises:the host partition capable of sending the request for a connection via the NIC to the monitoring partition, the request including information pertaining to the connection, the host partition further capable of storing the information pertaining to the connection, and the host partition additionally capable of making available to the monitoring partition the information pertaining to the session key generated by the application.
  12. 12
    The node according to Claim 9 wherein the monitoring partition is additionally capable of one of:preventing transmission of the encrypted data from the application if the encrypted data is compromised;and sending the data to a network interface card ("NIC") to be transmitted from the node if the data is uncompromised.
  13. 13
    The node according to Claim 8 wherein the monitoring partition is one of an Active Management Technologies ("AMT") partition, a Manageability Engine ("ME") partition, a Platform Resource Layer ("PRL") platform and a virtual machine ("VM").
  14. 14
    The node according to Claim 13 wherein the AMT partition is a VM running in a virtualized environment.
  15. 15
    The node according to Claim 8 further comprising:a main processor;and a dedicated processor dedicated to the monitoring partition.
  16. 16
    An article comprising a machine-accessible medium having stored thereon instructions that, when executed by a machine, cause the machine to:identify from a first partition a memory location of an application in a memory of a host operating system ("OS"), the host OS residing in a second partition;identify a session key within the memory location of the application in the host OS utilizing Direct Memory Access ("DMA");copy the session key into a memory in the first partition;utilize the session key in the first partition to decrypt encrypted data received in the first partition from the application;and examine decrypted data.
  17. 17
    The article according to Claim 16 wherein the first partition is one of an Active Management Technologies ("AMT") partition, a Manageability Engine ("ME") partition, a Platform Resource Layer ("PRL") platform and a virtual machine ("VM").
  18. 18
    The article according to Claim 17 wherein the AMT partition is a virtualized partition.
  19. 19
    The article according to Claim 16 wherein the instructions, when executed by the machine, further cause the machine to:prevent transmission of the encrypted data from the application if the encrypted data is compromised;and send the data to a network interface card ("NIC") to be transmitted from the node if the data is uncompromised.
  20. 20
    The article according to Claim 16 wherein the instructions, when executed by the machine, further cause the machine to establish a connection between the first partition and the second partition.
  21. 21
    The article according to Claim 20 wherein the instructions, when executed by the machine further cause the machine to establish the connection by:sending a request for a connection from the second partition to the first partition, the request including information pertaining to the connection;storing the information pertaining to the connection;generating the session key in the second partition;and making available to the first partition the information pertaining to the session key.