Data access control systems and methods

    公开(公告)号:US10049225B2

    公开(公告)日:2018-08-14

    申请号:US15656966

    申请日:2017-07-21

    摘要: Various hardware and software configurations are described herein which provide improved security and control over protected data. In some embodiments, a computer includes a main motherboard card coupled to all input/output devices connected to the computer, and a trusted operating system operates on the main motherboard which includes an access control module for controlling access to the protected data in accordance with rules. The trusted operating system stores the protected data in an unprotected form only on the memory devices on the main motherboard. The computer may also have a computer card coupled to the main motherboard via a PCI bus, on which is operating a guest operating system session for handling requests for data from software applications on the computer. A tamper detection mechanism is provided in the computer for protecting against attempts to copy the unprotected form of the protected data onto memory devices other than the one or more memory devices used by the motherboard or computer card.

    DATA ACCESS CONTROL SYSTEMS AND METHODS
    12.
    发明申请
    DATA ACCESS CONTROL SYSTEMS AND METHODS 有权
    数据访问控制系统和方法

    公开(公告)号:US20160117514A1

    公开(公告)日:2016-04-28

    申请号:US14923344

    申请日:2015-10-26

    摘要: Various hardware and software configurations are described herein which provide improved security and control over protected data. In some embodiments, a computer includes a main motherboard card coupled to all input/output devices connected to the computer, and a trusted operating system operates on the main motherboard which includes an access control module for controlling access to the protected data in accordance with rules. The trusted operating system stores the protected data in an unprotected form only on the memory devices on the main motherboard. The computer may also have a computer card coupled to the main motherboard via a PCI bus, on which is operating a guest operating system session for handling requests for data from software applications on the computer. A tamper detection mechanism is provided in the computer for protecting against attempts to copy the unprotected form of the protected data onto memory devices other than the one or more memory devices used by the motherboard or computer card.

    摘要翻译: 本文描述了各种硬件和软件配置,其提供改进的对受保护数据的安全性和控制。 在一些实施例中,计算机包括耦合到连接到计算机的所有输入/输出设备的主主板卡,并且可信操作系统在主主板上操作,其包括用于根据规则控制对受保护数据的访问的访问控制模块 。 受信任的操作系统仅将保护的数据存储在主主板上的存储设备上。 计算机还可以具有通过PCI总线耦合到主母板的计算机卡,在其上操作客户操作系统会话以处理来自计算机上的软件应用的数据请求。 在计算机中提供篡改检测机制,用于防止将未受保护形式的受保护数据复制到除主板或计算机卡使用的一个或多个存储设备之外的存储器设备上的尝试。

    Data access control systems and methods
    13.
    发明授权
    Data access control systems and methods 有权
    数据访问控制系统和方法

    公开(公告)号:US09171176B2

    公开(公告)日:2015-10-27

    申请号:US14307394

    申请日:2014-06-17

    摘要: Various hardware and software configurations are described herein which provide improved security and control over protected data. In some embodiments, a computer includes a main motherboard card coupled to all input/output devices connected to the computer, and a trusted operating system operates on the main motherboard which includes an access control module for controlling access to the protected data in accordance with rules. The trusted operating system stores the protected data in an unprotected form only on the memory devices on the main motherboard. The computer may also have a computer card coupled to the main motherboard via a PCI bus, on which is operating a guest operating system session for handling requests for data from software applications on the computer. A tamper detection mechanism is provided in the computer for protecting against attempts to copy the unprotected form of the protected data onto memory devices other than the one or more memory devices used by the motherboard or computer card.

    摘要翻译: 本文描述了各种硬件和软件配置,其提供改进的对受保护数据的安全性和控制。 在一些实施例中,计算机包括耦合到连接到计算机的所有输入/输出设备的主主板卡,并且可信操作系统在主主板上操作,其包括用于根据规则控制对受保护数据的访问的访问控制模块 。 受信任的操作系统仅将保护的数据存储在主主板上的存储设备上。 计算机还可以具有通过PCI总线耦合到主母板的计算机卡,在其上操作客户操作系统会话以处理来自计算机上的软件应用的数据请求。 在计算机中提供篡改检测机制,用于防止将未受保护形式的受保护数据复制到除主板或计算机卡使用的一个或多个存储设备之外的存储器设备上的尝试。