File access security method and means
First Claim
Patent Images
1. Method of securing data files in storage against unauthorized access, comprising the steps of:
- encrypting file data as a selected logical combination thereof with an initial one of a plurality of encryption key codes to produce file data in encrypted form for storage at selected file address locations;
establishing a record of accesses to each selected file address location and the one of the plurality of encryption key codes with which the file data at the address location is encrypted;
processing a request for access to file data at a selected file address location by determining from the record the number of prior accesses thereof and the encryption key code associated therewith;
decrypting file data at the selected file address location using said associated encryption key code;
re-encrypting file data for said selected file address location using a new one of said plurality of encryption key codes in said selected logical combination;
storing the newly re-encrypted file data at the accessed file address location; and
modifying the record to indicate an additional access to the selected file address location and the new encryption key code associated therewith.
1 Assignment
0 Petitions
Accused Products
Abstract
An improved file access security technique and associated apparatus accesses data which is stored in encrypted form under one encryption key and re-stores the data re-encrypted under another encryption key, and produces a record of each access and data re-encryption both as the control source of encryption keys for access and re-entry of encrypted data and as a secured audit record of users that had access to each file.
392 Citations
13 Claims
-
1. Method of securing data files in storage against unauthorized access, comprising the steps of:
-
encrypting file data as a selected logical combination thereof with an initial one of a plurality of encryption key codes to produce file data in encrypted form for storage at selected file address locations; establishing a record of accesses to each selected file address location and the one of the plurality of encryption key codes with which the file data at the address location is encrypted; processing a request for access to file data at a selected file address location by determining from the record the number of prior accesses thereof and the encryption key code associated therewith; decrypting file data at the selected file address location using said associated encryption key code; re-encrypting file data for said selected file address location using a new one of said plurality of encryption key codes in said selected logical combination; storing the newly re-encrypted file data at the accessed file address location; and modifying the record to indicate an additional access to the selected file address location and the new encryption key code associated therewith. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. Apparatus for securing data files in storage against unauthorized access, comprising:
-
storage means for storing file data in encrypted form at selectable file address locations; encryption means for supplying encrypted file data to a selected file address location as the logical encoding combination of file data and an encryption key signal applied thereto; generator means for applying selected encryption key signals to the encryption means; record means for producing indication of selected file address locations and key code signals associated with encryption of file data stored therein; circuit means responsive to identification of a selected file address location for determining from said record means the encryption key signal associated therewith for setting the generator means to supply the associated encryption key signal; decryption means disposed to receive encryption key signals from the generator means and encrypted file data from the storage means and operable in accordance with said logical encoding combination to decrypt the file data at said selected file address location; and means operable upon the decrypted file data for altering the generator means to supply a new encryption key signal for restoring the file data at the selected file address location newly encrypted with a new encryption key signal, said means altering the record means to produce an indication of the new encryption key signal associated with file data in the selected file address location. - View Dependent Claims (8, 9, 10, 11, 12)
-
-
13. A file access record produced by the process comprising the steps of:
-
storing at selected file address locations file data that is encrypted as the logical combination of file data and selected ones of a plurality of encryption key signals; decrypting file data at a selected file address location using the encryption key signal associated therewith in accordance with said logical combination; re-encrypting the decrypted file data as a logical combination thereof and a new encryption key signal for restoring at the corresponding file address location; and producing said file access record as the compilation at least of the number of times each selected file address location was decrypted and information indicative of the encryption key signals with which the file data at each selected file address location was re-encrypted and re-stored therein.
-
Specification