CPSec DLP: Kernel‐Level Content Protection Security System of Data Leakage Prevention. Issue 4 (1st July 2017)
- Record Type:
- Journal Article
- Title:
- CPSec DLP: Kernel‐Level Content Protection Security System of Data Leakage Prevention. Issue 4 (1st July 2017)
- Main Title:
- CPSec DLP: Kernel‐Level Content Protection Security System of Data Leakage Prevention
- Authors:
- Ma, Zhaofeng
- Abstract:
- Abstract : Data leakage prevention (DLP) is very important for sensitive or unauthorized data protection, however, most current DLP technologies are based on content monitor, detection and filtering, which can be easily bypassed or cheated. We propose a thorough and highlevel Content protection secure scheme of DLP (CPSec DLP) based on kernel‐level mandatory encryption, in which we proposed mutual authentication and key agreement method between client and server, and we adopted SM2 algorithm for session key management; and we propose kernel‐level mandatory secure middleware for unstructured data protection, in which the secure middleware works in File system driver (FSD) layer supporting for "write‐encryption, open‐decryption" operation, once the data is written to storage space either in hard‐disk or USB disk the data is mandatorily encrypted, while when the data is open the mandatory secure middleware decrypts the data to plain in system memory. Moreover we propose data share and delivery among domain internal users and external customers. In the CPSec DLP scheme, the encryption algorithms, security policy and rules can be dynamically parameterized when necessary, while in the lifecycle the data management can only be used according to its usage control rules, such as read‐only, write, save, print, export, backup rights. Upon the proposed CPSec DLP, we implemented the CPSec DLP system in kernel‐level driver layer based on FSD, which supports parameterized process andAbstract : Data leakage prevention (DLP) is very important for sensitive or unauthorized data protection, however, most current DLP technologies are based on content monitor, detection and filtering, which can be easily bypassed or cheated. We propose a thorough and highlevel Content protection secure scheme of DLP (CPSec DLP) based on kernel‐level mandatory encryption, in which we proposed mutual authentication and key agreement method between client and server, and we adopted SM2 algorithm for session key management; and we propose kernel‐level mandatory secure middleware for unstructured data protection, in which the secure middleware works in File system driver (FSD) layer supporting for "write‐encryption, open‐decryption" operation, once the data is written to storage space either in hard‐disk or USB disk the data is mandatorily encrypted, while when the data is open the mandatory secure middleware decrypts the data to plain in system memory. Moreover we propose data share and delivery among domain internal users and external customers. In the CPSec DLP scheme, the encryption algorithms, security policy and rules can be dynamically parameterized when necessary, while in the lifecycle the data management can only be used according to its usage control rules, such as read‐only, write, save, print, export, backup rights. Upon the proposed CPSec DLP, we implemented the CPSec DLP system in kernel‐level driver layer based on FSD, which supports parameterized process and document format for unstructured data leakage protection. Large amount of experiments manifest the proposed scheme is secure, reliable, extendible and efficient for kinds of format unstructured data leakage protection. … (more)
- Is Part Of:
- Chinese journal of electronics. Volume 26:Issue 4(2017)
- Journal:
- Chinese journal of electronics
- Issue:
- Volume 26:Issue 4(2017)
- Issue Display:
- Volume 26, Issue 4 (2017)
- Year:
- 2017
- Volume:
- 26
- Issue:
- 4
- Issue Sort Value:
- 2017-0026-0004-0000
- Page Start:
- 827
- Page End:
- 836
- Publication Date:
- 2017-07-01
- Subjects:
- Content protection security -- Unstructured data leakage protection -- Kernel‐level mandatory encryption / decryption -- Usage controls.
cryptography -- data protection -- device drivers -- middleware -- storage management
kernel‐level content protection security system -- data leakage prevention -- unauthorized data protection -- content monitor -- kernel‐level mandatory encryption -- mutual authentication -- key agreement method -- SM2 algorithm -- session key management -- kernel‐level mandatory secure middleware -- file system driver layer -- FSD layer -- write‐encryption‐open‐decryption operation -- storage space -- USB disk -- hard‐disk -- system memory -- data share -- data delivery -- CPSec DLP scheme -- security policy -- data management -- kernel‐level driver layer -- unstructured data leakage protection
Electronics -- Periodicals
Electronics -- China -- Periodicals
Electronics
China
Periodicals
621.38105 - Journal URLs:
- https://ietresearch.onlinelibrary.wiley.com/journal/20755597 ↗
http://ieeexplore.ieee.org/servlet/opac?punumber=7479413 ↗
http://ieeexplore.ieee.org/Xplore/home.jsp ↗ - DOI:
- 10.1049/cje.2017.05.002 ↗
- Languages:
- English
- ISSNs:
- 1022-4653
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3180.317180
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 23030.xml