Encrypting virtual memory

Niels Provos · Deep Blue (University of Michigan) · 2000

In modern operating systems, cryptographic file systems can protect confidential data from unauthorized access. However, once an authorized process has accessed data from a cryptographic file system, the data can appear as plaintext in the unprotected virtual memory backing store, even after system shutdown. The solution described in this paper uses swap encryption for processes in possession of confidential data. Volatile encryption keys are chosen randomly, and remain valid only for short time periods. Invalid encryption keys are deleted, effectively erasing all data that was encrypted with them. April 25, 2000 Center for Information Technology Integration University of Michigan 519 West William Street Ann Arbor, MI 48103-4943 Encrypting Virtual Memory Niels Provos Center for Information Technology Integration University of Michigan [email protected] Abstract In modern operating systems, cryptographic file systems can protect confidential data from unauthorized access....

Read the paper · More papers on PaperTik