The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 21, 2021

Filed:

Jul. 12, 2018
Applicant:

Acronis International Gmbh, Schaffhausen, CH;

Inventors:

Alexey Kostyushko, Moscow, RU;

Stanislav Protasov, Moscow, RU;

Serguei Beloussov, Costa del Sol, SG;

Assignee:

Acronis International GmbH, Schaffhausen, CH;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 21/56 (2013.01); G06F 21/55 (2013.01); G06F 7/58 (2006.01); H04L 29/06 (2006.01); H04L 9/08 (2006.01); G06F 21/60 (2013.01); H04L 9/00 (2006.01);
U.S. Cl.
CPC ...
G06F 21/565 (2013.01); G06F 7/582 (2013.01); G06F 21/554 (2013.01); G06F 21/568 (2013.01); G06F 21/602 (2013.01); H04L 9/002 (2013.01); H04L 9/0861 (2013.01); H04L 63/0428 (2013.01); H04L 63/145 (2013.01);
Abstract

A technique is described for protecting file data from malicious programs, in particularly, by decrypting data that has been maliciously encrypted by software such as ransomware. The described technique generates a copy of a first block of a plurality of files stored on a computing device, and also intercepts request(s) from a process executing on the computing device to obtain certain types of random data and system entropy, which are recorded. When the system detects that the plurality of files have been encrypted by a malicious program, the described system determines a cryptographic key determined based on the generated copies of the first blocks of the plurality of files and on the recorded random data, and uses that key to decrypt the plurality of files.


Find Patent Forward Citations

Loading…