| CPC G06F 21/78 (2013.01) [G06F 21/602 (2013.01); G06F 21/6209 (2013.01)] | 26 Claims |

|
1. A method for secure access control to a data storage system for a host apparatus by-an access control device, the method comprising:
as part of a first operating mode of the access control device, receiving user data (D) from the host apparatus and transmitting of the same in unchanged or modified form (D/D′) to the data storage system for local storage;
exchanging a first cryptographic secret (K) with a computer system to enable data to be encrypted by the access control device as a function of the first cryptographic secret (K);
receiving a data read request (RR) for at least a portion of the user data stored in the data storage system;
in response to the data read request (RR), transitioning the access control device to a second mode of operation in which the access control device is configured to carry out read access but no write or delete access to the data storage system; and
in the second operating mode, retrieving user data (D/D′) requested according to the data read request (RR) from the data storage system, encrypting the user data (D/D′) using the first cryptographic secret (K) or a key derived as a function thereof in accordance with a key generation rule to produce encrypted user data (K(D/D′)) and transmitting the encrypted user data (K(D/D′)) to a predetermined user data recipient;
wherein as part of the method, the user data (D/D′) is processed in such a way that the encrypted user data (K(D/D′) transmitted as part of the second operating mode represent an information which is extractable therefrom for the user data recipient without any decryption of the encrypted user data (K(D/D′)), which information represents an identity (ID) of the access control device and/or of the data storage system or which allows a deduction of the same.
|