Management of cryptography keys for data encapsulation in classified network has been troubling people. The aim of this article is to present a new mechanism for protecting classified data by using trusted cryptography module. The solution contains both runtime data protection and static file data protection. The key technique is using the feature of cryptography keys hidden technology of trusted cryptography module. The result of a simple performance test of the trusted cryptography module is provided while the solution for its insufficiency is also presented. By using the trusted cryptography module, an implementation with experiment result of a network control is presented.