Volatile key storage for data encryption
In a data storage system, stored data is secured using a key-based encryption algorithm. The disclosure provides mechanisms for increasing security of the stored data by storing a unique key used to encrypt and/or decrypt the data in a volatile key storage of a backplane, where power to the volatile key storage is routed through a connection that is closed when a corresponding data storage device is connected to the backplane and open when the corresponding data storage device is disconnected from the backplane.
1 . A computing system comprising:
a backplane comprising:
a backplane power source;
a first data connector configured for a data storage device,
an on-board controller configured to control data transfer between a host device and the data storage device, and
a volatile key storage device associated with the first data connector and configured to store a respective encryption key for data stored on the data storage device connected to the first data connector;
the data storage device; and
a caddy for supporting the data storage device, the caddy comprising a second data connector configured to couple to the first data connector of the backplane and a power connector configured to close a power connection from the backplane power source to the volatile key storage device while the data storage device is connected to the backplane, wherein the power connection between the volatile key storage device and the backplane power source traverses through the power connector in the caddy, and wherein the power connection from the backplane power source to the volatile key storage device is broken when the data storage device is disconnected from the backplane to cryptographically erase the data storage device.
2 . The computing system of claim 1 , wherein the backplane further comprises a backup power source coupled to the volatile key storage device, wherein the backup power source is configured to power the volatile key storage device for a finite period of time after a disruption of power supplied by the backplane power source, and wherein the respective encryption key stored in the volatile key storage device is lost and the data storage device is cryptographically erased once the finite period of time has elapsed while the disruption of power is maintained.
3 . The computing system of claim 1 , wherein the backplane further comprises a key generator configured to generate the respective encryption key for the volatile key storage device based on information from one or more data sources.
4 . The computing system of claim 1 , wherein the backplane further comprises an encryption engine comprising instructions executable by a processing component to perform one or more of encryption or decryption of data stored on the data storage device using the respective encryption key stored in the volatile key storage device.
5 . The computing system of claim 1 , wherein the on-board controller is further configured to send the respective encryption key of the volatile key storage device to the host device responsive to a request from the host device, and wherein the on-board controller is configured to transfer data between the data storage device and the host device to be encrypted or decrypted by the host device using the respective encryption key.
6 . A caddy for supporting a data storage device, the caddy comprising:
a support configured to hold the data storage device; and
a storage device-side power connector configured to be coupled to a corresponding backplane-side power connector, wherein the storage device-side power connector includes an electrical connection for completing a power connection to a volatile key storage device included in the backplane when connected to the backplane, and wherein the volatile key storage device stores a key usable to encrypt or decrypt data on the data storage device while the data storage device is connected to the backplane via the caddy.
7 . The caddy of claim 6 , further comprising a storage device-side data connector for interfacing with a backplane-side data connector to provide a data connection between the backplane and the data storage device, wherein the data connection is used to communicate data that is encrypted or decrypted by an encryption engine using the key.
8 . The caddy of claim 7 , wherein the storage device-side data connector is integrated with the storage device-side power connector.
9 . The caddy of claim 6 , wherein the storage device-side power connector is integrated in at least a portion of the support.
10 . The caddy of claim 6 , wherein the power connection to the volatile key storage device comprises a connection from a backplane power source to the volatile key storage, and wherein the power connection between the volatile key storage device and the backplane power source is opened to interrupt current flow from the backplane power source to the volatile key storage device when the storage device-side power connector is disconnected from the backplane-side power connector.
11 . A backplane computing system comprising:
a data connector configured for connecting to a data storage device;
an on-board controller configured to control data transfer between a host device and the data storage device;
a backplane power source;
a volatile key storage device associated with the data connector and configured to store a unique key usable to encrypt or decrypt data stored on the data storage device connected to the data connector; and
a power connector configured to close a power connection between the volatile key storage device and the backplane power source while connected to an associated storage-side power connector of the data storage device.
12 . The backplane computing system of claim 11 , further comprising a key generator configured to generate the unique key and transfer the unique key into the volatile key storage device.
13 . The backplane computing system of claim 12 , wherein the key generator is configured to generate the unique key using information from a plurality of data sources.
14 . The system of claim 12 , wherein the key generator is configured to generate the unique key or transfer the unique key into the volatile key storage device responsive to detection of a connection of the data storage device to the data connector or the power connector.
15 . The system of claim 11 , further comprising a backup power source coupled to the volatile key storage, wherein the backup power source is configured to power the volatile key storage device for a finite period of time after disruption of a flow of power from the backplane power source to the volatile key storage device, and wherein the unique key stored in the volatile key storage device is lost once the finite period of time has elapsed while the disruption is maintained.
16 . The system of claim 15 , further comprising a backup power source disconnect switch configured to be actuated to close or open a connection of the backup power source to the volatile key storage.
17 . The system of claim 11 , wherein the data connector is a first data connector, the power connector is a first power connector, the data storage device is a first data storage device, and the volatile key storage device is a first volatile key storage device, and wherein the system further comprises a second data connector, a second volatile key storage device, and a second power connector, and wherein the second power connector is configured to close a second power connection between the second volatile key storage device and the backplane power source while connected to an associated storage-side power connector of a second data storage device.
18 . The system of claim 17 , wherein the unique key is a first unique key stored in the first volatile key storage device, wherein a second unique key is stored in the second volatile key storage device while the second data storage device is connected to the second power connector, and wherein the first unique key is maintained in the first volatile key storage device and the second unique key is lost from the second volatile key storage device responsive to disconnection of the second data storage device from the second power connector while the first data storage device remains connected to the first power connector.
19 . The system of claim 11 , further comprising an encryption engine, the encryption engine including instructions executable by the on-board controller or a processing component of the system to encrypt or decrypt data on the data storage device using the unique key stored in the volatile key storage while the data storage device is connected to the power connector.
20 . The system of claim 11 , wherein the host device or the data storage device comprises an encryption engine, wherein the on-board controller controls a transfer and storage of encrypted data from the host device to the data storage device and a retrieval of the unique key from the volatile key storage device to the encryption engine, and wherein the encrypted data is encrypted or decrypted by the encryption engine using the unique key retrieved from the volatile key storage device.