Encrypted io user connections between IO users and storage volumes
Techniques are provided for encrypting IO (input/output) operations between IO users and storage volumes. One method comprises obtaining IO user context information associated with an established IO user connection between a processor-based IO user and at least a portion of a storage volume on a storage array, wherein the IO user context information comprises one or more keys for the established IO user connection; encrypting a payload of a given IO operation using at least one of the one or more keys; and transmitting the encrypted payload and at least a portion of the IO user context information over the established IO user connection, wherein the processor-based IO user and/or the storage array decrypt the encrypted payload using at least one of the one or more keys.
1 . A method, comprising:
obtaining IO (input/output) user context information associated with an established IO user connection, of a plurality of established IO user connections, between a given processor-based IO user, of a plurality of processor-based IO users, and at least a portion of at least one storage volume on a storage array, wherein the IO user context information comprises one or more keys for the established IO user connection, wherein a host device is associated with the plurality of processor-based IO users, wherein at least two of the plurality of processor-based IO users are associated with different ones of the plurality of established IO user connections between a respective processor-based IO user and the at least the portion of the at least one respective storage volume for the respective processor-based IO user;
encrypting a payload of a given IO operation from the given processor-based IO user using at least one of the one or more keys; and
transmitting the encrypted payload and at least a portion of the IO user context information over the established IO user connection for the given processor-based IO user, wherein one or more of the given processor-based IO user and the storage array decrypt the encrypted payload using at least one of the one or more keys, wherein the given IO operation is encrypted on the established IO user connection for the given processor-based IO user between the host device and the storage array;
wherein the method is performed by at least one processing device comprising a processor coupled to a memory.
2 . The method of claim 1 , wherein the given processor-based IO user stores the one or more keys in a secure memory.
3 . The method of claim 1 , wherein an establishing of the IO user connection comprises defining an encryption protocol for the IO user connection.
4 . The method of claim 1 , wherein an establishing of the IO user connection comprises the given processor-based IO user and the storage array sharing one or more of: (i) the one or more keys and (ii) a shared secret for generation of the one or more keys.
5 . The method of claim 1 , wherein the at least the portion of the IO user context information is transmitted in an unencrypted form.
6 . The method of claim 1 , wherein the given processor-based IO user comprises one or more of an application, an application acting on behalf of another user, an operating system of the host device, at least one processing device and a virtualized computing resource.
7 . The method of claim 1 , wherein the given processor-based IO user comprises an application and wherein one or more wrapper libraries perform one or more of a decryption function for read operations and an encryption function for write operations of the application over the established IO user connection.
8 . The method of claim 1 , further comprising initiating a rotation of the one or more keys.
9 . The method of claim 1 , further comprising the given processor-based IO user sending at least one read request to the storage array, wherein the storage array: (i) encrypts a payload of a read response to the at least one read request using an encryption key for the established IO user connection, and (ii) sends the encrypted payload and at least a portion of the IO user context information over the established IO user connection to the given processor-based IO user, and wherein the given processor-based IO user decrypts the encrypted payload using a decryption key for the established IO user connection.
10 . The method of claim 1 , further comprising the given processor-based IO user sending at least one write operation to the storage array, wherein the given processor-based IO user: (i) encrypts a payload of the at least one write operation using an encryption key for the established IO user connection, and (ii) sends the encrypted payload and at least a portion of the IO user context information over the established IO user connection to the storage array, and wherein the storage array decrypts the encrypted payload using a decryption key for the established IO user connection and stores the decrypted payload.
11 . The method of claim 1 , further comprising controlling a flow of the given IO operation over the established IO user connection using an out-of-band control path, for the given processor-based IO user, between the host device and at least one controller of the storage array.
12 . The method of claim 1 , wherein one or more of (i) a shared secret for generating one or more of at least one encryption key and at least one decryption key for the established IO user connection; and (ii) one or more of at least one encryption key and at least one decryption key for the established IO user connection are shared using an out-of-band control path, for the given processor-based IO user, between the host device and at least one controller of the storage array.
13 . An apparatus comprising:
at least one processing device comprising a processor coupled to a memory;
the at least one processing device being configured to implement the following steps:
obtaining IO (input/output) user context information associated with an established IO user connection, of a plurality of established IO user connections, between a given processor-based IO user, of a plurality of processor-based IO users, and at least a portion of at least one storage volume on a storage array, wherein the IO user context information comprises one or more keys for the established IO user connection, wherein a host device is associated with the plurality of processor-based IO users, wherein at least two of the plurality of processor-based IO users are associated with different ones of the plurality of established IO user connections between a respective processor-based IO user and the at least the portion of the at least one respective storage volume for the respective processor-based IO user;
encrypting a payload of a given IO operation from the given processor-based IO user using at least one of the one or more keys; and
transmitting the encrypted payload and at least a portion of the IO user context information over the established IO user connection for the given processor-based IO user, wherein one or more of the given processor-based IO user and the storage array decrypt the encrypted payload using at least one of the one or more keys, wherein the given IO operation is encrypted on the established IO user connection for the given processor-based IO user between the host device and the storage array.
14 . The apparatus of claim 13 , further comprising initiating a rotation of the one or more keys.
15 . The apparatus of claim 13 , further comprising the given processor-based IO user sending at least one read request to the storage array, wherein the storage array: (i) encrypts a payload of a read response to the at least one read request using an encryption key for the established IO user connection, and (ii) sends the encrypted payload and at least a portion of the IO user context information over the established IO user connection to the given processor-based IO user, and wherein the given processor-based IO user decrypts the encrypted payload using a decryption key for the established IO user connection.
16 . The apparatus of claim 13 , further comprising the given processor-based IO user sending at least one write operation to the storage array, wherein the given processor-based IO user: (i) encrypts a payload of the at least one write operation using an encryption key for the established IO user connection, and (ii) sends the encrypted payload and at least a portion of the IO user context information over the established IO user connection to the storage array, and wherein the storage array decrypts the encrypted payload using a decryption key for the established IO user connection and stores the decrypted payload.
17 . A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:
obtaining IO (input/output) user context information associated with an established IO user connection, of a plurality of established IO user connections, between a given processor-based IO user, of a plurality of processor-based IO users, and at least a portion of at least one storage volume on a storage array, wherein the IO user context information comprises one or more keys for the established IO user connection, wherein a host device is associated with the plurality of processor-based IO users, wherein at least two of the plurality of processor-based IO users are associated with different ones of the plurality of established IO user connections between a respective processor-based IO user and the at least the portion of the at least one respective storage volume for the respective processor-based IO user;
encrypting a payload of a given IO operation from the given processor-based IO user using at least one of the one or more keys; and
transmitting the encrypted payload and at least a portion of the IO user context information over the established IO user connection for the given processor-based IO user, wherein one or more of the given processor-based IO user and the storage array decrypt the encrypted payload using at least one of the one or more keys, wherein the given IO operation is encrypted on the established IO user connection for the given processor-based IO user between the host device and the storage array.
18 . The non-transitory processor-readable storage medium of claim 17 , further comprising initiating a rotation of the one or more keys.
19 . The non-transitory processor-readable storage medium of claim 17 , further comprising the given processor-based IO user sending at least one read request to the storage array, wherein the storage array: (i) encrypts a payload of a read response to the at least one read request using an encryption key for the established IO user connection, and (ii) sends the encrypted payload and at least a portion of the IO user context information over the established IO user connection to the given processor-based IO user, and wherein the given processor-based IO user decrypts the encrypted payload using a decryption key for the established IO user connection.
20 . The non-transitory processor-readable storage medium of claim 17 , further comprising the given processor-based IO user sending at least one write operation to the storage array, wherein the given processor-based IO user: (i) encrypts a payload of the at least one write operation using an encryption key for the established IO user connection, and (ii) sends the encrypted payload and at least a portion of the IO user context information over the established IO user connection to the storage array, and wherein the storage array decrypts the encrypted payload using a decryption key for the established IO user connection and stores the decrypted payload.