IP Library Granted Patent US 7,277,941
Granted Patent B2
US 7,277,941 · App. 10/990,284 · Granted Oct 2, 2007

System and method for providing encryption in a storage network by storing a secured encryption key with encrypted archive data in an archive storage device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,277,941
App. No.
10/990,284
Granted
Oct 2, 2007
Kind
B2
Abstract

In accordance with embodiments of the invention, a method is provided for performing a storage operation in a pipeline storage system in which one or more data streams containing data to be stored are written into data chunks. The method includes generating an encryption key associated with a first archive file to be stored when encryption is requested for the storage operation, encrypting the archive data from the data stream using the encryption key to create an encrypted data chunk when a data stream containing the archive file is processed in the pipeline storage system, storing the encrypted data chunk on a storage medium, and storing the encryption key in a manner accessible during a restore operation of the encrypted data chunk.

Claims (28)

1. A method for performing a storage operation in which one or more data streams write data to be stored to a data archive storage device, the method comprising:

when a user requests encryption of at least part of the data to be stored in the storage operation, generating an encryption key associated with the at least part of the data to be stored;

when a data stream stores the at least part of the data to be stored, encrypting the at least part of the data to be stored with an encryption key to create an encrypted archive data set;

storing the encrypted archive data set on the data archive storage device; and

storing the encryption key on the data archive storage device, wherein the encryption key is stored in at least one of two user-selectable secure configurations, a first configuration being a scrambled configuration of the encryption key such that the scrambled encryption key is capable of being automatically unscrambled by the system, and a second configuration being an encrypted configuration such that the encrypted encryption key is capable of being decrypted by a password or information received from the user.

2. The method of claim 1 , wherein the storage operation comprises a plurality of pipeline storage processes arranged in stages including an encryption process, and wherein encrypting the first archive file is performed by the encryption process.

3. The method of claim 1 , further comprising:

tagging the encrypted archive data set to indicate that the archive data is encrypted.

4. The method of claim 3 , wherein the tagged encrypted archive date set contains the encryption key.

5. The method of claim 1 , further comprising: restoring the data stored in the encrypted archive data set by retrieving the encryption key and decrypting the encrypted archive data set.

6. A system for encrypting archive data during a data storage operation, comprising:

means for generating an encryption key associated with the archive data, wherein the archive data is a copy of data created by a file system;

means for encrypting the archive data with the encryption key to create an encrypted data set;

means for storing the encrypted data set on a storage medium;

means for storing the encryption key on the storage medium; and

means for securing the encryption key, wherein the means for securing the encryption key include means for receiving input from a user indicating a selection of one of at least two different levels of security to be applied to the encryption key when storing the encryption key.

7. The system of claim 6 , wherein one of the levels of security is related to scrambling the encryption key such that the scrambled encryption key is recoverable by information stored in the system.

8. The system of claim 6 , wherein one of the levels of security is related to encrypting the encryption key such that the encrypted encryption key is recoverable by information received from the user.

9. A computer-readable medium whose contents cause a data storage system to perform a method of encrypting a copy of a data set created by a file system, the method comprising:

generating an encryption key associated with the copy of the data set;

encrypting the copy of the data set with the encryption key to create an encrypted data set;

receiving an indication from a user to store the encryption key in one of two user-selectable secure states; and

storing the encrypted data set and the encryption key in the user-selected secure state on a storage device separate from the file system.

10. The computer-readable medium of claim 9 , wherein storing the encryption key in one of two user-selectable secure states comprises scrambling the encryption key such that the scrambled encryption key is recoverable by a descramble component stored in the data storage system.

11. The computer-readable medium of claim 9 , wherein storing the encryption key in one of two user-selectable secure states comprises encrypting the encryption key such that the encrypted encryption key is recoverable by a password or information received from the user.

12. A secondary storage device for use with a data storage system that stores data created by a file system, comprising:

an archive data set, stored in a storage medium associated with the secondary storage device, containing a set of data files created by the file system, wherein the archive data set is encrypted by the data storage system using an encryption key;

the encryption key, stored in memory of the secondary storage device, used to encrypt the archive data set; wherein the encryption key is stored in one of at least two secure states.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jan 6, 2021
From: BANK OF AMERICA, N.A.
To: COMMVAULT SYSTEMS, INC.
Reel/Frame 054913/0905 →
SECURITY INTEREST Recorded Jul 2, 2014
From: COMMVAULT SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033266/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2013
From: IGNATIUS, PAUL; PRAHLAD, ANAND; TYAGARAJAN, MAHESH; VIJAYAN, MANOJ KUMAR; AMARENDRAN, ARUN PRASAD; KOTTOMTHARAYIL, RAJIV
To: COMMVAULT SYSTEMS, INC.
Reel/Frame 031666/0135 →
RELEASE Recorded Jul 7, 2008
From: SILICON VALLEY BANK
To: COMMVAULT SYSTEMS, INC.
Reel/Frame 021217/0246 →
SECURITY AGREEMENT Recorded May 8, 2006
From: COMMVAULT SYSTEMS, INC.
To: SILICON VALLEY BANK
Reel/Frame 017586/0261 →