IP Library Granted Patent US 8,392,684
Granted Patent B2
US 8,392,684 · App. 11/497,026 · Granted Mar 5, 2013

Data encryption in a network memory architecture for providing data based on local accessibility

Inventor: David Anthony Hughes (Los Altos Hills, CA)
Assignee: Silver Peak Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,392,684
App. No.
11/497,026
Granted
Mar 5, 2013
Kind
B2
Abstract

A network memory system for ensuring compliance is disclosed. The network memory system comprises a first appliance configured to encrypt first data, store the encrypted first data in a first memory device. The first appliance also determines whether the encrypted first data exists in a second appliance and transmits a store instruction comprising the encrypted first data based on the determination that the encrypted first data does not exist in the second appliance. The second appliance is further configured to receive a retrieve instruction comprising an index at which the encrypted first data is stored, process the retrieve instruction to obtain encrypted response data, and decrypt the encrypted response data.

Claims (40)

1. A network memory system for ensuring compliance, comprising:

a source-site appliance comprising a first processor and a first memory device, and configured to be coupled to a source-site computer via a source-site local area network;

a destination-site appliance comprising a second processor and a second memory device, and configured to be coupled to a destination-site computer via a destination-site local area network, the source-site computer in communication with the destination-site computer via a wide area network;

the source-site appliance configured to intercept data sent from the source-site computer to the destination-site computer, encrypt the data, store the data in the first memory device, determine whether the data exists in the second memory device, and transmit a store instruction comprising the data if the data does not exist in the second memory device; and

the destination-site appliance configured to receive the store instruction from the source-site appliance, store the data in the second memory device, subsequently receive a retrieve instruction comprising an index at which the data is stored in the second memory device, process the retrieve instruction to obtain encrypted response data, and decrypt the encrypted response data.

2. The network memory system of claim 1 wherein the destination-site appliance is further configured to transmit the decrypted response data.

3. The network memory system of claim 1 wherein the source-site appliance is configured to encrypt the data using an Advanced Encryption Scheme algorithm.

4. The network memory system of claim 1 wherein the source-site appliance is configured to encrypt the data using a Data Encryption Scheme algorithm.

5. The network memory system of claim 1 wherein the source-site appliance is configured to encrypt the data using a Triple Data Encryption Scheme algorithm.

6. The network memory system of claim 1 wherein the destination-site appliance is configured to combine the encrypted response data with a stream.

7. The network system of claim 1 wherein the source-site appliance is configured to store the data at the index independent of an application or data context.

8. A method for ensuring compliance in network memory, the method comprising:

in a source-site appliance, intercepting data sent from a source-site computer to a destination-site computer, the source-site appliance coupled to the source-site computer via a source-site local area network and the source-site computer in communication with the destination-site computer via a wide area network;

encrypting the data;

storing the data in a first memory device within the source-site appliance;

determining whether the data exists in a destination-site appliance appliance, the destination-site appliance coupled to the destination-site computer via a destination-site local area network;

transmitting a store instruction comprising the data from the source-site appliance based on the determination that the data does not exist in the destination-site appliance;

receiving the store instruction into the destination-site appliance;

storing the data in a second memory device within the destination-site appliance;

subsequently receiving a retrieve instruction into the destination-site appliance, the retrieve instruction comprising an index at which the data is stored;

in the destination-site appliance, processing the retrieve instruction to obtain encrypted response data; and

in the destination-site appliance, decrypting the encrypted response data.

9. The method of claim 8 further comprising transmitting the decrypted response data from the destination-site appliance.

10. The method of claim 8 further comprising encrypting the first data using an Advanced Encryption Scheme algorithm.

11. The method of claim 8 further comprising encrypting the first data using a Data Encryption Scheme algorithm.

12. The method of claim 8 further comprising encrypting the first data using a Triple Data Encryption Scheme algorithm.

13. The method of claim 8 further comprising combining the encrypted response data with a key stream.

14. The method of claim 9 further comprising storing the data at the index independent of an application or data context.

15. A software product for ensuring compliance in network memory comprising:

software operational when executed by a processor to direct the processor to intercept data sent from a source-site computer to a destination-site computer, encrypt the data in a source-site appliance, store the data in a first memory device within the source-site appliance, determine whether the data exists in a destination-site appliance, transmit a store instruction comprising the data from the source-site appliance based on the determination that the data does not exist in the destination-site appliance, receive the store instruction into the destination-site appliance, store the data in a second memory device within the destination-site appliance, subsequently receive a retrieve instruction into the destination-site appliance, the retrieve instruction comprising an index at which the data is stored, process the retrieve instruction to obtain encrypted response data in the destination-site appliance, and decrypt the encrypted response data in the destination-site appliance; and

a storage medium that stores the software.

16. The software product of claim 15 wherein the software is operational when executed by the processor to transmit the decrypted response data.

17. The software product of claim 15 wherein the software is operational when executed by the processor to encrypt the data using an Advanced Encryption Scheme algorithm.

18. The software product of claim 15 wherein the software is operational when executed by the processor to encrypt the data using a Data Encryption Scheme algorithm.

19. The software product of claim 15 wherein the software is operational when executed by the processor to encrypt the data using a Triple Data Encryption Scheme algorithm.

20. The software product if claim 15 wherein the software is operational when executed by the processor to combine the encrypted response data with a key stream.

21. The software product of claim 15 wherein the software is operational when executed by the processor to store the data at the index independent of an application or data context.

22. The network memory system of claim 1 wherein the destination-site computer is a server.

23. The method of claim 8 wherein the destination-site computer is a server.

24. The software product of claim 15 wherein the destination-site computer is a server.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2022
From: SILVER PEAK SYSTEMS, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 059669/0983 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2022
From: SILVER PEAK SYSTEMS, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 058943/0350 →
RELEASE OF SECURITY INTEREST Recorded Sep 22, 2020
From: GOLUB CAPITAL LLC
To: SILVER PEAK SYSTEMS, INC.
Reel/Frame 053852/0231 →
SECURITY INTEREST Recorded Apr 16, 2019
From: SILVER PEAK SYSTEMS, INC.
To: GOLUB CAPITAL LLC, AS AGENT
Reel/Frame 048921/0455 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2006
From: HUGHES, DAVID ANTHONY
To: SILVER PEAK SYSTEMS, INC.
Reel/Frame 018127/0572 →
Continuity (2)
Continuation In Part 11202697 · Aug 12, 2005
Related Publication 20070038858A1 · Feb 15, 2007