IP Library Granted Patent US 8,135,980
Granted Patent B2
US 8,135,980 · App. 12/342,438 · Granted Mar 13, 2012

Storage availability using cryptographic splitting

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,135,980
App. No.
12/342,438
Granted
Mar 13, 2012
Kind
B2
Abstract

A secure storage appliance is disclosed, along with methods of storing and reading data in a secure storage network. In one aspect, a method includes assigning a volume to a primary secure storage appliance located in a secure data storage network, the secure data storage network including a plurality of secure data paths between the primary secure storage appliance and a client device and a plurality of secure data paths between the secure storage appliance and a plurality of storage systems, the volume corresponding to physical storage at each of the plurality of storage systems. The method also includes detecting a connectivity problem on at least one of the secure data paths. The method further includes assessing whether to reassign the volume to a different secure storage appliance based upon the connectivity problem.

Claims (47)

1. A method of maintaining data connectivity in a secure storage network, the method comprising:

assigning a volume to a primary secure storage appliance located in a secure data storage network, the secure data storage network including a plurality of secure data paths between the primary secure storage appliance and a client device and a plurality of secure data paths between the secure storage appliance and a plurality of storage systems, the volume corresponding to physical storage at each of the plurality of storage systems;

detecting a connectivity problem on at least one of the secure data paths; and

assessing whether to reassign the volume to a different secure storage appliance based upon the connectivity problem;

wherein the plurality of secure data paths encrypt data transmitted over each of the plurality of secure data paths using different encryption keys; and

the data transmitted over each of the plurality of secure data paths corresponds to a different portion of the data being transmitted between the primary secure storage appliance and the client device.

2. The method of claim 1 , further comprising:

receiving data related to the volume at a second secure storage appliance communicatively connected to the primary secure storage appliance; and

after assessing whether to reassign the volume to a different secure storage appliance, assigning the volume to the second secure storage appliance, thereby rendering the second secure storage appliance a new primary storage appliance.

3. The method of claim 2 , further comprising, upon assigning the volume to the second secure storage appliance, disassociating the volume from the primary secure storage appliance.

4. The method of claim 2 , further comprising, upon assigning the volume to the second secure storage appliance, sending an error message to an administrator of the secure data storage network.

5. The method of claim 2 , wherein the second secure storage appliance resides within a cluster including the primary secure storage appliance.

6. The method of claim 1 , wherein detecting a connectivity problem on at least one of the secure data paths comprises detecting a lack of connectivity on all of the plurality of secure data paths between the primary secure storage appliance and the client device.

7. The method of claim 1 , wherein the volume is presented to the client device as a virtual disk.

8. The method of claim 1 , wherein detecting a connectivity problem on at least one of the secure data paths occurs at a secure storage appliance in response to receipt of a data request from a client.

9. The method of claim 8 , wherein the data request is a request selected from the group consisting of a read request and a write request.

10. The method of claim 1 , wherein detecting a connectivity problem on at least one of the secure data paths occurs at a secure storage appliance in response to receipt of a failed transmission message relating to a secondary data request from the primary secure storage appliance to one or more of the plurality of storage systems.

11. The method of claim 10 , wherein the secondary data request is a secondary read request for a block of data stored at the plurality of storage systems.

12. The method of claim 11 , further comprising:

determining a failed connection between the primary secure storage appliance and one or more of the plurality of storage systems such that the secure storage appliance cannot successfully reconstitute the block of data identified by the secondary read request; and

assigning the volume to a second secure storage appliance, thereby rendering the second secure storage appliance a new primary storage appliance.

13. The method of claim 12 , further comprising, upon assigning the volume to the second secure storage appliance, disassociating the volume from the primary secure storage appliance.

14. The method of claim 12 , further comprising, upon assigning the volume to the second secure storage appliance, sending an error message to an administrator of the secure data storage network.

15. The method of claim 1 , wherein assessing whether to reassign the volume to a different secure storage appliance based upon the connectivity problem includes assessing alternative data paths to the primary secure storage appliance from among the plurality of secure data paths.

16. A multi-path secure storage network comprising:

a client device;

a plurality of storage systems;

a primary secure storage appliance associated with a volume, the primary secure storage appliance configured to manage data requests associated with the volume, the volume associated with data stored at each of the plurality of storage systems;

a plurality of secure data paths between the primary secure storage appliance and the client device; and

a plurality of secure data paths between the primary secure storage appliance and the plurality of storage systems;

wherein the primary secure storage appliance is configured to detect a connectivity problem on at least one of the secure data paths and assess whether to reassign the volume to a different secure storage appliance based upon the connectivity problem;

the plurality of secure data paths encrypt data transmitted over each of the plurality of secure data paths using different encryption keys; and

the data transmitted over each of the plurality of secure data paths corresponds to a different portion of the data being transmitted between the primary secure storage appliance and the client device.

17. The multi-path secure storage network of claim 16 , wherein the primary secure storage appliance is further configured to receive data related to the volume at a second secure storage appliance communicatively connected to the primary secure storage appliance, and, after assessing whether to reassign the volume to a different secure storage appliance, associate the volume with the second secure storage appliance, thereby rendering the second secure storage appliance a new primary storage appliance.

18. The multi-path secure storage network of claim 17 , wherein the primary secure storage appliance is further configured to, upon transferring association of the volume to the second secure storage appliance, disassociate from the volume.

19. The multi-path secure storage network of claim 17 , wherein the primary secure storage appliance is further configured to, upon transferring association of the volume to the second secure storage appliance, send an error message to an administrator of the secure data storage network.

20. The multi-path secure storage network of claim 16 , wherein the primary secure storage appliance is configured to detect a connectivity problem on at least one of the secure data paths in response to receipt of a data request from a client.

21. The multi-path secure storage network of claim 20 , wherein the data request is a request selected from the group consisting of a read request and write request.

22. The multi-path secure storage network of claim 16 , wherein the volume is presented to the client device as a virtual disk.

23. A method of maintaining data connectivity in a secure storage network, the method comprising:

assigning a volume to a primary secure storage appliance located in a secure data storage network, the secure data storage network including a plurality of secure data paths between the primary secure storage appliance and a client device and a plurality of secure data paths between the secure storage appliance and a plurality of storage systems, the volume corresponding to physical storage at each of the plurality of storage systems;

detecting a connectivity problem on at least one of the secure data paths;

assessing whether to reassign the volume to a different secure storage appliance based upon the connectivity problem;

assigning the volume to a second secure storage appliance, thereby rendering the second secure storage appliance a new primary storage appliance; and

disassociating the volume from the primary secure storage appliance;

wherein the plurality of secure data paths encrypt data transmitted over each of the plurality of secure data paths using different encryption keys; and

the data transmitted over each of the plurality of secure data paths corresponds to a different portion of the data being transmitted between the primary secure storage appliance and the client device.

Assignments (12)
AMENDED AND RESTATED PATENT SECURITY AGREEMENT Recorded Jun 27, 2025
From: UNISYS CORPORATION; UNISYS HOLDING CORPORATION; UNISYS NPL, INC.; UNISYS AP INVESTMENT COMPANY I
To: COMPUTERSHARE TRUST COMPANY, N.A., AS COLLATERAL TRUSTEE
Reel/Frame 071759/0527 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2020
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: UNISYS CORPORATION
Reel/Frame 054231/0496 →
RELEASE OF SECURITY INTEREST Recorded Nov 9, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION (SUCCESSOR TO GENERAL ELECTRIC CAPITAL CORPORATION)
To: UNISYS CORPORATION
Reel/Frame 044416/0358 →
SECURITY INTEREST Recorded Oct 6, 2017
From: UNISYS CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 044144/0081 →
PATENT SECURITY AGREEMENT Recorded Apr 27, 2017
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL TRUSTEE
Reel/Frame 042354/0001 →
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2013
From: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL TRUSTEE
To: UNISYS CORPORATION
Reel/Frame 030082/0545 →
RELEASE OF SECURITY INTEREST Recorded Mar 15, 2013
From: DEUTSCHE BANK TRUST COMPANY
To: UNISYS CORPORATION
Reel/Frame 030004/0619 →
SECURITY AGREEMENT Recorded May 3, 2012
From: UNISYS CORPORATION
To: DEUTSCHE BANK NATIONAL TRUST COMPANY
Reel/Frame 028147/0218 →
SECURITY AGREEMENT Recorded Jun 27, 2011
From: UNISYS CORPORATION
To: GENERAL ELECTRIC CAPITAL CORPORATION, AS AGENT
Reel/Frame 026509/0001 →
RELEASE BY SECURED PARTY Recorded Sep 14, 2009
From: CITIBANK, N.A.
To: UNISYS CORPORATION; UNISYS HOLDING CORPORATION
Reel/Frame 023263/0631 →
RELEASE BY SECURED PARTY Recorded Jul 31, 2009
From: CITIBANK, N.A.
To: UNISYS CORPORATION; UNISYS HOLDING CORPORATION
Reel/Frame 023312/0044 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Feb 10, 2009
From: UNISYS CORPORATION
To: CITIBANK, N.A.
Reel/Frame 022237/0172 →