IP Library Granted Patent US 10,007,807
Granted Patent B2
US 10,007,807 · App. 12/346,561 · Granted Jun 26, 2018

Simultaneous state-based cryptographic splitting in a secure storage appliance

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,007,807
App. No.
12/346,561
Granted
Jun 26, 2018
Kind
B2
Abstract

Methods and systems for managing I/O requests in a secure storage appliance are disclosed. One method includes receiving a plurality of I/O requests at the secure storage appliance, each I/O request associated with a block of data and a volume, each volume associated with a plurality of shares stored on a plurality of physical storage devices. The method further includes storing a plurality of blocks of data in buffers of the secure storage appliance, each of the blocks of data associated with one or more of the plurality of I/O requests. The method also includes associating a state with each of the blocks of data, the state selected from a plurality of states associated with processing of an I/O request. The method includes determining the availability of a resource in the secure storage appliance, the resource used to process an I/O request of a buffer, and, upon determining that the resource is available, applying the resource to a block of data in the buffer and updating the state associated with the block of data.

Claims (43)

1. A method of managing input/output (I/O) requests in a secure storage appliance, the method including:

receiving a plurality of I/O requests at the secure storage appliance, each I/O request associated with a primary block of data and a volume, each volume associated with a plurality of primary data blocks, the volume being mapped to a specific subset of a plurality of physical storage devices, and the volume including a metadata store, wherein the plurality of I/O requests are thereby processed concurrently;

storing a plurality of primary blocks of data in buffers of the secure storage appliance, each of the primary blocks of data associated with one or more of the plurality of I/O requests, wherein at least one of the buffers is a direct buffer;

associating a state with each of the primary blocks of data, the state selected from a plurality of states associated with processing of an I/O request;

determining an availability of a resource in the secure storage appliance, the resource used to process an I/O request of a buffer; and

upon determining that the resource is available, applying the resource to a primary block of data in the buffer and updating the state associated with the primary block of data;

wherein the volume is presented as a single virtual disk to clients;

wherein the resource includes a parser driver configured to perform a cryptographic splitting operation on the primary block of data to generate a plurality of secondary data blocks;

wherein the metadata store includes share and key information defining volumes, virtual disks and client access rights, to either process or reroute requests assigned to the failed device;

wherein after cryptographically splitting the primary block of data into the plurality of secondary data blocks, each secondary data block is encrypted with a different session key, each secondary data block is included in a stripe of dataset;

wherein each stripe of dataset further includes a share label, the share label is in plain text; and

wherein each stripe of data further includes a signature identifying physical device that the stripe is stored, each stripe of data includes a header information, each stripe of data includes a virtual disk information, the signature, the header information, and the virtual disk information are encrypted with a same community of interest key.

2. The method of claim 1 , wherein the resource includes a storage resource configured to write the plurality of secondary data blocks to shares associated with the volume.

3. The method of claim 1 , wherein the resource includes a parser driver configured to perform a reconstitution operation on a plurality of secondary data blocks to form the primary block of data.

4. The method of claim 1 , wherein the plurality of states includes at least one of a read state, a decode state, an idle state, a transfer state, an encode state, or a write state.

5. The method of claim 1 , wherein the primary block of data is received from a client device.

6. The method of claim 1 , wherein the resource includes an entry in an outstanding write list.

7. The method of claim 1 , further comprising, after processing the I/O request using the resource, releasing the buffer.

8. The method of claim 1 , further comprising receiving a plurality of I/O requests related to a primary block of data.

9. The method of claim 1 , further comprising, upon detecting changed data in a buffer, marking the buffer to be written to a plurality of shares of the volume.

10. The method of claim 9 , wherein the primary block of data in the buffer relates to a read I/O request and a write I/O request.

11. A secure storage appliance comprising:

a plurality of buffers;

a plurality of resources useable in processing input/output (I/O) requests;

a programmable circuit configured to execute program instructions to:

receive a plurality of I/O requests at the secure storage appliance, each I/O request associated with a primary block of data and a volume, each volume associated with a plurality of primary data blocks, the volume being mapped to a specific subset of a plurality of physical storage devices, and the volume including a metadata store, wherein the plurality of I/O requests are thereby processed concurrently;

store a plurality of primary blocks of data in buffers from among the plurality of buffers, each of the primary blocks of data associated with one or more of the plurality of I/O requests, wherein at least one of the buffers is a direct buffer;

associate a state with each of the primary blocks of data, the state selected from a plurality of states associated with processing of an I/O request;

determine an availability of a resource from among the plurality of resources; and

apply the resource to a primary block of data in a buffer and updating the state associated with the primary block of data upon determining that the resource is available;

wherein the volume is presented as a virtual disk to clients;

wherein the resource includes a parser driver configured to perform a cryptographic splitting operation on the primary block of data to generate a plurality of secondary data blocks;

wherein the metadata store includes share and key information defining volumes, virtual disks and client access rights, to either process or reroute requests assigned to the failed device;

wherein after cryptographically splitting the primary block of data into the plurality of secondary data blocks, each secondary data block is encrypted with a different session key, each secondary data block is included in a stripe of dataset;

wherein each stripe of dataset further includes a share label, the share label is in plain text; and

wherein each stripe of data further includes a signature identifying physical device that the stripe is stored, each stripe of data includes a header information, each stripe of data includes a virtual disk information, the signature, the header information, and the virtual disk information are encrypted with a same community of interest key.

12. The secure storage appliance of claim 11 , wherein the plurality of resources includes a parser driver configured to perform a reconstitution operation on a plurality of secondary data blocks to form the primary block of data.

13. The secure storage appliance of claim 11 , wherein the plurality of states includes at least one of a read state, a decode state, an idle state, a transfer state, an encode state, or a write state.

14. The secure storage appliance of claim 11 , wherein the plurality of resources includes at least one resource selected from the group consisting of:

a parser driver;

a host bus adapter port; and

an entry in an outstanding write list.

15. The secure storage appliance of claim 11 , wherein the programmable circuit is programmed to receive a plurality of I/O requests related to the primary block of data.

Assignments (13)
AMENDED AND RESTATED PATENT SECURITY AGREEMENT Recorded Jun 27, 2025
From: UNISYS CORPORATION; UNISYS HOLDING CORPORATION; UNISYS NPL, INC.; UNISYS AP INVESTMENT COMPANY I
To: COMPUTERSHARE TRUST COMPANY, N.A., AS COLLATERAL TRUSTEE
Reel/Frame 071759/0527 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2020
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: UNISYS CORPORATION
Reel/Frame 054231/0496 →
SECURITY INTEREST Recorded Sep 13, 2018
From: UNISYS CORPORATION
To: WELLS FARGO BANK NA
Reel/Frame 046860/0832 →
RELEASE OF SECURITY INTEREST Recorded Nov 9, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION (SUCCESSOR TO GENERAL ELECTRIC CAPITAL CORPORATION)
To: UNISYS CORPORATION
Reel/Frame 044416/0358 →
SECURITY INTEREST Recorded Oct 6, 2017
From: UNISYS CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 044144/0081 →
PATENT SECURITY AGREEMENT Recorded Apr 27, 2017
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL TRUSTEE
Reel/Frame 042354/0001 →
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2013
From: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL TRUSTEE
To: UNISYS CORPORATION
Reel/Frame 030082/0545 →
RELEASE OF SECURITY INTEREST Recorded Mar 15, 2013
From: DEUTSCHE BANK TRUST COMPANY
To: UNISYS CORPORATION
Reel/Frame 030004/0619 →
SECURITY AGREEMENT Recorded Jun 27, 2011
From: UNISYS CORPORATION
To: GENERAL ELECTRIC CAPITAL CORPORATION, AS AGENT
Reel/Frame 026509/0001 →
RELEASE BY SECURED PARTY Recorded Sep 14, 2009
From: CITIBANK, N.A.
To: UNISYS CORPORATION; UNISYS HOLDING CORPORATION
Reel/Frame 023263/0631 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2009
From: SUMMERS, SCOTT; FRENCH, ALBERT
To: UNISYS CORPORATION
Reel/Frame 023164/0418 →
RELEASE BY SECURED PARTY Recorded Jul 31, 2009
From: CITIBANK, N.A.
To: UNISYS CORPORATION; UNISYS HOLDING CORPORATION
Reel/Frame 023312/0044 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Feb 10, 2009
From: UNISYS CORPORATION
To: CITIBANK, N.A.
Reel/Frame 022237/0172 →