IP Library Granted Patent US 9,742,564
Granted Patent B2
US 9,742,564 · App. 12/780,204 · Granted Aug 22, 2017

Method and system for encrypting data

Inventors: Darren J. Moffat (Lower Earley, GB); Jeffrey S. Bonwick (Los Altos, CA); William H. Moore (Fremont, CA); Matthew A. Ahrens (San Francisco, CA); Mark J. Maybee (Boulder, CO); George Wilson (Brisbane, CA); Neil V. Perrin (Westminster, CO)
Assignee: Oracle International Corporation
H04L9/0894G06F21/602H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,742,564
App. No.
12/780,204
Filed
May 14, 2010
Granted
Aug 22, 2017
Kind
B2
Art Unit
2435
USPC
713/189
Abstract

A processing device may generate a data encryption key configured to encrypt unique data within a clone of an encrypted data set and associated with a set of transaction identifiers of a transaction based file system. The processing device may further wrap the data encryption key with a wrapping key, create a cloned encrypted data set with the data encryption key, and store the wrapped data encryption key with the cloned encrypted data set indexed by at least one of the set of transaction identifiers.

Claims (31)

1. A method for making data in a data set inaccessible comprising:

generating a data encryption key (i) configured to encrypt data within a data set of a copy-on-write transaction based file system and (ii) associated with a set of monotonically increasing transaction identifiers, each indicating when a corresponding block of data was written at a particular location, of the copy-on-write transaction based file system;

wrapping the data encryption key with a wrapping key;

creating an encrypted data set with the data encryption key;

storing the wrapped data encryption key with the encrypted data set indexed by at least one of the set of monotonically increasing transaction identifiers;

receiving a command to delete the encrypted data set; and

altering or changing the wrapping key in response to the command to make data in the encrypted data set inaccessible.

2. The method of claim 1 further comprising generating another data encryption key (i) configured to encrypt unique data within a clone of the encrypted data set and (ii) associated with another set of transaction identifiers of the copy-on-write transaction based file system.

3. The method of claim 2 further comprising wrapping the another data encryption key with a wrapping key.

4. The method of claim 3 further comprising creating a cloned encrypted data set with the another data encryption key.

5. The method of claim 4 further comprising storing the wrapped another data encryption key with the cloned encrypted data set indexed by at least one of the another set of transaction identifiers.

6. The method of claim 1 wherein wrapping the data encryption key with a wrapping key includes encrypting the data encryption key with another key using Advanced Encryption Standard (AES) in Counter with CBC-MAC (CCM) mode.

7. A computer processing system comprising:

at least one processing device to (i) generate a data encryption key (a) configured to encrypt unique data within a clone of an encrypted data set and (b) associated with a set of monotonically increasing transaction identifiers, each indicating when a corresponding block of data was written at a particular location, of a copy-on-write transaction based file system, (ii) wrap the data encryption key with a wrapping key, (iii) create a cloned encrypted data set with the data encryption key, and (iv) store the wrapped data encryption key with the cloned encrypted data set indexed by at least one of the set of monotonically increasing transaction identifiers.

8. The system of claim 7 wherein the at least one processing device is further programmed to receive a command to delete the cloned encrypted data set and to alter or change the wrapping key in response to the command to make data in the cloned encrypted data set inaccessible.

9. The system of claim 7 wherein the at least one processing device is further programmed to wrap the data encryption key with a wrapping key by encrypting the data encryption key with another key using Advanced Encryption Standard (AES) in Counter with CBC-MAC (CCM) mode.

10. The system of claim 7 wherein the copy-on-write transaction based file system is Z file system (ZFS).

11. A non-transitory computer-readable storage medium having information stored thereon for directing one or more computers to

generate a data encryption key configured to encrypt data within a data set of a copy-on-write transaction based file system and associated with a set of monotonically increasing transaction identifiers, each indicating when a corresponding block of data was written at a particular location, of the copy-on-write transaction based file system,

wrap the data encryption key with a wrapping key,

create an encrypted data set with the data encryption key,

store the wrapped data encryption key with the encrypted data set indexed by at least one of the set of monotonically increasing transaction identifiers,

generate another data encryption key configured to encrypt unique data within a clone of the encrypted data set and associated with another set of transaction identifiers of the copy-on-write transaction based file system,

wrap the another data encryption key with another wrapping key,

create a cloned encrypted data set with the another data encryption key, and

store the wrapped another data encryption key with the cloned encrypted data set indexed by at least one of the another set of transaction identifiers.

12. The non-transitory computer-readable storage medium of claim 11 wherein the information stored thereon further directs the one or more computers to receive a command to delete the encrypted data set and to alter or change the wrapping key in response to the command to make data in the encrypted data set inaccessible.

13. The non-transitory computer-readable storage medium of claim 11 wherein the information stored thereon further directs the one or more computers to receive a command to delete the cloned encrypted data set and to alter or change the another wrapping key in response to the command to make data in the cloned encrypted data set inaccessible.

14. The non-transitory computer-readable storage medium of claim 11 wherein the wrapping key and another wrapping key are different.

15. The non-transitory computer-readable storage medium of claim 11 wherein the copy-on-write transaction based file system is Z file system (ZFS).

16. The non-transitory computer-readable storage medium of claim 11 wherein the another set of transaction identifiers is a monotonically increasing set of transaction identifiers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2010
From: MOFFAT, DARREN J.; BONWICK, JEFFREY S.; MOORE, WILLIAM H.; AHRENS, MATTHEW A.; MAYBEE, MARK J.; WILSON, GEORGE; PERRIN, NEIL V.
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 024400/0216 →
Continuity (1)
Related Publication 20110283113A1 · Nov 17, 2011