IP Library Granted Patent US 8,769,274
Granted Patent B2
US 8,769,274 · App. 13/604,427 · Granted Jul 1, 2014

Backup and restore in a secure appliance with integrity and confidentiality

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,769,274
App. No.
13/604,427
Granted
Jul 1, 2014
Kind
B2
Abstract

A cloud deployment appliance includes a key stored internally and that is used during restore to decrypt encrypted backup images. That key is not available to an administrator of the appliance; instead, the administrator receives a “value” that has been generated externally to the appliance and, in particular, by applying a public key of a public key pair to the key. The value is possessed by the administrator, but it does not expose the key. Upon a given occurrence, such as a disk failure in the appliance, the administrator uses the value to obtain” the key, which is then used to restore an encrypted backup image. The key is obtained by having the administrator provide the value to an entity, e.g., the appliance manufacturer, who then recovers the key for the administrator (by applying the private key of the public key pair).

Claims (41)

1. Apparatus, comprising:

a processor;

computer memory holding computer program instructions that when executed by the processor perform a method of secure backup and restore, the method comprising:

storing a key, the key having associated therewith a value that has been generated by applying a public key of a public key pair to the key, wherein possessing the value does not expose the key;

encrypting data using the key to generate an encrypted backup image;

upon a given occurrence, receiving a copy of the key from an entity, the entity having generated the copy of the key upon receipt by the entity of the value; and

using the copy of the key to recover the encrypted backup image.

2. The apparatus as described in claim 1 wherein the encrypted backup image is recovered by applying the key to the encrypted backup image.

3. The apparatus as described in claim 1 wherein the given occurrence is a recoverable disk failure.

4. The apparatus as described in claim 1 wherein the copy of the key received from the entity is generated as a result of applying a private key of the public key pair to the value.

5. The apparatus as described in claim 1 wherein the method further includes:

generating a new key for use in encrypting data;

encrypting the new key with the public key to generate a new value;

maintaining the new key internally while providing the new value externally.

6. The apparatus as described in claim 5 wherein the method further includes providing the new value to the entity.

7. The apparatus as described in claim 1 wherein the key is associated with its own key pair.

8. A computer program product in a non-transitory computer readable medium for use in a data processing system, the computer program product holding computer program instructions which, when executed by the data processing system, perform a method of secure backup and restore, the method comprising:

storing a key, the key having associated therewith a value that has been generated by applying a public key of a public key pair to the key, wherein possessing the value does not expose the key;

encrypting data using the key to generate an encrypted backup image;

upon a given occurrence, receiving a copy of the key from an entity, the entity having generated the copy of the key upon receipt by the entity of the value; and

using the copy of the key to recover the encrypted backup image.

9. The computer program product as described in claim 8 wherein the encrypted backup image is recovered by applying the key to the encrypted backup image.

10. The computer program product as described in claim 8 wherein the given occurrence is a recoverable disk failure.

11. The computer program product as described in claim 8 wherein the copy of the key received from the entity was generated as a result of applying a private key of the public key pair to the value.

12. The computer program product as described in claim 8 wherein the method further includes:

generating a new key for use in encrypting data;

encrypting the new key with the public key to generate a new value;

maintaining the new key internally while providing the new value externally.

13. The computer program product as described in claim 12 wherein the method further includes providing the new value to the entity.

14. The computer program product as described in claim 8 wherein the key is associated with its own key pair.

15. An appliance, comprising:

a data store that stores data a key, the key having associated therewith a value that has been generated by applying a public key of a public key pair to the key, wherein possessing the value does not expose the key and the key is not available in a clear form externally;

a hardware processor;

computer memory holding instructions executed by the processor (i) to encrypt data using the key to generate an encrypted backup, and (ii) to receive a copy of the key from an entity upon a given occurrence, the entity having generated the copy of the key upon receipt by the entity of the value, and (iii) to use the copy of the key to recover the encrypted backup image.

16. Apparatus, comprising:

a processor;

computer memory, holding computer program instructions that when executed by the processor perform a method of secure backup and restore, the method comprising:

storing a key, the key having associated therewith a value that has been generated by applying a public key of a public key pair to the key, wherein possessing the value does not expose the key;

encrypting data using the key to generate an encrypted backup image;

upon a given occurrence, wherein the given occurrence is an unrecoverable disk failure, receiving a copy of the key from an entity, the entity having generated the copy of the key upon receipt by the entity of the value; and

using the copy of the key to recover the encrypted backup image.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: DROPBOX, INC.
Reel/Frame 069635/0332 →
SECURITY INTEREST Recorded Dec 12, 2024
From: DROPBOX, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069604/0611 →
RELEASE OF SECURITY INTEREST Recorded Dec 12, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: DROPBOX, INC.
Reel/Frame 069613/0744 →
PATENT SECURITY AGREEMENT Recorded Mar 10, 2021
From: DROPBOX, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 055670/0219 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2017
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: DROPBOX, INC.
Reel/Frame 043938/0489 →
SECURITY INTEREST Recorded Apr 14, 2017
From: DROPBOX, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 042254/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2012
From: CHAO, CHING-YUN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 028904/0313 →