IP Library Granted Patent US 9,372,760
Granted Patent B1
US 9,372,760 · App. 13/656,536 · Granted Jun 21, 2016

Systems and methods for securely storing backup data while facilitating fast failovers

Inventor: Ynn-Pyng Anker Tsaur (Oviedo, FL)
Assignee: Veritas Technologies LLC
G06F11/1458G06F11/14G06F11/1448H04L69/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,372,760
App. No.
13/656,536
Filed
Oct 19, 2012
Granted
Jun 21, 2016
Kind
B1
Art Unit
2132
USPC
711/162
Abstract

A computer-implemented method for securely storing backup data while facilitating fast failovers may include 1) identifying, at a primary site, a virtual disk file that includes a backup image, 2) modifying a boot sector within the virtual disk file to add a boot loader that supports reading disks encrypted with whole disk encryption, 3) encrypting the backup image within the virtual disk file, except for at least one decryption area, with whole disk encryption, and 4) storing the virtual disk file at a secondary site after encrypting the backup image within the virtual disk file. Various other methods, systems, and computer-readable media are also disclosed.

Claims (54)

1. A computer-implemented method for securely storing backup data while facilitating fast failovers, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

identifying, at a primary site, a virtual disk file that comprises a backup image comprising a backup of a disk at the primary site;

modifying a boot sector within the virtual disk file to add a boot loader, wherein:

the boot loader executes as part of a bootstrapping process;

the boot loader facilitates decrypting disks encrypted with whole disk encryption;

encrypting, at the primary site, the backup image within the virtual disk file, except for at least one decryption area comprising one or more portions of the disk at the primary site used in the bootstrapping process, with whole disk encryption;

storing the virtual disk file at a secondary site after encrypting the backup image within the virtual disk file.

2. The computer-implemented method of claim 1 , wherein adding the boot loader comprises adding a boot loader that takes a passcode as input and uses the passcode to decrypt a session key used for decrypting data stored on the disk.

3. The computer-implemented method of claim 1 , wherein:

the backup of the disk at the primary site comprises the backup of the disk of a host system within the primary site;

encrypting the backup image at the primary site comprises encrypting the backup image at a media server at the primary site.

4. The computer-implemented method of claim 1 , wherein encrypting with whole disk encryption comprises encrypting all of the disk at the primary site except for the one or more portions of the disk of the primary site used in the bootstrapping process.

5. The computer-implemented method of claim 1 , further comprising injecting an encryption disk driver into the virtual disk file.

6. The computer-implemented method of claim 1 , further comprising determining, based on a security standard, that the backup image is to be encrypted before transmitting the backup image outside the primary site;

wherein encrypting the backup image is in response to determining that the backup is to be encrypted based on the security standard.

7. The computer-implemented method of claim 1 , wherein identifying the virtual disk file comprises backing up an additional virtual disk file to create the virtual disk file.

8. The computer-implemented method of claim 1 , wherein identifying the virtual disk file comprises backing up a physical host system at the primary site to create the backup image.

9. A system for securely storing backup data while facilitating fast failovers, the system comprising:

an identification module, stored in memory, that identifies, at a primary site, a virtual disk file that comprises a backup image comprising a backup of a disk at the primary site;

a modification module, stored in memory, that modifies a boot sector within the virtual disk file to add a boot loader, wherein:

the boot loader executes as part of a bootstrapping process;

the boot loader facilitates decrypting disks encrypted with whole disk encryption;

an encryption module, stored in memory, that encrypts, at the primary site, the backup image within the virtual disk file, except for at least one decryption area comprising one or more portions of the disk at the primary site used in the bootstrapping process, with whole disk encryption;

a storage module, stored in memory, that stores the virtual disk file at a secondary site after encrypting the backup image within the virtual disk file;

at least one processor configured to execute the identification module, the modification module, the encryption module, and the storage module.

10. The system of claim 9 , wherein:

the modification module modifies the boot sector to add the boot loader by modifying the boot sector to add a boot loader that takes a passcode as input and uses the passcode to decrypt a session key used for decrypting data stored on the disk.

11. The system of claim 9 , wherein:

the backup of the disk at the primary site comprises the backup of the disk of a host system within the primary site;

the encryption module is programmed to encrypt the backup image at a media server at the primary site.

12. The system of claim 9 , further comprising a failover module, stored in memory, that:

identifies a failover from the primary site to the secondary site;

in response to the failover, loads the backup image in a virtual machine at the secondary site.

13. The system of claim 9 , wherein the modification module further injects an encryption disk driver into the virtual disk file.

14. The system of claim 9 ,

wherein the encryption module further determines, based on a security standard, that the backup image is to be encrypted before transmitting the backup image outside the primary site;

wherein the encryption module encrypts the backup image in response to determining that the backup is to be encrypted based on the security standard.

15. The system of claim 9 , wherein the identification module identifies the virtual disk file by backing up an additional virtual disk file to create the virtual disk file.

16. The system of claim 9 , wherein the identification module identifies the virtual disk file by backing up a physical host system at the primary site to create the backup image.

17. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

identify, at a primary site, a virtual disk file that comprises a backup image comprising a backup of a disk at the primary site;

modify a boot sector within the virtual disk file to add a boot loader, wherein:

the boot loader executes as part of a bootstrapping process;

the boot loader facilitates decrypting disks encrypted with whole disk encryption;

encrypt, at the primary site, the backup image within the virtual disk file, except for at least one decryption area comprising one or more portions of the disk at the primary site used in the bootstrapping process, with whole disk encryption;

store the virtual disk file at a secondary site after encrypting the backup image within the virtual disk file.

18. The non-transitory computer-readable medium of claim 17 , wherein:

the one or more computer-executable instructions cause the computing device to add the boot loader by causing the computing device to add a boot loader that takes a passcode as input and uses the passcode to decrypt a session key used for decrypting data stored on the disk.

19. The non-transitory computer-readable medium of claim 17 , wherein:

the backup of the disk at the primary site comprises the backup of the disk of a host system within the primary site;

the one or more computer-executable instructions cause the computing device to encrypt the backup image at the primary site by causing the computing device to encrypt the backup image at a media server at the primary site.

20. The non-transitory computer-readable medium of claim 17 , wherein the one or more computer-executable instructions further cause the computing device to:

identify a failover from the primary site to the secondary site;

in response to the failover, load the backup image in a virtual machine at the secondary site.

Assignments (14)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2026
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 075728/0466 →
AMENDMENT NO. 1 TO PATENT SECURITY AGREEMENT Recorded Apr 8, 2025
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2025
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 070335/0013 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC (F/K/A VERITAS US IP HOLDINGS LLC)
Reel/Frame 069712/0090 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY IN PATENTS AT R/F 037891/0726 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS US IP HOLDINGS, LLC
Reel/Frame 054535/0814 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
MERGER Recorded Apr 18, 2016
From: VERITAS US IP HOLDINGS LLC
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 038483/0203 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037891/0726 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037891/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2016
From: SYMANTEC CORPORATION
To: VERITAS US IP HOLDINGS LLC
Reel/Frame 037693/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2012
From: TSAUR, YNN-PYNG ANKER
To: SYMANTEC CORPORATION
Reel/Frame 029162/0381 →