IP Library Granted Patent US 9,411,986
Granted Patent B2
US 9,411,986 · App. 13/961,315 · Granted Aug 9, 2016

System and method for encrypting secondary copies of data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,411,986
App. No.
13/961,315
Granted
Aug 9, 2016
Kind
B2
Abstract

A system and method for encrypting secondary copies of data is described. In some examples, the system encrypts a secondary copy of data after the secondary copy is created. In some examples, the system looks to information about a data storage system, and determines when and where to encrypt data based on the information.

Claims (27)

1. A data storage system that encrypts secondary copies of data, the system comprising:

at least one computer processor comprising computer hardware, the computer processor configured to perform a storage operation that creates at least one secondary copy of data;

the computer processor further configured to calculate a completion time to create and encrypt at least a portion of the secondary copy;

when the completion time exceeds a threshold time, the computer processor is configured to transfer the secondary copy to at least one storage device without encrypting at least a portion of the secondary copy, and after transfer, encrypt one or more unencrypted portions of the secondary copy; and

when the completion time is less than the threshold time, the computer processor is configured to encrypt at least a portion of the secondary copy in association with performing the storage operation.

2. The system of claim 1 , wherein the computer processor is further configured to maintain an index of encrypted and unencrypted portions of the secondary copy.

3. The system of claim 1 , wherein the threshold time is static.

4. The system of claim 1 , wherein the threshold time dynamically changes based on the performance of the storage operation.

5. The system of claim 1 , wherein the threshold time dynamically changes based on system capacity.

6. The system of claim 1 , wherein the threshold time is based on a storage window.

7. The system of claim 1 , wherein the computer processor is further configured to determine which portions of the secondary copy can be stored without encryption.

8. The system of claim 1 , wherein the computer processor is further configured to determine which portions of the secondary copy can be stored without encryption based on types of data.

9. The system of claim 1 , further comprising a second computer processor that is remotely located from the at least one computer processor, the second computer processor configured to encrypt the unencrypted portions of the secondary copy.

10. The system of claim 1 , wherein the computer processor is further configured to maintain an index of encrypted and unencrypted portions of multiple secondary copies associated with different storage operations.

11. A data storage system that that encrypts secondary copies of data, the system comprising:

at least one computer processor comprising computer hardware, the computer processor configured to perform a storage operation that creates at least one secondary copy of data;

the computer processor further configured to calculate a completion time to create and encrypt at least a portion of the secondary copy; and

when the completion time exceeds a threshold time, the computer processor is configured to transfer the secondary copy to at least one storage device without encrypting at least a portion of the secondary copy, and after transfer, encrypt one or more unencrypted portions of the secondary copy.

12. The system of claim 11 , wherein the computer processor is further configured to maintain an index of encrypted and unencrypted portions of the secondary copy.

13. The system of claim 11 , wherein the threshold time is static.

14. The system of claim 11 , wherein the threshold time dynamically changes based on the performance of the storage operation.

15. The system of claim 11 , wherein the threshold time dynamically changes based on system capacity.

16. The system of claim 11 , wherein the threshold time is based on a storage window.

17. The system of claim 11 , wherein the computer processor is further configured to determine which portions of the secondary copy can be stored without encryption.

18. The system of claim 11 , wherein the computer processor is further configured to determine which portions of the secondary copy can be stored without encryption based on types of data.

19. The system of claim 11 , further comprising a second computer processor that is remotely located from the at least one computer processor, the second computer processor configured to encrypt the unencrypted portions of the secondary copy.

20. The system of claim 11 , wherein the computer processor is further configured to maintain an index of encrypted and unencrypted portions of multiple secondary copies associated with different storage operations.

Assignments (5)
SUPPLEMENTAL CONFIRMATORY GRANT OF SECURITY INTEREST IN UNITED STATES PATENTS Recorded Apr 16, 2025
From: COMMVAULT SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 070864/0344 →
SECURITY INTEREST Recorded Dec 13, 2021
From: COMMVAULT SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 058496/0836 →
RELEASE OF SECURITY INTEREST Recorded Jan 6, 2021
From: BANK OF AMERICA, N.A.
To: COMMVAULT SYSTEMS, INC.
Reel/Frame 054913/0905 →
SECURITY INTEREST Recorded Jul 2, 2014
From: COMMVAULT SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033266/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2014
From: GOKHALE, PARAG; EROFEEV, ANDREI; MULLER, MARCUS S.
To: COMMVAULT SYSTEMS, INC.
Reel/Frame 032483/0691 →