IP Library Granted Patent US 9,594,698
Granted Patent B2
US 9,594,698 · App. 13/966,035 · Granted Mar 14, 2017

Local keying for self-encrypting drives (SED)

Inventors: G. Paul Koning (New Boston, NH); Damon Hsu-Hung (Providence, RI); Stuart L. Hollander (Merrimack, NH)
Assignee: Dell Products, LP
G06F12/1408G06F21/78H04L9/085H04L9/0894G06F2221/2107H04L9/0861H04L9/0891
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,594,698
App. No.
13/966,035
Filed
Aug 13, 2013
Granted
Mar 14, 2017
Kind
B2
Art Unit
2437
USPC
713/193
Abstract

A method and system self encrypts a disk storage device. Given a plurality of data storage devices, the system establishes an encryption key for the plurality of data storage devices. The system locally stores the encryption key in a piecewise manner throughout the plurality of data storage devices such that the encryption key is rendered undeterminable with less than a threshold subset of the plurality of data storage devices. This results in the plurality of data storage devices being self encrypting. Upon an increase or decrease in the plurality, the system resplits the encryption key and locally stores the resulting pieces throughout the changed (increased/decreased) plurality of data storage devices. This renders the encryption key undeterminable with less than a new or revised threshold each time the plurality is changed.

Claims (66)

1. A method of self encrypting a disk storage device comprising:

providing a plurality of data storage devices;

establishing an access key for the plurality of data storage devices;

determining a media encryption key using a random number generator;

encrypting data stored on the plurality of data storage devices using the media encryption key; encrypting the media encryption key using the access key;

locally storing shares of the access key in a first piecewise manner throughout the plurality of data storage devices such that the access key is rendered undeterminable with less than a threshold subset of the locally stored shares stored on the plurality of data storage devices, resulting in the plurality of data storage devices being self encrypted;

generating a set of backup shares of the access key in a second piecewise manner being stored on a plurality of backup data storage devices, the set of backup shares of the access key remaining operable after removal or addition of any of the plurality of data storage devices and further remaining operable after change to the shares of the access key;

responsive to changing the plurality of storage devices:

re-computing a new piecewise manner to store the access key throughout the plurality of data storage devices, by splitting the access key into a set of shares that are different than the locally stored shares before the change to the plurality of storage devices; and

storing different shares of the set of shares on different ones of the changed plurality of data storage devices,

wherein the re-computing the new piecewise local storing of the access key renders the access key undeterminable with less than a new threshold, the new threshold being a subset of the changed plurality of data storage devices,

wherein the change to the plurality of data storage devices is any of removal of one or more data storage devices from the plurality and addition of one or more data storage devices to the plurality, resulting in increase or decrease of a number of data storage devices of the plurality; and

wherein the set of backup shares have shares with a different threshold subset from the threshold subset of the locally stored shares.

2. A method of claim 1 wherein the step of locally storing the access key in a piecewise manner applies a secret sharing process.

3. A method of claim 2 wherein the secret sharing process is Shamir's secret sharing.

4. A method of claim 2 wherein the secret sharing process includes:

splitting the access key into N pieces (shares);

storing different ones of the pieces on N different ones of the plurality of data storage devices, such that the threshold subset of the plurality is (N+1)/2 of the data storage devices.

5. A method of claim 1 wherein the plurality of data storage devices is a RAID (Redundant Array of Independent Disks) configuration.

6. A method of claim 1 wherein the encrypted data stored on the plurality of data storage devices is in a band of a data storage device.

7. A method of claim 1 wherein the access key is a user-generated password.

8. The method of claim 1 , further comprising:

responsive to one of the set of backup shares being compromised, generating a new set of backup shares.

9. A self encrypting data storage system comprising:

a plurality of data storage devices; and

an encryption engine configured to:

establish an access key for the plurality of data storage devices,

determine a media encryption key using a random number generator,

encrypt data stored on the plurality of data storage devices using the media encryption key,

encrypt the media encryption key using the access key,

locally store shares of the access key in a first piece wise manner throughout the plurality of data storage devices such that the access key is rendered undeterminable with less than a threshold subset of the locally stored shares stored on the plurality of data storage devices, resulting in the plurality of data storage devices being self encrypted;

generate a set of backup shares of the access key in a second piecewise manner being stored on a plurality of backup data storage devices, the set of backup shares of the access key remaining operable after removal or addition of any of the plurality of data storage devices and further remaining operable after change to the shares of the access key;

upon a change to the plurality of data storage devices:

re-compute a new piecewise manner to store the access key throughout the plurality of data storage devices, by splitting the access key into a set of shares that are different from the locally stored shares before the change to the plurality of storage devices, and

store different shares of the set of pieces on different ones of the changed plurality of data storage devices,

wherein the re-computing the new piecewise manner of the access key renders the access key undeterminable with less than a new threshold, the new threshold being a subset of the changed plurality of data storage devices,

wherein the change to the plurality of data storage devices is any of removal of one or more data storage devices from the plurality and addition of one or more data storage devices to the plurality, resulting in increase or decrease of the plurality; and

wherein the set of backup shares have shares with a different threshold subset from the threshold subset of the locally stored shares.

10. The self encrypting data storage system of claim 9 wherein the encryption engine locally stores the access key in a piece wise manner by applying a secret sharing process.

11. The system of claim 10 wherein the secret sharing process is Shamir's secret sharing.

12. The system of claim 10 wherein the encryption engine applies the secret sharing process by:

splitting the access key into N pieces (shares);

storing different ones of the pieces on N different ones of the plurality of data storage devices, such that the threshold subset of the plurality is (N+1)/2 of the data storage devices.

13. The system of claim 9 wherein the plurality of data storage devices is a RAID (Redundant Array of Independent Disks) configuration.

14. The system of claim 9 wherein the encrypted data stored on the plurality of data storage devices is in a band of a data storage device.

15. The system of claim 9 wherein the access key is a user-generated password.

16. A data handling system comprising:

a plurality of data storage devices, the data storage devices being self-encrypting; and

an encryption engine configured to:

establish an access key for the plurality of data storage devices,

determine a media encryption key using a random number generator,

encrypt data stored on the plurality of data storage devices using the media encryption key,

encrypt the media encryption key using the access key,

locally store shares of the access key in a piece wise manner throughout the plurality of data storage devices such that the access key is rendered undeterminable with less than a threshold subset of the locally stored shares stored on the plurality of data storage devices, resulting in the plurality of data storage devices being self encrypted,

generate a set of backup shares of the access key in a second piecewise manner being stored on a plurality of backup data storage devices, the set of backup shares of the access key remaining operable after removal or addition of any of the plurality of data storage devices and further remaining operable after change to the shares of the access key; and

responsive to a change to the plurality of data storage devices:

(i) re-computing a new piecewise manner to store the access key throughout the changed plurality of data storage devices, by splitting the access key into a set of shares that are different than the locally stored shares used before the change to the plurality of storage devices, and

(ii) store different pieces of the set of pieces throughout the changed plurality of data storage devices,

wherein the re-computing the new piecewise manner of the access key renders the encryption key undeterminable with less than a new threshold, the new threshold being a subset of the changed plurality of data storage devices;

wherein the change to the plurality of data storage devices is any of removal of one or more data storage devices from the plurality and addition of one or more data storage devices to the plurality, resulting in increase or decrease of the plurality; and

wherein the set of backup shares have shares with a different threshold subset from the threshold subset of the locally stored shares.

17. The system of claim 16 wherein the encryption engine locally stores the access key in a piece wise manner by applying a secret sharing process that includes:

splitting the access key into N pieces (shares);

storing different ones of the N pieces on N different ones of the plurality of data storage devices, such that the threshold subset of the plurality is (N+1)/2 of the data storage devices.

18. The system of claim 16 wherein the encrypted data stored on the plurality of data storage devices is in a band of a data storage device.

19. The system of claim 16 wherein the access key is a user-generated password.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2013
From: KONING, G. PAUL; HSU-HUNG, DAMON; HOLLANDER, STUART L.
To: DELL PRODUCTS, LP
Reel/Frame 031001/0870 →
Continuity (1)
Related Publication 20150052369A1 · Feb 19, 2015