IP Library Granted Patent US 9,633,232
Granted Patent B2
US 9,633,232 · App. 14/309,488 · Granted Apr 25, 2017

System and method for encrypting secondary copies of data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,633,232
App. No.
14/309,488
Granted
Apr 25, 2017
Kind
B2
Abstract

A system and method for encrypting secondary copies of data is described. In some examples, the system encrypts a secondary copy of data after the secondary copy is created. In some examples, the system looks to information about a data storage system, and determines when and where to encrypt data based on the information.

Claims (30)

1. A system of re-encrypting data copied to one or more secondary storage devices comprising:

a storage manager comprising at least computer hardware configured to process information about a data storage operation associated with copying data stored on one or more primary storage devices to one or more secondary devices;

the storage manager further configured to estimate a completion time required to encrypt and copy the data;

when the completion time exceeds a threshold, the storage manager is configured to determine a first subset of the data to store as a non-encrypted first subset;

an encryption component comprising at least computer hardware configured to encrypt a second subset of the data to store as an encrypted second subset, wherein the encryption component is configured to encrypt the second subset based on a first encryption scheme; and

the encryption component further decrypts the encrypted second subset associated with the first encryption scheme and re-encrypts at least a portion of the second subset with a second encryption scheme, wherein at least a portion of the non-encrypted first subset remains non-encrypted.

2. The system of claim 1 wherein the encryption component encrypts the second subset of the data with the first encryption scheme using resources associated with the data storage operation.

3. The system of claim 1 wherein the encryption component encrypts the second subset of the data with the first encryption scheme using other resources that are not associated with the data storage operation.

4. The system of claim 1 wherein the encryption component re-encrypts at least the portion of the second subset with the second encryption scheme using resources that are associated with the data storage operation.

5. The system of claim 1 wherein the encryption component re-encrypts at least the portion of the second subset with the second encryption scheme using resources that are not associated with the data storage operation.

6. The system of claim 1 wherein the re-encrypted second portion of the second subset is stored one or more third storage devices.

7. The system of claim 1 wherein the re-encrypted second portion of the second subset is stored in at least a third storage device that has a different storage format than the one or more secondary storage devices.

8. The system of claim 1 wherein at least a second portion of the non-encrypted first subset is encrypted with the second encryption scheme.

9. The system of claim 1 further comprising an encryption tracking component configured to maintain an index that identifies the non-encrypted first subset.

10. The system of claim 1 further comprising an encryption tracking component configured to maintain an index that identifies the encrypted second subset.

11. A method of re-encrypting data copied to one or more secondary storage devices, the method comprising:

receiving information about a data storage operation associated with copying data stored on one or more primary storage devices to one or more secondary devices;

estimating a completion time required to encrypt and copy the data;

when the completion time exceeds a threshold, determining a first subset of the data to store as a non-encrypted first subset;

encrypting a second subset of the data to store as an encrypted second subset, wherein the encrypting is performed based on a first encryption scheme; and

decrypting the encrypted second subset associated with the first encryption scheme and re-encrypting at least a portion of the second subset with a second encryption scheme, wherein at least a portion of the non-encrypted first subset remains non-encrypted.

12. The method of claim 11 wherein encrypting the second subset of the data with the first encryption scheme uses resources associated with the data storage operation.

13. The method of claim 11 wherein encrypting the second subset of the data with the first encryption scheme uses other resources that are not associated with the data storage operation.

14. The method of claim 11 wherein re-encrypting at least the portion of the second subset with the second encryption scheme uses resources that are associated with the data storage operation.

15. The method of claim 11 wherein re-encrypting at least the portion of the second subset with the second encryption scheme uses resources that are not associated with the data storage operation.

16. The method of claim 11 further comprising storing the re-encrypted second portion of the second subset one or more third storage devices.

17. The method of claim 11 further comprising storing the re-encrypted second portion of the second subset in at least a third storage device that has a different storage format than the one or more secondary storage devices.

18. The method of claim 11 further comprising encrypting at least a second portion of the non-encrypted first subset with the second encryption scheme.

19. The method of claim 11 further comprising maintaining an index that identifies the non-encrypted first subset.

20. The method of claim 11 further comprising maintaining an index that identifies the encrypted second subset.

Assignments (3)
SUPPLEMENTAL CONFIRMATORY GRANT OF SECURITY INTEREST IN UNITED STATES PATENTS Recorded Apr 16, 2025
From: COMMVAULT SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 070864/0344 →
SECURITY INTEREST Recorded Dec 13, 2021
From: COMMVAULT SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 058496/0836 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2014
From: GOKHALE, PARAG; EROFEEV, ANDREI; MULLER, MARCUS S.
To: COMMVAULT SYSTEMS, INC.
Reel/Frame 033713/0521 →