IP Library Granted Patent US 9,298,938
Granted Patent B2
US 9,298,938 · App. 14/575,755 · Granted Mar 29, 2016

System and method for general purpose encryption of data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,298,938
App. No.
14/575,755
Granted
Mar 29, 2016
Kind
B2
Abstract

Systems and methods for reducing problems and disadvantages associated with traditional approaches to encryption and decryption of data are provided. An information handling system may include a processor, a memory communicatively coupled to the processor, and an encryption accelerator communicatively coupled to the processor. The encryption accelerator may be configured to encrypt and decrypt information in accordance with a plurality of cryptographic functions, receive a command from the processor to perform an encryption or decryption task upon data associated with an input/output operation, and in response to receiving the command, encrypt or decrypt the data associated with the input/output operation based on a particular one of the plurality of cryptographic functions.

Claims (33)

1. An information handling system, comprising:

a processor;

a memory communicatively coupled to the processor;

a storage resource communicatively coupled to the processor; and

an encryption status module stored in the memory and configured to:

determine an encryption status of a volume of the storage resource;

track the encryption status of the volume by periodically storing, during an encryption or decryption task, a variable indicating a portion of the volume that has been encrypted or decrypted and whether the volume is at least partially encrypted or decrypted;

determine whether the volume is in a partially encrypted or decrypted state in response to an interruption to the encryption or decryption of the data stored on the volume; and

boot from the volume in the partially encrypted or decrypted state based on the determination that the volume is in the partially encrypted or decrypted state.

2. The information handling system of claim 1 , wherein the encryption status module is further configured to determine the variable by combining a first variable indicating the portion of the volume that has been encrypted or decrypted and a second variable indicating whether the volume is at least partially encrypted or decrypted.

3. The information handling system of claim 1 , wherein the variable indicates an address of a last encrypted or decrypted sector of the volume.

4. The information handling system of claim 1 , wherein the storage resource includes a sealed encryption key that is unique to the storage resource.

5. The information handling system of claim 4 , further comprising a cryptoprocessor communicatively coupled to the processor, the cryptoprocessor configured to unwrap the unique sealed encryption key for use in connection with an encryption or decryption task to be performed on data from the storage resource.

6. The information handling system of claim 5 , wherein the cryptoprocessor is further configured to authenticate that a user associated with the data is authorized to provide the unique sealed encryption key.

7. A method for encryption and decryption of data, comprising:

determining, by an encryption status module, an encryption status of a volume of a storage resource;

tracking, by the encryption status module, the encryption status of the volume by periodically storing, during an encryption or decryption task, a variable indicating a portion of the volume that has been encrypted or decrypted and whether the volume is at least partially encrypted or decrypted;

determining whether the volume is in a partially encrypted or decrypted state in response to an interruption to the encryption or decryption of the data stored on the volume; and

booting from the volume in the partially encrypted or decrypted state based on the determination that the volume is in the partially encrypted or decrypted state.

8. The method of claim 7 , further comprising determining, by the encryption status module, the variable by combining a first variable indicating the portion of the volume that has been encrypted or decrypted and a second variable indicating whether the volume is at least partially encrypted or decrypted.

9. The method of claim 7 , wherein the variable indicates an address of a last encrypted or decrypted sector of the volume.

10. The method of claim 7 , wherein the storage resource includes a sealed encryption key that is unique to the storage resource.

11. The method of claim 10 , further comprising unwrapping, by a cryptoprocessor communicatively coupled to the encryption status module, the unique sealed encryption key for use in connection with an encryption or decryption task to be performed on data from the storage resource.

12. The method of claim 11 , further comprising authenticating, by the cryptoprocessor, that a user associated with the data is authorized to provide the unique sealed encryption key.

13. A non-transitory computer-readable medium comprising instructions stored therein, the instructions readable by a processor and, when read and executed, configured to cause the processor to:

determine an encryption status of a volume of a storage resource;

track the encryption status of the volume by periodically storing, during an encryption or decryption task, a variable indicating a portion of the volume that has been encrypted or decrypted and whether the volume is at least partially encrypted or decrypted;

determine whether the volume is in a partially encrypted or decrypted state in response to an interruption to the encryption or decryption of the data stored on the volume; and

boot from the volume in the partially encrypted or decrypted state based on the determination that the volume is in the partially encrypted or decrypted state.

14. The computer-readable medium of claim 13 , wherein the instructions are further configured to cause the processor to determine the variable by combining a first variable indicating the portion of the volume that has been encrypted or decrypted and a second variable indicating whether the volume is at least partially encrypted or decrypted.

15. The computer-readable medium of claim 13 , wherein the variable indicates an address of a last encrypted or decrypted sector of the volume.

16. The computer-readable medium of claim 13 , wherein the storage resource includes a sealed encryption key that is unique to the storage resource.

17. The computer-readable medium of claim 16 , wherein the instructions are further configured to cause the processor to unwrap the unique sealed encryption key for use in connection with an encryption or decryption task to be performed on data from the storage resource.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF REEL 035104 FRAME 0043 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0123 →
RELEASE OF REEL 035103 FRAME 0809 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0934 →
RELEASE OF REEL 035103 FRAME 0536 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040016/0864 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035104/0043 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035103/0536 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035103/0809 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2014
From: STUFFLEBEAM, KENNETH W.; KOPP, MICHELE
To: DELL PRODUCTS L.P.
Reel/Frame 034551/0413 →