IP Library Granted Patent US 10,484,179
Granted Patent B1
US 10,484,179 · App. 14/673,919 · Granted Nov 19, 2019

Data consistency in an encrypted replication environment

Inventors: Assaf Natanzon (Tel Aviv, IL); Amir Amit (Ramat Hasharon, IL)
Assignee: EMC IP Holding Company LLC
H04L9/3236G06F3/067G06F3/0619G06F3/0665H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,484,179
App. No.
14/673,919
Granted
Nov 19, 2019
Kind
B1
Abstract

A System, Computer Program Product, and computer-executable method for testing data consistency in a replicated data storage environment, wherein the replicated data storage environment includes a production site and a target site, wherein the target site is located within a cloud storage provider, the System, Computer Program Product, and computer-executable method includes receiving a request for a data consistency check of encrypted data stored at the target site, retrieving replicated signatures from the target site, retrieving production signatures from the production site, and determining data consistency based on an analysis of the replicated signatures and the production signatures.

Claims (17)

1. A computer-executable method for testing data consistency in a replicated data storage environment, wherein the replicated data storage environment includes data storage systems at a production site and a target site, wherein the target site is located within a cloud storage provider and each of the data storage systems includes one or more processors and memory, the computer-executable method comprising: receiving a request for a data consistency check of encrypted data stored at the second data storage system at the target site; retrieving replicated signatures from the second data storage system at the target site, wherein the replicated signatures are based on encrypted data stored at the second data storage system, wherein the encrypted data is data that was encrypted with a production encryption key maintained only at the production site; retrieving production signatures from a first data storage system from the production site, wherein retrieving production signatures comprises: encrypting data from the first data storage system at the production site using the production encryption key maintained only at the production site; and creating the production signatures based on the encrypted data from the production site; and determining data consistency based on an analysis of the replicated signatures and the production signatures, wherein, to accurately verify consistency between the replicated signatures and the production signatures, the production encryption key maintained only at the production site is used for to encrypt both the encrypted data from the first data storage system and the encrypted data stored at the second data storage system.

2. The computer-executable method of claim 1 , further comprising initiating a data consistency check at a host in communication with the replicated data storage environment.

3. The computer-executable method of claim 1 , wherein the replicated data storage environment includes a Data Protection Appliance (DPA); configuring the DPA to conduct the data consistency check.

4. The computer-executable method of claim 3 , wherein configuring comprises: creating a periodic event using the DPA, wherein the periodic event is enabled to initiate the data consistency check.

5. The computer-executable method of claim 1 , wherein the replicated data storage environment is enabled to conduct the data consistency check on a periodic basis.

6. The computer-executable method of claim 1 , wherein retrieving the signatures from the replica site comprises: reading data from the replica site; and creating signatures for the read data using a hashing function.

7. A system, comprising: a replicated data storage environment, wherein the replicated data storage environment includes data storage systems at a production site and a target site; and computer-executable program logic encoded in memory of one or more computers enabled to test for data consistency in the replicated data storage environment, wherein the computer-executable program logic is configured for the execution of: receiving a request for a data consistency check of encrypted data stored at a first storage system at the target site; retrieving replicated signatures from the target site, wherein the replicated signatures are based on encrypted data stored at a second storage system at the target site, wherein the encrypted data is data that was encrypted with a production encryption key maintained only at the production site; retrieving production signatures from the production site, wherein retrieving production signatures comprises: encrypting data from the production site using the production encryption key maintained only at the production site; and creating the production signatures based on the encrypted data from the production site; and determining data consistency based on an analysis of the replicated signatures and the production signatures, wherein, to accurately verify consistency between the replicated signatures and the production signatures, the production encryption key maintained only at the production site is used for to encrypt both the encrypted data from the first data storage system and the encrypted data stored at the second data storage system.

8. The system of claim 7 , wherein the computer-executable program logic is further configured for the execution of initiating a data consistency check at a host in communication with the replicated data storage environment.

9. The system of claim 7 , wherein the computer-executable program logic is further configured for the execution of: wherein the replicated data storage environment includes a Data Protection Appliance (DPA); and configuring the DPA to conduct the data consistency check.

10. The system of claim 9 , wherein configuring comprises: 5 creating a periodic event using the DPA, wherein the periodic event is enabled to initiate the data consistency check.

11. The system of claim 7 , wherein the replicated data storage environment is enabled to conduct the data consistency check on a periodic basis.

12. The system claim 7 , wherein retrieving the signatures from the replica site comprises: reading data from the replica site; and creating signatures for the read data using a hashing function.

13. A computer program product for testing data consistency in a replicated data storage environment, wherein the replicated data storage environment includes data storage systems a production site and a target site, wherein the target site is located within a cloud storage provider, the computer program product comprising: a non-transitory computer readable medium encoded with computer-executable code, the code configured to enable the execution of: receiving a request for a data consistency check of encrypted data stored at a first data storage system at the target site; retrieving replicated signatures from the target site, wherein the replicated signatures are based on encrypted data stored at a second data storage system at the target site, wherein the encrypted data is data that was encrypted with a production encryption key maintained only at the production site; retrieving production signatures from the production site, wherein retrieving production signatures comprises: encrypting data from the production site using the production encryption key maintained only at the production site; and creating the production signatures based on the encrypted data from the production site; and determining data consistency based on an analysis of the replicated signatures and the production signatures, wherein, to accurately verify consistency between the replicated signatures and the production signatures, the production encryption key maintained only at the production site is used for to encrypt both the encrypted data from the first data storage system and the encrypted data stored at the second data storage system.

14. The computer program product of claim 13 , wherein the code is further configured to initiating a data consistency check at a host in communication with the replicated data storage environment.

15. The computer program product of claim 13 , wherein the code is further configured to wherein the replicated data storage environment includes a Data Protection Appliance (DPA); configuring the DPA to conduct the data consistency check.

16. The computer program product of claim 15 , wherein configuring comprises: creating a periodic event using the DPA, wherein the periodic event is enabled to initiate the data consistency check.

17. The computer program product of claim 13 , wherein retrieving the signatures from the replica site comprises: reading data from the replica site; and creating signatures for the read data using a hashing function.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052216/0758) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0680 →
RELEASE OF SECURITY INTEREST AF REEL 052243 FRAME 0773 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0152 →
SECURITY AGREEMENT Recorded Mar 26, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052243/0773 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 24, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052216/0758 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 050452 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 2, 2019
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 050610/0071 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2016
From: NATANZON, ASSAF; AMIT, AMIR
To: EMC CORPORATION
Reel/Frame 037668/0085 →
Cited By (2)
US 12,373,315 US 12,380,007