IP Library Granted Patent US 9,892,265
Granted Patent B1
US 9,892,265 · App. 14/674,205 · Granted Feb 13, 2018

Protecting virtual machine data in cloud environments

Inventors: Soumya Tripathy (West Bengal, IN); Subhadeep Ghosh (West Bengal, IN)
Assignee: Veritas Technologies LLC
G06F21/602G06F9/4406G06F9/45533
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,892,265
App. No.
14/674,205
Granted
Feb 13, 2018
Kind
B1
Abstract

Various systems, methods, and processes to protect virtual machine data in a cloud environment are disclosed. A request for requested data is received at an encryption virtual machine. The requested data is encrypted, and the encryption virtual machine is configured to receive the request from an application virtual machine via a loader. The requested data includes one or more operating system modules, and the operating system modules are configured to be used by the application virtual machine. The requested data is accessed in a storage volume, which is communicatively coupled to the encryption virtual machine. The requested data is then retrieved from the storage volume and decrypted at the encryption virtual machine. The decrypted data is then sent to the loader.

Claims (98)

1. A method comprising:

receiving a request for requested data at an encryption virtual machine, wherein the requested data is encrypted,

the encryption virtual machine is configured to receive the request from a plurality of application virtual machines via a plurality of loaders,

the requested data comprises one or more operating system modules, and

the operating system modules are configured to be used by the plurality of application virtual machines;

accessing the requested data in a storage volume, wherein

the storage volume is communicatively coupled to the encryption virtual machine,

the encryption virtual machine is coupled between the plurality of application virtual machines and the storage volume,

the requested data is retrieved from the storage volume, and

the requested data is decrypted at the encryption virtual machine; and

sending the decrypted data to the plurality of loaders.

2. The method of claim 1 , wherein

the one or more operating system modules comprise operating system data, and

the operating system data is used by a loader of the plurality of loaders to boot an application virtual machine of the plurality of application virtual machines.

3. The method of claim 1 , wherein

the storage volume is not communicatively coupled to the plurality of application virtual machines.

4. The method of claim 2 , wherein

the loader implements a Storage Area Network (SAN) client,

the encryption virtual machine implements a SAN target, and

the SAN client serves the application virtual machine with the decrypted data sent to the loader from the SAN target.

5. The method of claim 2 , further comprising:

accessing a map file in the encryption virtual machine prior to accessing the requested data in a storage volume, wherein

the map file comprises an encryption key associated with the application virtual machine,

the map file maintains a mapping between the application virtual machine and the encryption key associated with the application virtual machine, and

the map file comprises a location of the requested data in the storage volume.

6. The method of claim 2 , wherein

the loader is communicatively coupled to both the application virtual machine and the encryption virtual machine.

7. The method of claim 4 , wherein

the SAN client uses Internet Small Computer System Interface (iSCSI) protocol to send the request for data to the SAN target; and

the SAN target uses the iSCSI protocol to send the decrypted data to the SAN client.

8. The method of claim 2 , wherein

the loader is implemented in a virtual disk, the loader is a boot loader, and the virtual disk is an iPXE disk.

9. A non-transitory computer readable storage medium comprising program instructions executable to:

receive a request for requested data at an encryption virtual machine, wherein the requested data is encrypted,

the encryption virtual machine is configured to receive the request from a plurality of application virtual machines via a plurality of loaders,

the requested data comprises one or more operating system modules, and

the operating system modules are configured to be used by the plurality of application virtual machines;

access the requested data in a storage volume, wherein

the storage volume is communicatively coupled to the encryption virtual machine,

the encryption virtual machine is coupled between the plurality of application virtual machines and the storage volume,

the requested data is retrieved from the storage volume, and

the requested data is decrypted at the encryption virtual machine; and

send the decrypted data to the plurality of loaders.

10. The non-transitory computer readable storage medium of claim 9 , wherein

the one or more operating system modules comprise operating system data, and

the operating system data is used by a loader of the plurality of loaders to boot an application virtual machine of the plurality of application virtual machines, and

the storage volume is not communicatively coupled to the application virtual machine.

11. The non-transitory computer readable storage medium of claim 10 , wherein

the loader implements a Storage Area Network (SAN) client,

the encryption virtual machine implements a SAN target,

the SAN client serves the application virtual machine with the decrypted data sent to the loader from the SAN target,

the SAN client uses Internet Small Computer System Interface (iSCSI) protocol to send the request for data to the SAN target; and

the SAN target uses the iSCSI protocol to send the decrypted data to the SAN client.

12. The non-transitory computer readable storage medium of claim 10 , further comprising:

accessing a map file in the encryption virtual machine prior to accessing the requested data in a storage volume, wherein

the map file comprises an encryption key associated with the application virtual machine,

the map file maintains a mapping between the application virtual machine and the encryption key associated with the application virtual machine, and

the map file comprises a location of the requested data in the storage volume.

13. The non-transitory computer readable storage medium of claim 10 , wherein

the loader is communicatively coupled to both the application virtual machine and the encryption virtual machine.

14. The non-transitory computer readable storage medium of claim 10 , wherein

the loader is implemented in a virtual disk,

the loader is a boot loader, and

the virtual disk is an iPXE disk.

15. A system comprising:

one or more hardware processors; and

a memory coupled to the one or more hardware processors, wherein the memory stores program instructions executable by the one or more hardware processors to:

receive a request for requested data at an encryption virtual machine, wherein the requested data is encrypted,

the encryption virtual machine is configured to receive the request from a plurality of application virtual machines via a plurality of loaders,

the requested data comprises one or more operating system modules, and

the operating system modules are configured to be used by the plurality of application virtual machines;

access the requested data in a storage volume, wherein

the storage volume is communicatively coupled to the encryption virtual machine,

the encryption virtual machine is coupled between the plurality of application virtual machines and the storage volume,

the requested data is retrieved from the storage volume, and

the requested data is decrypted at the encryption virtual machine; and

send the decrypted data to the plurality of loaders.

16. The system of claim 15 , wherein

the one or more operating system modules comprise operating system data, and

the operating system data is used by a loader of the plurality of loaders to boot an application virtual machine of the plurality of application virtual machines, and

the storage volume is not communicatively coupled to the application virtual machine.

17. The system of claim 16 , wherein

the loader implements a Storage Area Network (SAN) client,

the encryption virtual machine implements a SAN target,

the SAN client serves the application virtual machine with the decrypted data sent to the loader from the SAN target,

the SAN client uses Internet Small Computer System Interface (iSCSI) protocol to send the request for data to the SAN target; and

the SAN target uses the iSCSI protocol to send the decrypted data to the SAN client.

18. The system of claim 16 , further comprising:

accessing a map file in the encryption virtual machine prior to accessing the requested data in a storage volume, wherein

the map file comprises an encryption key associated with the application virtual machine,

the map file maintains a mapping between the application virtual machine and the encryption key associated with the application virtual machine, and

the map file comprises a location of the requested data in the storage volume.

19. The system of claim 16 , wherein

the loader is communicatively coupled to both the application virtual machine and the encryption virtual machine.

20. The system of claim 16 , wherein

the loader is implemented in a virtual disk,

the loader is a boot loader, and

the virtual disk is an iPXE disk.

Assignments (13)
AMENDMENT NO. 1 TO PATENT SECURITY AGREEMENT Recorded Apr 8, 2025
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2025
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 070335/0013 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC (F/K/A VERITAS US IP HOLDINGS LLC)
Reel/Frame 069712/0090 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY IN PATENTS AT R/F 037891/0726 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS US IP HOLDINGS, LLC
Reel/Frame 054535/0814 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
MERGER Recorded Apr 18, 2016
From: VERITAS US IP HOLDINGS LLC
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 038483/0203 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037891/0726 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037891/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2016
From: SYMANTEC CORPORATION
To: VERITAS US IP HOLDINGS LLC
Reel/Frame 037693/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2015
From: TRIPATHY, SOUMYA; GHOSH, SUBHADEEP
To: SYMANTEC CORPORATION
Reel/Frame 035298/0662 →