IP Library Granted Patent US 9,396,341
Granted Patent B1
US 9,396,341 · App. 14/675,252 · Granted Jul 19, 2016

Data encryption in a de-duplicating storage in a multi-tenant environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,396,341
App. No.
14/675,252
Granted
Jul 19, 2016
Kind
B1
Abstract

The present invention addresses encryption systems and methods in the de-duplication of data in a multi-tenant environment. The system provides isolation between tenants' stored data and the storage system. The tenants' data is broken down into many smaller raw data items. Fingerprints are generated for the raw data and compared to fingerprints of raw data previously stored on the storage system. The raw data and fingerprint are encrypted with a single use key (SUK) by the storage system. The SUK encrypted fingerprint is wrapped with a storage system key and stored with other fingerprints. The SUK encrypted fingerprint is also returned to the tenants and wrapped with a tenant key. The use of tenant key wraps allows the tenant data to be protected and confidential to each tenant but allows the raw data to be shared by all tenants.

Claims (57)

1. A method for deduplicating data on a storage system comprising:

storing in the storage system a plurality of raw data objects;

storing in the storage system a plurality of fingerprints, each of the plurality of fingerprints corresponding to one of the raw data object of the plurality of raw data objects;

converting a tenant data object into a plurality of raw data objects;

calculating, by a hardware processor, a first fingerprint for a first raw data object that is one of the plurality of raw data objects;

comparing the first fingerprint with the plurality of fingerprints that have been stored;

if the first fingerprint matches any of the plurality of fingerprints that have been stored, associating the first fingerprint to the raw data object of the stored fingerprint, and not storing the first data object in the storage system;

if the first fingerprint does not match the stored fingerprint, storing the first data object in the storage system, wherein the first data object is stored in a single use key encrypted format and the first fingerprint is calculated before the first data object is encrypted;

encrypting each of the plurality of fingerprints with a single use key of a plurality of single use keys by the storage system;

transmitting some of the plurality of fingerprints that have been encrypted with the single use keys to a tenant by the storage system; and

wrapping the single use keys that encrypt the some of the fingerprints with a tenant key (T-key) by the tenant.

2. The method of claim 1 further comprising:

encrypting each of the raw data objects with one single use key of the plurality of single use keys.

3. The method of claim 2 wherein each of the single use keys is used to encrypt one of the raw data objects.

4. The method of claim 2 wherein each of the single use keys is used to encrypt two or more of the raw data objects.

5. The method of claim 1 further comprising:

encrypting each of the plurality of raw data objects with the single use key of the plurality of single use keys by the storage system.

6. The method of claim 1 further comprising:

wrapping each of the plurality of fingerprints encrypted with the plurality of single use keys with a storage system key by the storage system.

7. A system for deduplicating data, the system comprising:

a hardware processor in a computer system and configured to:

store in the storage system a plurality of raw data objects;

store in the storage system a plurality of fingerprints, each of the plurality of fingerprints corresponding to one of the raw data object of the plurality of raw data objects;

convert a tenant data object into a plurality of raw data objects;

calculate a first fingerprints for a first raw data object that is one of the plurality of raw data objects;

compare the first fingerprint with the plurality of fingerprints that have been stored;

if the first fingerprint matches any of the plurality of fingerprints that have been stored, associate the first fingerprint to the raw data object of the stored fingerprint, and not store the first data object in the storage system;

if the first fingerprint does not match the stored fingerprint, store the first data object in the storage system, wherein the first data object is stored in a single use key encrypted format and the first fingerprint is calculated before the first data object is encrypted;

encrypt each of the plurality of fingerprints with a single use key of a plurality of single use keys by the storage system;

transmit some of the plurality of fingerprints that have been encrypted with the single use keys to a tenant by the storage system; and

wrap the single use keys that encrypt the some of the fingerprints with a tenant key (T-key) by the tenant.

8. The system of claim 7 wherein the hardware processor is configured to:

encrypt each of the raw data objects with one single use key of the plurality of single use keys.

9. The system of claim 8 wherein each of the single use keys is used to encrypt one of the raw data objects.

10. The system of claim 8 wherein each of the single use keys is used to encrypt two or more of the raw data objects.

11. The system of claim 7 wherein the hardware processor is configured to:

encrypt each of the plurality of raw data objects with the single use key of the plurality of single use keys by the storage system.

12. The system of claim 7 wherein the processor based the hardware processor is configured to:

wrap each of the plurality of fingerprints encrypted with the plurality of single use keys with a storage system key by the storage system.

13. A computer program product, comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein, the computer-readable program code adapted to be executed by one or more processors to implement a method comprising:

storing in a storage system a plurality of raw data objects;

storing in the storage system a plurality of fingerprints, each of the plurality of fingerprints corresponding to one of the raw data object of the plurality of raw data objects;

converting a tenant data object into a plurality of raw data objects;

calculating, by a hardware processor, a first fingerprint for a first raw data object that is one of the plurality of raw data objects;

comparing the first fingerprint with the plurality of fingerprints that have been stored;

if the first fingerprint matches any of the plurality of fingerprints that have been stored, associating the first fingerprint to the raw data object of the stored fingerprint, and not storing the first data object in the storage system;

if the first fingerprint does not match the stored fingerprint, storing the first data object in the storage system, wherein the first data object is stored in a single use key encrypted format and the first fingerprint is calculated before the first data object is encrypted;

encrypting each of the plurality of fingerprints with a single use key of a plurality of single use keys by the storage system;

transmitting some of the plurality of fingerprints that have been encrypted with the single use keys to a tenant by the storage system; and

wrapping the single use keys that encrypt the some of the fingerprints with a tenant key (T-key) by the tenant.

14. The method of claim 13 further comprising:

encrypting each of the raw data objects with one single use key of the plurality of single use keys.

15. The method of claim 14 wherein each of the single use keys is used to encrypt two or more of the raw data objects.

16. The method of claim 13 further comprising:

encrypting each of the plurality of raw data objects with the single use key of the plurality of single use keys by the storage system.

17. The method of claim 13 further comprising:

wrapping each of the plurality of fingerprints encrypted with the plurality of single use keys with a storage system key by the storage system.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040206/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2015
From: CHANDRA, SURENDAR; SAWYER, DARREN
To: EMC CORPORATION
Reel/Frame 036535/0235 →