IP Library Granted Patent US 9,740,880
Granted Patent B1
US 9,740,880 · App. 14/827,690 · Granted Aug 22, 2017

Encrypted virtual machines in a cloud

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,740,880
App. No.
14/827,690
Granted
Aug 22, 2017
Kind
B1
Abstract

A method, system, and computer program product for intercepting communication between a virtual machine and an encrypted replication data stored on a storage medium and redirecting the communication to a remote replication appliance and using a key stored on the remote replication appliance to enable the virtual machine to facilitate communication with the encrypted replication data stored on the storage medium, wherein facilitating communication enables the virtual machine to interact with the encrypted replication data as unencrypted data.

Claims (38)

1. A system for accessing encrypted replication data stored on a storage medium, the system comprising:

a remote replication appliance, and

computer-executable logic operating in memory, wherein the computer-executable program logic is configured to enable a processor to execute:

intercepting communication between a virtual machine and the encrypted replication data stored on the storage medium and redirecting the communication to the remote replication appliance;

installing a certificate for accessing a key manager;

obtaining a key from the key manager;

using the key stored on the remote replication appliance to enable the virtual machine to facilitate communication with the encrypted replication data stored on the storage medium; wherein facilitating communication enables the virtual machine to interact with the encrypted replication data as unencrypted data by having the remote replication appliance use the key to decrypt and encrypt data for the virtual machine;

erasing the key from the remote replication appliance when the certificate is not re-installed at a regular interval.

2. The system of claim 1 , wherein the facilitating communication comprises encrypting data sent from the virtual machine and sending the encrypted data to the encrypted replication data stored on the storage medium.

3. The system of claim 1 , wherein facilitating communication comprises decrypting data sent from the encrypted replication data stored on the storage medium and sending the decrypted data to the virtual machine.

4. The system of claim 1 wherein obtaining the key from the key manager comprises providing the key manager with a key ID.

5. The system of claim 1 wherein the program logic is further configured to enable the processor to execute:

erasing the key from the remote replication appliance once communication between the virtual machine and the encrypted replication data stored on the storage medium has finished.

6. The system of claim 1 wherein redirecting the communication comprises sending data to the remote replication appliance as a SCSI command and modifying fields in a CDB of the SCSI command.

7. A method for accessing encrypted replication data stored on a storage medium, the method comprising:

intercepting communication between a virtual machine and the encrypted replication data stored on the storage medium and redirecting the communication to a remote replication appliance;

installing a certificate for accessing a key manager;

obtaining a key from the key manager;

using the key stored on the remote replication appliance to enable the virtual machine to facilitate communication with the encrypted replication data stored on the storage medium; wherein facilitating communication enables the virtual machine to interact with the encrypted replication data as unencrypted data by having the remote replication appliance use the key to decrypt and encrypt data for the virtual machine;

erasing the key from the remote replication appliance when the certificate is not re-installed at a regular interval.

8. The method of claim 7 wherein the facilitating communication comprises encrypting data sent from the virtual machine and sending the encrypted data to the encrypted replication data stored on the storage medium.

9. The method of claim 7 wherein facilitating communication comprises decrypting data sent from the encrypted replication data stored on the storage medium and sending the decrypted data to the virtual machine.

10. The method of claim 7 wherein obtaining the key from the key manager comprises providing the key manager with a key ID.

11. The method of claim 7 further comprising erasing the key from the remote replication appliance once communication between the virtual machine and the encrypted replication data stored on the storage medium has finished.

12. The method of claim 7 wherein redirecting the communication comprises sending data to the remote replication appliance as a SCSI command and modifying fields in a CDB of the SCSI command.

13. A computer program product comprising:

a non-transitory computer readable medium encoded with computer executable program code, wherein the code enables a processor to execute:

intercepting communication between a virtual machine and encrypted replication data stored on a storage medium and redirecting the communication to a remote replication appliance;

installing a certificate for accessing a key manager;

obtaining the key from the key manager;

using the key stored on the remote replication appliance to enable the virtual machine to facilitate communication with the encrypted replication data stored on the storage medium; wherein facilitating communication enables the virtual machine to interact with the encrypted replication data as unencrypted data by having the remote replication appliance use the key to decrypt and encrypt data for the virtual machine;

erasing the key from the remote replication appliance when the certificate is not re-installed at a regular interval.

14. The program product of claim 13 wherein the facilitating communication comprises encrypting data sent from the virtual machine and sending the encrypted data to the encrypted replication data stored on the storage medium.

15. The program product of claim 13 wherein facilitating communication comprises decrypting data sent from the encrypted replication data stored on the storage medium and sending the decrypted data to the virtual machine.

16. The program product of claim 13 wherein obtaining the key from the key manager comprises providing the key manager with a key ID.

17. The program product of claim 13 wherein the code further enables the processor to execute:

erasing the key from the remote replication appliance once communication between the virtual machine and the encrypted replication data stored on the storage medium has finished.

18. The program product of claim 13 wherein redirecting the communication comprises sending data to the remote replication appliance as a SCSI command and modifying fields in a CDB of the SCSI command.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (044535/0109) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0414 →
RELEASE OF SECURITY INTEREST AT REEL 044535 FRAME 0001 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0475 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Nov 29, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 044535/0109 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Nov 29, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 044535/0001 →