IP Library › Granted Patent US 10,146,961
Granted Patent B1
US 10,146,961 · App. 15/274,373 · Granted Dec 4, 2018

Encrypting replication journals in a storage system

Inventors: Leehod Baruch (Rishon Leziyon, IL); Assaf Natanzon (Tel Aviv, IL); Jehuda Shemer (Kfar Saba, IL); Amit Lieberman (Raanana, IL); Ron Bigman (Holon, IL)
Assignee: EMC IP HOLDING COMPANY LLC
G06F21/78G06F3/065G06F3/0619G06F3/0673H04L9/0891H04L9/0894H04L2209/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,146,961
App. No.
15/274,373
Filed
Sep 23, 2016
Granted
Dec 4, 2018
Kind
B1
Art Unit
2498
USPC
713/193
Abstract

Described embodiments provide systems and methods for encrypting journal data of a storage system. At least one key is generated, each key having an associated key identifier. The at least one key and the associated key identifiers are stored to a key store. User data is read from a replica volume of the storage system. The read user data is encrypted with an associated key. Encrypted data is written to a journal associated with the replica volume. The key identifier of the associated key is written to the journal.

Claims (63)

1. A method of encrypting journal data of a storage system, the method comprising:

generating keys, each of the keys having an associated key identifier;

storing the keys and the associated key identifiers to a key store;

reading user data from a replica volume of the storage system;

encrypting the read user data with one of the keys;

writing encrypted user data to a journal associated with the replica volume;

writing the key identifier of the key used to the encrypted user data to the journal;

determining, from encrypted journal data of the journal, the key identifier of the key corresponding to the encrypted user data;

decrypting the encrypted journal data with the key from the key store, the retrieved key corresponding to the key identifier;

writing the decrypted journal data to a roll back replica;

rolling back a production volume to an earlier point in time based upon the roll back replica; and

writing decrypted journal data to a metadata stream associated with the roll back replica and rolling back the production volume based upon the metadata stream.

2. The method of claim 1 , wherein generating the keys comprises generating, periodically based on a key expiration period, at least one new key to replace at least one expired key.

3. The method of claim 1 , further comprising:

setting, based upon a protection window of the storage system, journal data as expired; and

determining a key identifier associated with the expired journal data; and

permanently deleting the key associated with the determined key identifier.

4. The method of claim 3 , further comprising:

periodically performing a garbage collection operation to delete journal data associated with deleted keys.

5. The method of claim 4 , wherein the garbage collection operation is performed as a background operation during idle time of the storage system, and wherein the key expiration period is set based upon the protection window.

6. A system comprising:

a processor; and

memory storing computer program code that when executed on the processor causes the processor to operate a storage system, the storage system operable to encrypting journal data by performing the operations of:

generating keys, each of the keys having an associated key identifier;

storing the keys and the associated key identifiers to a key store;

reading user data from a replica volume of the storage system;

encrypting the read user data with one of the keys;

writing encrypted user data to a journal associated with the replica volume;

writing the key identifier of the key used to encrypt the user data to the journal;

determining, from encrypted journal data of the journal, the key identifier of the key corresponding to the encrypted user data;

decrypting the journal data with a key retrieved from the key store;

writing the decrypted journal data to a roll back replica;

rolling back the production volume to an earlier point in time based upon the roll back replica; and

writing decrypted journal data to a metadata stream associated with the roll back replica and rolling back the production volume based upon the metadata stream.

7. The system of claim 6 , wherein the storage system is further operable to perform the operation of generating, periodically based on a key expiration period, at least one new key to replace at least one expired key.

8. The system of claim 6 , wherein the storage system is further operable to perform the operations of:

setting, based upon a protection window of the storage system, journal data as expired; and

determining a key identifier associated with the expired journal data; and

permanently deleting the key associated with the determined key identifier.

9. The system of claim 8 , wherein the storage system is further operable to perform the operation of:

periodically performing a garbage collection operation to delete journal data associated with deleted keys,

wherein the garbage collection operation is performed as a background operation during idle time of the storage system, and wherein the key expiration period is set based upon the protection window.

10. A computer program product including a non-transitory computer readable storage medium having computer program code encoded thereon that when executed on a processor of a computer causes the computer to operate a storage system, the computer program product comprising:

computer program code for performing operations, comprising:

generating keys, each of the keys having an associated key identifier;

storing the keys and the associated key identifiers to a key store;

reading user data from a replica volume of the storage system;

encrypting the read user data with one of the keys;

writing encrypted user data to a journal associated with the replica volume;

writing the key identifier of the key used to encrypt the user data to the journal; and

rolling back a production volume of the storage system to an earlier point in time, comprising:

determining, from encrypted journal data of the journal, the key identifier of the key corresponding to the encrypted user data;

decrypting the journal data with the key from the key store, the retrieved key corresponding to the key identifier;

writing the decrypted journal data to a roll back replica;

rolling back the production volume to the earlier point in time based upon the roll back replica; and

writing decrypted journal data to a metadata stream associated with the roll back replica and rolling back the production volume based upon the metadata stream.

11. The computer program product of claim 10 , further comprising computer program code for generating, periodically based on a key expiration period, at least one new key to replace at least one expired key.

12. The computer program product of claim 10 , wherein the computer program code further performs operations comprising:

setting, based upon a protection window of the storage system, journal data as expired; and

determining a key identifier associated with the expired journal data; and

permanently deleting the key associated with the determined key identifier.

13. The computer program product of claim 12 , further comprising computer program code for periodically performing a garbage collection operation to delete journal data associated with deleted keys,

wherein the garbage collection operation is performed as a background operation during idle time of the storage system, and wherein the key expiration period is set based upon the protection window.

Assignments (6)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 050405 FRAME 0534 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058001/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050405/0534 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2016
From: BARUCH, LEEHOD; NATANZON, ASSAF; SHEMER, JEHUDA; LIEBERMAN, AMIT; BIGMAN, RON
To: EMC IP HOLDING COMPANY, LLC
Reel/Frame 039926/0936 →
Cited By (1)
US 12,452,655