IP Library Granted Patent US 9,830,278
Granted Patent B1
US 9,830,278 · App. 15/275,926 · Granted Nov 28, 2017

Tracking replica data using key management

Inventors: John S. Harwood (Paxton, MA); Thomas E. Linnell (Northborough, MA); John T. Fitzgerald (Mansfiled, MA)
Assignee: EMC IP HOLDING COMPANY LLC
G06F12/1408G06F3/065G06F3/067G06F3/0619G06F3/0689H04L63/061G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,830,278
App. No.
15/275,926
Granted
Nov 28, 2017
Kind
B1
Abstract

Source and replica data in a storage area network is tracked during management of data encryption keys. Association of source and replica data allows for all copies of customer information in an enterprise to be managed as a single entity for deletion or tracked for management purposes by using referenced data encryption keys upon creation of replicas. Any replica from a source storage object can be created using the source storage object data encryption key or an associated key and tracked by these keys as a subset of the number of replicas created. Management of the data encryption keys can control the lifetime of data on a storage array and in the storage area network without managing every replicated instance for the lifetime of the data.

Claims (47)

1. A computer-implemented method for generating a wrapped data encryption key, the method comprising:

generating, at a server, an encryption key based on a secure pseudo-random number generator;

concatenating an object identifier to the encryption key, the object identifier associated with an object to be encrypted;

generating a ciphertext by encrypting the concatenated encryption key with a key encryption key;

generating an authenticity code by encrypting the encrypted concatenated encryption key with a redundancy key; and

generating a wrapped data encryption key by concatenating the ciphertext with the authenticity code.

2. The method of claim 1 , further comprising:

receiving, at a storage processor from a host processor via a storage area network, a request to write the object to a logical unit number of a disk drive set;

receiving, from the server via a computer network, the wrapped data encryption key;

encrypting the object with the wrapped data encryption key; and

storing the object to the logical unit number.

3. The method of claim 1 , further comprising:

receiving, at a second storage processor from the first storage processor via the storage area network, a request to replicate the object;

storing, by the second storage processor, the object in a second logical unit number of a second disk drive set; and

transmitting, by the second storage processor to the server via a computer network, an request to associate the wrapped encryption key with the object stored in the second logical unit number of the second disk drive set.

4. A system for generating a wrapped data encryption key, the method comprising:

a processor;

a memory storing instructions, the instructions being adapted to cause the processor to execute steps comprising:

generating, at a server, an encryption key based on a secure pseudo-random number generator;

concatenating an object identifier to the encryption key, the object identifier associated with an object to be encrypted;

generating a ciphertext by encrypting the concatenated encryption key with a key encryption key;

generating an authenticity code by encrypting the encrypted concatenated encryption key with a redundancy key; and

generating a wrapped data encryption key by concatenating the ciphertext with the authenticity code.

5. The system of claim 4 , the instructions being adapted to cause the processor to execute steps comprising:

receiving, at a storage processor from a host processor via a storage area network, a request to write the object to a logical unit number of a disk drive set;

receiving, from the server via a computer network, the wrapped data encryption key;

encrypting the object with the wrapped data encryption key; and

storing the object to the logical unit number.

6. The system of claim 3 , the instructions being adapted to cause the processor to execute steps comprising:

receiving, at a second storage processor from the first storage processor via the storage area network, a request to replicate the object;

storing, by the second storage processor, the object in a second logical unit number of a second disk drive set; and

transmitting, by the second storage processor to the server via a computer network, an request to associate the wrapped encryption key with the object stored in the second logical unit number of the second disk drive set.

7. A non-transitory computer readable medium including computer code adapted to be executed on electronic computer hardware, the code comprising:

code for generating, at a server, an encryption key based on a secure pseudo-random number generator;

code for concatenating an object identifier to the encryption key, the object identifier associated with an object to be encrypted;

code for generating a ciphertext by encrypting the concatenated encryption key with a key encryption key;

code for generating an authenticity code by encrypting the encrypted concatenated encryption key with a redundancy key; and

code for generating a wrapped data encryption key by concatenating the ciphertext with the authenticity code.

8. The non-transitory computer readable medium of claim 7 , the code further comprising:

code for receiving, at a storage processor from a host processor via a storage area network, a request to write the object to a logical unit number of a disk drive set;

code for receiving, from the server via a computer network, the wrapped data encryption key;

code for encrypting the object with the wrapped data encryption key; and

code for storing the object to the logical unit number.

9. The non-transitory computer readable medium of claim 7 , the code further comprising:

code for receiving, at a second storage processor from the first storage processor via the storage area network, a request to replicate the object;

code for storing, by the second storage processor, the object in a second logical unit number of a second disk drive set; and

code for transmitting, by the second storage processor to the server via a computer network, an request to associate the wrapped encryption key with the object stored in the second logical unit number of the second disk drive set.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 061749/0924 →
RELEASE OF SECURITY INTEREST AT REEL 045482 FRAME 0395 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0314 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
Continuity (1)
Continuation 12043728 · Mar 6, 2008