IP Library Granted Patent US 10,282,556
Granted Patent B2
US 10,282,556 · App. 15/885,567 · Granted May 7, 2019

Secure cloud-based storage of data shared across file system objects and clients

Inventors: Thomas Manville (Mountain View, CA); Julio Lopez (Mountain View, CA); Rajiv Desai (Mountain View, CA); Nathan Rosenblum (San Francisco, CA)
Assignee: EMC IP Holding Company LLC
G06F21/602G06F3/0608G06F3/0641G06F17/30094G06F17/30097G06F17/30156G06F17/30203G06F21/6218G06F21/6227G06F21/6272G06F2221/2107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,282,556
App. No.
15/885,567
Granted
May 7, 2019
Kind
B2
Abstract

Techniques to provide secure cloud-based storage of data shared across file system objects and clients are disclosed. In various embodiments, a primary encryption key is determined for an object associated with a plurality of component chunks of file system data. The primary encryption key is used to generate for each of said component chunks a corresponding chunk key, based at least in part on the primary encryption key and data comprising or otherwise associated with the chunk. The respective chunk keys are provided to a file system client configured to create and store the object at least in part by encrypting each chunk included in the plurality of component chunks using the chunk key provided for that chunk to generated encrypted chunk data, and combining the encrypted chunk data to create and store the object.

Claims (34)

1. A method of storing file system data, comprising:

computing a corresponding chunk hash value for each of a plurality of component chunks of file system data associated with an object, wherein the corresponding chunk hash value is based on at least a portion of data stored in the corresponding component chunk;

determining a primary encryption key for the object, wherein the object is comprised of the plurality of component chunks, wherein the primary encryption key is based on a hash value associated with the plurality of component chunks;

using the primary encryption key to generate, for each of said plurality of component chunks, a corresponding chunk key, wherein the corresponding chunk key is based at least in part on the primary encryption key including the hash value associated with the plurality of component chunks and the corresponding chunk hash value associated with the corresponding chunk; and

providing chunk keys of the plurality of component chunks associated with the object to a file system client, wherein the file system client is configured to encrypt each chunk included in the plurality of component chunks using a chunk key provided for that chunk.

2. The method of claim 1 , wherein the primary encryption key is determined based at least in part on data comprising or otherwise associated with the plurality of component chunks.

3. The method of claim 1 , further comprising storing the primary encryption key in a file system metadata table.

4. The method of claim 1 , wherein a size of the plurality of component chunks is selected to achieve a desired performance with respect to de-duplication.

5. The method of claim 1 , wherein the chunk keys are not stored in file system metadata.

6. The method of claim 1 , further comprising providing to the file system client an identification of the plurality of component chunks to be included in the object.

7. The method of claim 1 , wherein the plurality of component chunks of file system data comprise at least a part of a file.

8. The method of claim 7 , further comprising receiving a request to store the file, the request including data identifying the plurality of component chunks as being associated with the file.

9. The method of claim 1 , further comprising receiving a request to access a file with which the plurality of component chunks are associated.

10. The method of claim 9 , further comprising providing in response to the request a locator to be used to retrieve the object, and for each chunk a corresponding offset within the object and a corresponding chunk key to be used to decrypt the chunk.

11. A system, comprising:

a communication interface; and

a processor coupled to the communication interface and configured to:

compute a corresponding chunk hash value for each of a plurality of component chunks of file system data associated with an object, wherein the corresponding chunk hash value is based on at least a portion of data stored in the corresponding component chunk;

determine a primary encryption key for the object, wherein the object is comprised of the plurality of component chunks, wherein the primary encryption key is based on a hash value associated with the plurality of component chunks;

use the primary encryption key to generate, for each of said plurality of component chunks, a corresponding chunk key, wherein the corresponding chunk key is based at least in part on the primary encryption key including the hash value associated with the plurality of component chunks and the corresponding chunk hash value associated with the corresponding chunk; and

provide chunk keys of the plurality of component chunks associated with the object, via the communication interface, to a file system client, wherein the file system client is configured to encrypt each chunk included in the plurality of component chunks using a chunk key provided for that chunk.

12. The system of claim 11 , wherein the primary encryption key is determined based at least in part on data comprising or otherwise associated with the plurality of component chunks.

13. The system of claim 11 , wherein the processor is further configured to store the primary encryption key in a file system metadata table.

14. The system of claim 11 , wherein a size of the plurality of component chunks is selected to achieve a desired performance with respect to de-duplication.

15. The system of claim 11 , wherein the chunk keys are not stored in file system metadata.

16. The system of claim 11 , wherein the processor is further configured to provide to the file system client an identification of the plurality of component chunks to be included in the object.

17. The system of claim 11 , wherein the plurality of component chunks of file system data comprise at least a part of a file.

18. The system of claim 17 , wherein the processor is further configured to receive a request to store the file, the request including data identifying the plurality of component chunks as being associated with the file.

19. The system of claim 11 , wherein the processor is further configured to receive a request to access a file with which the plurality of component chunks are associated; and to provide in response to the request a locator to be used to retrieve the object, and for each chunk a corresponding offset within the object and a corresponding chunk key to be used to decrypt the chunk.

20. A computer program product to store file system data, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

computing a corresponding chunk hash value for each of a plurality of component chunks of file system data associated with an object, wherein the corresponding chunk hash value is based on at least a portion of data stored in the corresponding component chunk;

determining a primary encryption key for the object, wherein the object is comprised of the plurality of component chunks, wherein the primary encryption key is based on a hash value associated with the plurality of component chunks;

using the primary encryption key to generate, for each of said plurality of component chunks, a corresponding chunk key, wherein the corresponding chunk key is based at least in part on the primary encryption key including the hash value associated with the plurality of component chunks and the corresponding chunk hash value associated with the corresponding chunk; and

providing chunk keys of the plurality of component chunks associated with the object to a file system client, wherein the file system client is configured to encrypt each chunk included in the plurality of component chunks using a chunk key provided for that chunk.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 061749/0924 →
RELEASE OF SECURITY INTEREST AT REEL 045482 FRAME 0395 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0314 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2019
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 048671/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2019
From: MANVILLE, THOMAS; LOPEZ, JULIO; DESAI, RAJIV; ROSENBLUM, NATHAN
To: EMC CORPORATION
Reel/Frame 048665/0219 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
Continuity (2)
Continuation 14675439 · Mar 31, 2015
Related Publication 20180157852A1 · Jun 7, 2018