IP Library Granted Patent US 10,936,759
Granted Patent B1
US 10,936,759 · App. 16/118,546 · Granted Mar 2, 2021

Systems, methods and computer-readable media for providing enhanced encryption in a storage system

Inventors: Paresh Chatterjee (Fremont, CA); Raghavan Sowrirajan (Fremont, CA); Sakthi Kumar B (Chennai, IN); Soumyadarshi Adhikari (Chennai, IN)
Assignee: Amzetta Technologies, LLC
G06F21/80G06F3/064G06F3/0623G06F3/0644G06F3/0659G06F3/0673H04L9/088H04L9/0631
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,936,759
App. No.
16/118,546
Granted
Mar 2, 2021
Kind
B1
Abstract

Described herein are systems, methods, and computer-readable media for providing enhanced encryption in a data storage system. An example method can include receiving a data set, selecting a first portion of the data set as a unique encryption key, encrypting a second portion of the data set using the unique encryption key, and writing the encrypted second portion of the data set to a storage device.

Claims (34)

1. A computer-implemented method for providing enhanced encryption in a data storage system, comprising:

receiving, using a processor, a data set comprising a plurality of data blocks;

selecting, using the processor, a first portion of the data set as a unique encryption key, the first portion of the data set comprising one or more of the data blocks;

encrypting, using the processor, a second portion of the data set using the unique encryption key, the second portion of the data set comprising one or more of the data blocks, wherein each of the first and second portions of the data set comprises different data blocks;

encrypting, using the processor, the first portion of the data set using a user-defined encryption key;

partitioning, using the processor, the encrypted data set into a plurality of data blocks, wherein the encrypted data set includes the encrypted first and second portions of the data set; and

writing, using the processor, the plurality of data blocks of the encrypted data set in a non-sequential order to a storage device.

2. The computer-implemented method of claim 1 , further comprising restricting, using the processor, access to the user-defined encryption key.

3. The computer-implemented method of claim 1 , wherein the plurality of data blocks of the encrypted data set are written at a contiguous region of the storage device.

4. The computer-implemented method of claim 3 , further comprising maintaining, using the processor, a lookup table for storing the non-sequential order of the plurality of data blocks written at the contiguous region of the storage device.

5. The computer-implemented method of claim 1 , wherein the plurality of data blocks of the encrypted data set are written at a plurality of non-contiguous regions of the storage device.

6. The computer-implemented method of claim 5 , further comprising maintaining, using the processor, a mapping table for storing respective physical locations of the plurality of data blocks written at the plurality of non-contiguous regions of the storage device.

7. The computer-implemented method of claim 1 , further comprising serializing, using the processor, the plurality of data blocks of the encrypted data set with a plurality of data blocks of a second encrypted data set.

8. The computer-implemented method of claim 1 , wherein the first portion of the data set is at least one of randomly selected, selected by a user, or selected in dependence on a target logical volume for the data set.

9. A non-transitory computer-readable recording medium having computer-executable instructions stored thereon for providing enhanced encryption in a data storage system that, when executed by a processor, cause the processor to:

receive a data set comprising a plurality of data blocks;

select a first portion of the data set as a unique encryption key, the first portion of the data set comprising one or more of the data blocks;

encrypt a second portion of the data set using the unique encryption key, the second portion of the data set comprising one or more of the data blocks, wherein each of the first and second portions of the data set comprises different data blocks;

encrypt the first portion of the data set using a user-defined encryption key;

partition the encrypted data set into a plurality of data blocks, wherein the encrypted data set includes the encrypted first and second portions of the data set; and

write the plurality of data blocks of the encrypted data set in a non-sequential order to a storage device.

10. The non-transitory computer-readable recording medium of claim 9 , having further computer-executable instructions stored thereon that, when executed by the processor, cause the processor to restrict access to the user-defined encryption key.

11. The non-transitory computer-readable recording medium of claim 9 , wherein the plurality of data blocks of the encrypted data set are written at a contiguous region or non-contiguous region of the storage device.

12. The non-transitory computer-readable recording medium of claim 9 , having further computer-executable instructions stored thereon that, when executed by the processor, cause the processor to serialize the plurality of data blocks of the encrypted data set with a plurality of data blocks of a second encrypted data set.

13. The non-transitory computer-readable recording medium of claim 9 , wherein the first portion of the data set is at least one of randomly selected, selected by a user, or selected in dependence on a target logical volume for the data set.

14. A storage server computer for providing enhanced encryption, comprising:

a processor; and

a memory operably connected to the processor, the memory having computer-executable instructions stored thereon that, when executed by the processor, cause the processor to:

receive a data set comprising a plurality of data blocks;

select a first portion of the data set as a unique encryption key, the first portion of the data set comprising one or more of the data blocks;

encrypt a second portion of the data set using the unique encryption key, the second portion of the data set comprising one or more of the data blocks, wherein each of the first and second portions of the data set comprises different data blocks;

encrypt the first portion of the data set using a user-defined encryption key;

partition the encrypted data set into a plurality of data blocks, wherein the encrypted data set includes the encrypted first and second portions of the data set; and

write the plurality of data blocks of the encrypted data set in a non-sequential order to a storage device.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2020
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: AMZETTA TECHNOLOGIES, LLC
Reel/Frame 053198/0255 →
CONVERSION Recorded Mar 24, 2020
From: AMERICAN MEGATRENDS, INC.
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 052216/0207 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2018
From: SOWRIRAJAN, RAGHAVAN; KUMAR B, SAKTHI; ADHIKARI, SOUMYADARSHI
To: AMERICAN MEGATRENDS, INC.
Reel/Frame 046933/0707 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2018
From: CHATTERJEE, EXECUTRIX OF THE ESTATE OF PARESH CHATTERJEE, UDITA
To: AMERICAN MEGATRENDS, INC.
Reel/Frame 046933/0724 →
Cited By (3)
US 12,323,521 US 12,362,944 US 12,695,614