IP Library Granted Patent US 11,032,259
Granted Patent B1
US 11,032,259 · App. 16/167,789 · Granted Jun 8, 2021

Data protection in a storage system

Inventors: Andrew Bernat (Mountain View, CA); Timothy Brennan (San Francisco, CA); Ethan Miller (Santa Cruz, CA); John Colgrove (Los Altos, CA)
Assignee: Pure Storage, Inc.
H04L63/061G06F21/78H04L9/085G06F2221/2107G06F2221/2131
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,032,259
App. No.
16/167,789
Granted
Jun 8, 2021
Kind
B1
Abstract

In a storage system that includes a plurality of NVMe SSDs, data protection may be carried out by: for each of the plurality of NVMe SSDs, encrypting a device key using a master secret, wherein the device key, when not encrypted, is used to encrypt and decrypt data in one or more namespaces on the NVMe SSD; generating a plurality of shares from the master secret; and storing a separate share of the plurality of shares in a namespace prohibited from encryption on each NVMe SSD.

Claims (40)

1. A method comprising:

for each of the plurality of NVMe SSDs (‘Non-Volatile Memory Express Solid State Drives’) of a storage system, encrypting a device key using a master secret,

wherein the device key is used to encrypt and decrypt data in one or more namespaces on the NVMe SSD;

generating a plurality of shares from the master secret; and

storing a separate share of the plurality of shares in a namespace prohibited from encryption on each NVMe SSD.

2. The method of claim 1 , wherein each namespace other than the namespace that is prohibited from encryption is accessible for writing only with a device key and accessible for reading without the device key.

3. The method as recited in claim 2 , wherein encrypting, for each NVMe SSD, the device key further comprises encrypting the device key using the master secret and a value unique to the corresponding NVMe SSD.

4. The method as recited in claim 3 , further comprising:

reconstructing the master secret using a given number of shares of the plurality of shares and decrypting encrypted device keys using the master secret to generate decrypted device keys;

storing the decrypted device keys in a volatile memory; and

using the decrypted device keys to perform a plurality of accesses to one or more of the NVMe SSDs.

5. The method as recited in claim 1 , wherein a number of shares needed to reconstruct the master secret is greater than a number of shares associated with any single physical grouping of the NVMe SSDs.

6. The method as recited in claim 1 , further comprising decrypting one or more encrypted device keys using the master secret.

7. The method as recited in claim 6 , further comprising storing the decrypted device keys in a volatile memory.

8. The method as recited in claim 7 , further comprising using the decrypted device keys to perform a plurality of accesses to one or more of the NVMe SSDs.

9. A storage system comprising:

a plurality of Non-Volatile Memory Express (‘NVMe’) Solid State Drives (‘SSDs’) and a controller, wherein the controller is configured to carry out:

for each of the plurality of NVMe SSDs, encrypting a device key using a master secret, wherein the device key is used to encrypt and decrypt data in one or more namespaces on the NVMe SSD;

generating a plurality of shares from the master secret; and

storing a separate share of the plurality of shares in a namespace prohibited from encryption on each NVMe SSD.

10. The storage system of claim 9 , wherein each namespace other than the namespace that is prohibited from encryption is accessible for writing only with a device key and accessible for reading without the device key.

11. The storage system as recited in claim 10 , wherein encrypting, for each NVMe SSD, the device key further comprises encrypting the device key using the master secret and a value unique to the corresponding NVMe SSD.

12. The storage system of claim 11 , wherein the controller is further configured to carry out:

reconstructing the master secret using a given number of shares of the plurality of shares.

13. The storage system as recited in claim 12 , wherein the controller is further configured to carry out decrypting one or more encrypted device keys using the master secret.

14. The storage system as recited in claim 13 , wherein the controller is further configured to carry out storing the decrypted device keys in a volatile memory.

15. The storage system as recited in claim 14 , wherein the controller is further configured to carry out using the decrypted device keys to perform a plurality of accesses to one or more of the NVMe SSDs.

16. The storage system of claim 9 , wherein a number of shares needed to reconstruct the master secret is greater than a number of shares associated with any single physical grouping of the NVMe SSDs.

17. A storage system comprising:

a plurality of storage devices and a controller, wherein each storage device includes an interposer that couples the storage device to the storage system, and wherein the controller is configured to carry out:

for each of the plurality of storage devices, encrypting a device key using a master secret, wherein the device key is used to encrypt and decrypt data in the storage device;

generating a plurality of shares from the master secret; and

storing a separate share of the plurality of shares in memory of each storage device's interposer.

18. The storage system of claim 17 , wherein each storage device is accessible for writing only with a device key and accessible for reading without the device key.

19. The storage system as recited in claim 17 , wherein encrypting, for each storage device, the device key further comprises encrypting the device key using the master secret and a value unique to the corresponding storage device.

20. The storage system of claim 19 , wherein the controller is further configured to carry out the steps:

reconstructing the master secret using a given number of shares of the plurality of shares;

decrypting one or more encrypted device keys using the master secret;

storing the decrypted device keys in a volatile memory; and

using the decrypted device keys to perform a plurality of accesses to one or more of the storage devices.

Assignments (3)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2018
From: BERNAT, ANDREW; BRENNAN, TIMOTHY; MILLER, ETHAN; COLGROVE, JOHN
To: PURE STORAGE, INC.
Reel/Frame 047275/0952 →
Cited By (5)
US 12,387,015 US 12,406,100 US 12,493,431 US 12,547,322 US 12,634,143