IP Library › Granted Patent US 10,680,813
Granted Patent B2
US 10,680,813 · App. 16/270,254 · Granted Jun 9, 2020

Crypto-erasure resilient to network outage

Inventor: Charles W. Kaufman (Redmond, WA)
Assignee: EMC IP Holding Company LLC
H04L9/0891H04L9/083H04L9/0822H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,680,813
App. No.
16/270,254
Granted
Jun 9, 2020
Kind
B2
Abstract

Providing a server polling component for remote cryptographic key erasure resilient to network outage. A set of keys received from a server are stored on data storage. The data storage sends a status request to the server. If a key enabled status is received, the data storage continues normal operations. If a key disabled status is received, a key failure action is performed. The key failure action includes deleting one or more of the keys in the set of keys or shutting down one or more storage devices of the data storage. If no response is received from the server, the data storage iteratively resends the status request at retry time intervals until a response is received from the server or until a time out period expires. On expiration of the time out period, the key failure action is performed.

Claims (15)

1. One or more non-transitory, computer-readable storage media having computer executable instructions, said instructions comprising server polling instructions that, when executed, cause at least one processor to:

send a key request to an external key server, the key request is a request for a set of keys stored on the external key server, the set of keys corresponding to a portion of encrypted data stored on a data storage;

utilize a local copy of the set of keys to decrypt the portion of the encrypted data on receiving a key enabled status from the external key server, the key enabled status indicating the set of keys are available from the key server;

initiate a key failure action on receiving a key unavailable response indicating at least one key in the set of keys is unavailable from the key server; and

on determining a time out period is reached without receiving a response to the key request from the key server, perform the key failure action.

2. The computer storage media of claim 1 , wherein the key request is a first key request, and wherein the key decryption component is further executed to cause the at least one processor to:

on determining a first retry time interval has occurred, send a second key request to the key server,

wherein the server polling component iteratively sends key requests to the server at retry time intervals until a response is received from the key server or a time out period occurs, and

wherein the time out period is a maximum length of time for sending key requests to the key server at the retry time intervals without receiving a response to the key requests from the key server.

3. The computer storage media of claim 1 , wherein the key server is a first key server, and wherein the key decryption component is further executed to cause the at least one processor to:

send the key request to a set of key servers, the set of key servers comprising the first key server and a second key server;

utilize the local copy of the set of keys to decrypt the portion of the encrypted data on receiving the set of keys from all key servers in the set of key servers; and

initiate the key failure action on failing to receive at least one key in the set of keys from one or more key servers in the set of key server within a time out period.

4. The computer storage media of claim 1 , wherein performing the key failure action further comprises disabling at least one data storage device on the data storage associated with the encrypted data corresponding to the set of keys.

5. The computer storage media of claim 1 , wherein performing the key failure action further comprises deleting the local copy of the set of keys from a memory of the data storage.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2019
From: KAUFMAN, CHARLES W.
To: EMC CORPORATION
Reel/Frame 050132/0208 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2019
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 048691/0661 →
Continuity (2)
Division 15085890 · Mar 30, 2016
Related Publication 20190173675A1 · Jun 6, 2019
Cited By (1)
US 12,346,267