IP Library Granted Patent US 11,449,620
Granted Patent B2
US 11,449,620 · App. 16/366,101 · Granted Sep 20, 2022

Transparent high-performance data-at-rest encryption for platform-as-a-service (PaaS) environments

Inventor: Maksim Yankovskiy (Mountain View, CA)
Assignee: ZETTASET, INC.
G06F21/602G06F8/60G06F9/45558G06F16/188H04L9/083H04L9/0894G06F2009/4557H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,449,620
App. No.
16/366,101
Granted
Sep 20, 2022
Kind
B2
Abstract

Apparatus and methods are disclosed for transparently and efficiently encrypting data-at-rest in a platform as a service (PaaS) environment. Disclosed techniques transparently transform any existing persistent data services in the PaaS environment into respective secure data services. For the deployment of the above secure data services, an encryption addon containing an addon core and activity-based callouts is provided. The addon core contains a kernel module for encryption/decryption. A coordinator in charge of the deployment executes a pre-filesystem-creation callout that encrypts a raw storage device before creating a filesystem on it. It then deploys a secure data service configured to use the filesystem. Thus, applications using the data service can now transparently store data as encrypted data-at-rest in the filesystem. Similarly, the coordinator also executes a pre-filesystem-mounting callout before mounting the filesystem for accessing encrypted-data-rest. Thus, applications using the secure data service can transparently decrypt and use the encrypted data-at-rest.

Claims (24)

1. A computer system for providing a platform as a service (PaaS), said computer system comprising at least one memory device storing computer-readable instructions and at least one microprocessor coupled to said at least one memory device for executing said computer-readable instructions, said at least one microprocessor configured to:

(a) deploy a virtual machine (VM);

(b) deploy a stemcell operating-system in said VM;

(c) deploy an encryption addon in said VM, wherein said encryption addon comprises an addon core, a pre-filesystem-creation callout and a pre-filesystem-mounting callout;

(d) deploy over a device driver of a raw persistent storage device, an encrypt-decrypt kernel module contained in a setup code of said addon core;

(e) in advance of creating a filesystem on said raw persistent storage device accessible in said VM, execute said pre-filesystem-creation callout for encrypting said raw persistent storage device to obtain a corresponding encrypted raw persistent storage device;

(f) create said filesystem on said encrypted raw persistent storage device;

(g) deploy a secure data service configured on said filesystem for storing and accessing data as encrypted data-at-rest related to said PaaS; and

(h) wherein said encrypt-decrypt kernel module traps write operations issued from said secure data service for ongoing encryption, and traps read operations issued from said secure data service for ongoing decryption of said data-at-rest.

2. The computer system of claim 1 , wherein said encrypted data-at-rest is stored in said filesystem in one of a relational database, a noSQL database, an object database and flat files.

3. The computer system of claim 1 , wherein said encryption addon further comprises one or both of a post-filesystem-creation callout and a post-filesystem-mounting callout.

4. A computer-implemented method of providing an encrypted data service in a platform-as-a-service (PaaS) environment, said method comprising the steps of:

(a) deploying a virtual machine (VM) in said PaaS environment;

(b) deploying a stemcell in said VM;

(c) deploying an encryption addon in said VM, said encryption addon comprising an addon core, a pre-filesystem-creation callout and a pre-filesystem-mounting callout;

(d) deploying over a device driver of a raw persistent storage device, an encrypt-decrypt kernel module contained in a setup code of said addon core;

(e) in advance of creating a filesystem on said raw persistent storage device accessible in said VM, executing said pre-filesystem-creation callout for encrypting said raw persistent storage device, and thus obtaining a corresponding encrypted raw persistent storage device;

(f) creating said filesystem on said encrypted raw persistent storage device;

(g) deploying said encrypted data service on said filesystem for storing and accessing data as encrypted data-at-rest;

(h) providing said steps (a) through (g) to be performed by a coordinator module operating in said PaaS environment; and

(i) providing said encrypt-decrypt kernel module to trap write operations issued from said encrypted data service for ongoing encryption, and providing said encrypt-decrypt kernel module to trap read operations issued from said encrypted data service for ongoing decryption of said encrypted data-at-rest.

5. The computer-implemented method of claim 4 , storing said encrypted data-at-rest in said filesystem in one of a relational database, a noSQL database, an object database and flat files.

6. The computer-implemented method of claim 4 with said encryption addon further comprising one or both of a pre-filesystem-unmounting callout and a pre-filesystem-destroying callout.

7. The computer-implemented method of claim 6 , providing said pre-filesystem-destroying callout to be executed during a dismantling of said encrypted data service.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2025
From: ZETTASET, INC.; TPK INVESTMENTS, LLC
To: TPK INVESTMENTS, LLC; CYBER CASTLE, INC.
Reel/Frame 070572/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2019
From: YANKOVSKIY, MAKSIM
To: ZETTASET, INC.
Reel/Frame 048713/0246 →
Continuity (1)
Related Publication 20200311288A1 · Oct 1, 2020