IP Library Granted Patent US 11,595,204
Granted Patent B2
US 11,595,204 · App. 16/431,132 · Granted Feb 28, 2023

Adaptive re-keying in a storage system

Inventors: Xuan Tang (Hopkinton, MA); Marion Meirlaen (Framingham, MA)
Assignee: EMC IP Holding Company LLC
H04L9/0891G06F3/0622G06F3/0637G06F3/0689G06F11/3034G06F11/3414
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,204
App. No.
16/431,132
Granted
Feb 28, 2023
Kind
B2
Abstract

Techniques for adaptive re-keying of encrypted data are provided. For example, a method comprises the following steps. Utilization information associated with a storage system is obtained, wherein the storage system comprises a set of storage devices. The method dynamically selects a re-keying process from a plurality of different re-keying processes based on at least a portion of the obtained utilization information. At least a portion of the set of storage devices are re-keyed in accordance with the selected re-keying process.

Claims (34)

1. An apparatus, comprising:

at least one processing device comprising a processor coupled to a memory;

the processing device implementing a re-keying manager for re-keying a set of storage devices in a storage system, wherein the set of storage devices comprise a set of storage array groups, wherein each of the set of storage array groups has a cryptographic key for use;

wherein the re-keying manager is configured to:

set a compliance limit for each of the cryptographic keys;

obtain utilization information associated with the storage system based at least in part on system resources and performance data, the system resources and the performance data being utilized with the compliance limit set for each of the cryptographic keys to dynamically calculate a re-key order;

dynamically select a re-keying process from a plurality of different re-keying processes based on at least a portion of the obtained utilization information and the re-key order; and

re-key at least a portion of the set of storage devices in accordance with the selected re-keying process.

2. The apparatus of claim 1 , wherein the utilization information comprises a utilization percentage value associated with a cache of the storage system.

3. The apparatus of claim 2 , wherein a first re-keying process of the plurality of different re-keying processes is selected when the cache utilization percentage value is below a given threshold value, and wherein a second re-keying process of the plurality of different re-keying processes is selected when the cache utilization percentage value is at or above the given threshold value.

4. The apparatus of claim 3 , wherein the first re-keying process comprises a proactive sparing re-keying process, and the second re-keying process comprises a data in place re-keying process.

5. The apparatus of claim 1 , wherein the utilization information comprises an input/output workload level.

6. The apparatus of claim 5 , wherein a speed of the selected re-keying process is selected based on the input/output workload level.

7. The apparatus of claim 1 , wherein re-keying is performed on a priority basis such that one storage array group is re-keyed before another storage array group based on which storage array group has a time span due to expire sooner.

8. The apparatus of claim 1 , wherein the re-keying manager is further configured to send an alert when a time to re-key a given storage array group is longer than a remainder of a given time span.

9. A method, comprising:

obtaining utilization information associated with a storage system based at least in part on system resources and performance data, wherein the storage system comprises a set of storage devices comprising a set of storage array groups, wherein each of the set of storage array groups has a cryptographic key for use, wherein the system resources and the performance data are utilized with a compliance limit set for each of the cryptographic keys for at least dynamically calculating a re-key order;

dynamically selecting a re-keying process from a plurality of different re-keying processes based on at least a portion of the obtained utilization information and the re-key order; and

re-keying at least a portion of the set of storage devices in accordance with the selected re-keying process;

wherein the obtaining, dynamic selecting and re-keying are performed by at least one processing device comprising a processor coupled to a memory.

10. The method of claim 9 , wherein the utilization information comprises a utilization percentage value associated with a cache of the storage system.

11. The method of claim 10 , wherein a first re-keying process of the plurality of different re-keying processes is selected when the cache utilization percentage value is below a given threshold value, and wherein a second re-keying process of the plurality of different re-keying processes is selected when the cache utilization percentage value is at or above the given threshold value.

12. The method of claim 11 , wherein the first re-keying process comprises a proactive sparing re-keying process, and the second re-keying process comprises a data in place re-keying process.

13. The method of claim 9 , wherein the utilization information comprises an input/output workload level.

14. The method of claim 13 , wherein a speed of the selected re-keying process is selected based on the input/output workload level.

15. The method of claim 9 , wherein the re-keying step is performed on a priority basis such that one storage array group is re-keyed before another storage array group based on which storage array group has a time span due to expire sooner.

16. The method of claim 9 , further comprising sending an alert when a time to re-key a given storage array group is longer than a remainder of a given time span.

17. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes said processing device to:

obtain utilization information associated with a storage system based at least in part on system resources and performance data, wherein the storage system comprises a set of storage devices comprising a set of storage array groups, wherein each of the set of storage array groups has a cryptographic key for use, wherein the system resources and the performance data are utilized with a compliance limit set for each of the cryptographic keys for at least dynamically calculating a re-key order;

dynamically select a re-keying process from a plurality of different re-keying processes based on at least a portion of the obtained utilization information and the re-key order; and

re-key at least a portion of the set of storage devices in accordance with the selected re-keying process.

18. The processor-readable storage medium of claim 17 , wherein the re-keying step is performed on a priority basis.

19. The processor-readable storage medium of claim 17 , wherein the utilization information comprises a utilization percentage value associated with a cache of the storage system.

20. The processor-readable storage medium of claim 17 , wherein the utilization information comprises an input/output workload level.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2019
From: TANG, XUAN; MEIRLAEN, MARION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 049364/0461 →
Continuity (1)
Related Publication 20200389305A1 · Dec 10, 2020