IP Library Granted Patent US 11,893,126
Granted Patent B2
US 11,893,126 · App. 16/601,329 · Granted Feb 6, 2024

Data deletion for a multi-tenant environment

Inventors: Andrew Miller (Greenville, SC); Reena Gupta (Sunnyvale, CA)
Assignee: PURE STORAGE, INC.
G06F21/6227G06F12/0253H04L9/0891H04L9/0894G06F2212/1044G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,893,126
App. No.
16/601,329
Granted
Feb 6, 2024
Kind
B2
Abstract

A method of secure data deletion in a multitenant environment, performed by a storage system is provided. The method includes associating a key with a tenant, in the multitenant environment, as a result of the storage system receiving data from the tenant through a virtual local area network (VLAN) or from an Internet protocol (IP) address. The method includes storing the data, encrypted by the key, in the storage system, and determining that the key, as retained in the storage system, is to be deleted, so that the data is to be inaccessible in unencrypted form, responsive to a request from the tenant to delete the data.

Claims (62)

1. A method, comprising:

associating a key with a tenant, in a multitenant environment, as a result of a storage system receiving data from the tenant through a network;

storing the data, encrypted by the key, in the storage system;

receiving, from the tenant, a request to delete the data; and

in response to receiving the request:

initiating deletion of the data by starting a timer for a data recoverability time span;

determining that the key, as retained in the storage system, is to be deleted, so that the data is to be inaccessible in unencrypted form;

deleting the key, after the data recoverability time span; and

delaying garbage collection of the encrypted data for an amount of time after the data recoverability time span.

2. The method of claim 1 wherein the associating the key with the tenant comprises:

tagging the key with a tenant tag.

3. The method of claim 1 further comprising:

canceling a direction to delete the key, responsive to a request from the tenant to cancel deleting the data.

4. The method of claim 1 further comprising:

excluding the encrypted data from garbage collection, during a data recoverability time span.

5. The method of claim 1 further comprising:

exporting the key to the tenant, responsive to the request from the tenant to delete the data and importing the key from the tenant, responsive to a request to cancel deletion of the data.

6. The method of claim 1 further comprising:

exporting the key to the tenant, responsive to the request from the tenant to delete the data while retaining the key in the storage system, as a master key for approval and delaying deletion of the key during a data recoverability time span to support access by the tenant to the data, with approval by the master key, responsive to the tenant returning the exported key.

7. A tangible, non-transitory, computer-readable media having instructions thereupon which, when executed by a processor, cause the processor to perform a method comprising:

associating a key with a tenant, in a multitenant environment, as a result of a storage system receiving data from the tenant through a network, which the storage system recognizes as associated with the tenant;

encrypting the data with the key;

storing the encrypted data in the storage system;

retaining the key associated with the tenant, in the storage system, so that the key is not available external to the storage system while so retained;

receiving, from the tenant, a request to delete the data; and

in response to receiving the request:

initiating deletion of the data by starting a timer for a data recoverability time span;

determining that the key, as retained in the storage system is to be deleted, so that the data is to be inaccessible in unencrypted form;

deleting the key, after the data recoverability time span; and

delaying garbage collection of the encrypted data for an amount of time after the data recoverability time span.

8. The tangible, non-transitory, computer-readable media of claim 7 , wherein the method further comprises:

generating the key and tagging the key with a tenant tag for the associating the key with the tenant.

9. The tangible, non-transitory, computer-readable media of claim 7 , wherein the method further comprises:

canceling a direction to delete the key, responsive to a request from the tenant to cancel deleting the data, so that the key continues to be retained in the storage system.

10. The tangible, non-transitory, computer-readable media of claim 7 , wherein the method further comprises:

excluding the encrypted data that is tagged with the tenant tag from garbage collection, during an agreed-upon data recoverability time span that starts with the request from the tenant to delete the data, wherein the associating the key with the tenant comprises tagging the key with the tenant tag.

11. The tangible, non-transitory, computer-readable media of claim 7 , wherein the method further comprises:

exporting the key to the tenant, responsive to the request from the tenant to delete the data while retaining the encrypted data in the storage system to allow importing the key from the tenant to the storage system, responsive to a request by the tenant, within an agreed-upon data recoverability time span that starts with the request from the tenant to delete the data, to cancel deletion of the data.

12. The tangible, non-transitory, computer-readable media of claim 7 , wherein the method further comprises:

exporting the key to the tenant, responsive to the request from the tenant to delete the data while retaining the key in the storage system, as a master key for approval and delaying deletion of the key during an agreed-upon data recoverability time span that starts with the request from the tenant to delete the data to support access by the tenant to the data, using the key that was exported, with approval by the master key, responsive to a request by the tenant within the data recoverability time span to undelete the data, accompanied by the tenant returning the exported key to the storage system.

13. A storage system, comprising:

storage memory;

a communication interface; and

one or more processors, to:

encrypt data with a key;

tag the key with a tenant tag, to associate the key to a tenant in a multitenant environment, as a result of the storage system receiving the data from the tenant through the communication interface from a network and recognizing association with the data and the tenant;

store the encrypted data in the storage memory;

retain the key associated with the tenant, in the storage system, so that the key is not available external to the storage system while so retained; and receive, from the tenant, a request to delete the data;

in response to receiving the request:

initiate deletion of the data by starting a timer for a data recoverability time span;

determine that the key, as retained in the storage system is to be deleted, so that the data is to be inaccessible in unencrypted form;

deleting the key, after the data recoverability time span; and

delaying garbage collection of the encrypted data for an amount of time after the data recoverability time span.

14. The storage system of claim 13 , further comprising the one or more processors to:

cancel a direction to delete the key, responsive to receiving a request from the tenant to cancel deleting the data, so that the key continues to be retained in the storage system.

15. The storage system of claim 13 , further comprising the one or more processors to:

exclude the encrypted data that is tagged with the tenant tag from garbage collection, during an agreed-upon data recoverability time span that starts with the receiving the request from the tenant to delete the data, wherein the associating the key with the tenant comprises tagging the key with the tenant tag.

16. The storage system having secure data deletion in a multitenant environment of claim 13 , further comprising the one or more processors to:

export the key to the tenant, responsive to the request from the tenant to delete the data

to retain the encrypted data in the storage system and import the key from the tenant to the storage system, responsive to receiving a request to cancel deletion of the data.

17. The storage system having secure data deletion in a multitenant environment of claim 13 , further comprising the one or more processors to:

export the key to the tenant, responsive to the request from the tenant to delete the data while retaining the key in the storage system, as a master key for approval; and delay deletion of the key during an agreed-upon data recoverability time span that starts with the request from the tenant to delete the data to support access by the tenant to the data, using the key that was exported, with approval by the master key, responsive to receiving a request from the tenant within the data recoverability time span to undelete the data, with the tenant returning the exported key to the storage system.

Assignments (4)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2019
From: PARK, SANG MOK; LEE, JI EUN; BAN, SUNG HO; LEE, YOON SUNG
To: HYUNDAI MOTOR COMPANY; KIA MOTORS CORPORATION
Reel/Frame 051088/0847 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2019
From: MILLER, ANDREW; GUPTA, REENA
To: PURE STORAGE, INC.
Reel/Frame 050768/0801 →
Continuity (1)
Related Publication 20210110055A1 · Apr 15, 2021