IP Library Granted Patent US 11,153,075
Granted Patent B2
US 11,153,075 · App. 16/737,704 · Granted Oct 19, 2021

Systems and methods for minimizing boot time when using a unique key encryption key per storage resource in secure enterprise key management provisioning

Inventors: Balaji B. Rao (Austin, TX); Chandrashekar Nelogal (Round Rock, TX); Swathi Prasad Neti (Georgetown, TX); Chandrashekara Lingaiah Nagaratna (Austin, TX); Divya Vijayvargiya (Cedar Park, TX); Diwahar Natarajan (Austin, TX)
Assignee: Dell Products L.P.
H04L9/0822G06F9/4401G06F21/602H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,075
App. No.
16/737,704
Granted
Oct 19, 2021
Kind
B2
Abstract

In accordance with embodiments of the present disclosure, a key management utility may be configured to, during boot of an information handling system, prioritize retrieval of key encryption keys of bootable storage resources of a plurality of storage resources over retrieval of key encryption keys of non-bootable storage resources of the plurality of storage resources and prioritize decryption of media encryption keys of bootable storage resources of the plurality of storage resources using their corresponding key encryption keys over decryption of media encryption keys of non-bootable storage resources of the plurality of storage resources using their corresponding key encryption keys.

Claims (36)

1. An information handling system comprising:

a processor;

a plurality of storage resources communicatively coupled to the processor, each storage resource having a media encryption key for encrypting data written to such storage resource and decrypted data read from such storage resource, wherein such media encryption key is encrypted by a corresponding key encryption key, such that a unique key encryption key exists for each of the plurality of storage resources;

a storage controller communicatively coupled to the processor and the plurality of storage resources and configured to manage one or more functions of the plurality of storage resources; and

a management controller communicatively coupled to the processor and configured to, during boot of the information handling system and in concert with the storage controller, prioritize retrieval of key encryption keys of bootable storage resources of the plurality of storage resources over retrieval of key encryption keys of non-bootable storage resources of the plurality of storage resources and prioritize decryption of media encryption keys of bootable storage resources of the plurality of storage resources using their corresponding key encryption keys over decryption of media encryption keys of non-bootable storage resources of the plurality of storage resources using their corresponding key encryption keys.

2. The information handling system of claim 1 , wherein the management controller is further configured to:

retrieve unique identifiers associated with the bootable storage resources; and

based on such unique identifiers, prioritize retrieval of key encryption keys of bootable storage resources over retrieval of key encryption keys of non-bootable storage resources.

3. The information handling system of claim 2 , wherein the management controller is configured to retrieve key encryption keys of the plurality of storage resources from a key management server communicatively coupled to the management controller via a network.

4. The information handling system of claim 2 , wherein the management controller is further configured to, based on such unique identifiers, prioritize transmission of key encryption keys of bootable storage resources to the storage controller over retrieval of key encryption keys of non-bootable storage resources.

5. The information handling system of claim 4 , wherein the storage controller is configured to prioritize decryption of media encryption keys of bootable storage resources over decryption of media encryption keys of non-bootable storage resources based on an order of receipt of key encryption keys from the management controller.

6. The information handling system of claim 2 , wherein the management controller is configured to retrieve the unique identifiers associated with the bootable storage resources from a boot list of unique identifiers created during factory provisioning of the information handling system.

7. The information handling system of claim 2 , wherein the management controller is configured to retrieve the unique identifiers associated with the bootable storage resources from a boot list of unique identifiers created during intended end use of the information handling system.

8. A management controller configured for management of an information handling system comprising a processor, a plurality of storage resources communicatively coupled to the processor, each storage resource having a media encryption key for encrypting data written to such storage resource and decrypted data read from such storage resource, wherein such media encryption key is encrypted by a corresponding key encryption key, such that a unique key encryption key exists for each of the plurality of storage resources, the management controller comprising:

a communication interface for communicatively coupling to a storage controller communicatively coupled to the processor and the plurality of storage resources and configured to manage one or more functions of the plurality of storage resources; and

a key management utility configured to, during boot of the information handling system and in concert with the storage controller, prioritize retrieval of key encryption keys of bootable storage resources of the plurality of storage resources over retrieval of key encryption keys of non-bootable storage resources of the plurality of storage resources and prioritize decryption of media encryption keys of bootable storage resources of the plurality of storage resources using their corresponding key encryption keys over decryption of media encryption keys of non-bootable storage resources of the plurality of storage resources using their corresponding key encryption keys.

9. The management controller of claim 8 , wherein the key management utility is further configured to:

retrieve unique identifiers associated with the bootable storage resources; and

based on such unique identifiers, prioritize retrieval of key encryption keys of bootable storage resources over retrieval of key encryption keys of non-bootable storage resources.

10. The management controller of claim 9 , wherein the key management utility is configured to retrieve key encryption keys of the plurality of storage resources from a key management server communicatively coupled to the management controller via a network.

11. The management controller of claim 9 , wherein the key management utility is further configured to, based on such unique identifiers, prioritize transmission of key encryption keys of bootable storage resources to the storage controller over retrieval of key encryption keys of non-bootable storage resources.

12. The management controller of claim 11 , wherein the storage controller is configured to prioritize decryption of media encryption keys of bootable storage resources over decryption of media encryption keys of non-bootable storage resources based on an order of receipt of key encryption keys from the management controller.

13. The management controller of claim 9 , wherein the key management utility is configured to retrieve the unique identifiers associated with the bootable storage resources from a boot list of unique identifiers created during factory provisioning of the information handling system.

14. The management controller of claim 9 , wherein the key management utility is configured to retrieve the unique identifiers associated with the bootable storage resources from a boot list of unique identifiers created during intended end use of the information handling system.

15. A method for use in an information handling system comprising a processor, and a plurality of storage resources communicatively coupled to the processor, each storage resource having a media encryption key for encrypting data written to such storage resource and decrypted data read from such storage resource, wherein such media encryption key is encrypted by a corresponding key encryption key, such that a unique key encryption key exists for each of the plurality of storage resources, the method comprising, during boot of the information handling system:

identifying bootable storage resources of the plurality of storage resources;

prioritizing retrieval of key encryption keys of bootable storage resources of the plurality of storage resources over retrieval of key encryption keys of non-bootable storage resources of the plurality of storage resources; and

prioritizing decryption of media encryption keys of bootable storage resources of the plurality of storage resources using their corresponding key encryption keys over decryption of media encryption keys of non-bootable storage resources of the plurality of storage resources using their corresponding key encryption keys.

16. The method of claim 15 , further comprising:

retrieving unique identifiers associated with the bootable storage resources in order to identify the bootable storage resources; and

based on such unique identifiers, prioritizing retrieval of key encryption keys of bootable storage resources over retrieval of key encryption keys of non-bootable storage resources.

17. The method of claim 16 , further comprising retrieving key encryption keys of the plurality of storage resources from a key management server communicatively coupled to the management controller via a network.

18. The method of claim 16 , further comprising, based on such unique identifiers, prioritizing transmission of key encryption keys of bootable storage resources to a storage controller for managing the plurality of storage resources over retrieval of key encryption keys of non-bootable storage resources.

19. The method of claim 18 , wherein the storage controller is configured to prioritize decryption of media encryption keys of bootable storage resources over decryption of media encryption keys of non-bootable storage resources based on an order of receipt of key encryption keys from the management controller.

20. The method of claim 16 , further comprising retrieving the unique identifiers associated with the bootable storage resources from a boot list of unique identifiers created during factory provisioning of the information handling system.

21. The method of claim 16 , further comprising retrieving the unique identifiers associated with the bootable storage resources from a boot list of unique identifiers created during intended end use of the information handling system.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052216/0758) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0680 →
RELEASE OF SECURITY INTEREST AF REEL 052243 FRAME 0773 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0152 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 26, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052243/0773 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 24, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052216/0758 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2020
From: RAO, BALAJI B.; NELOGAL, CHANDRASHEKAR; NETI, SWATHI PRASAD; NAGARATNA, CHANDRASHEKARA LINGAIAH; VIJAYVARGIYA, DIVYA; NATARAJAN, DIWAHAR
To: DELL PRODUCTS L.P.
Reel/Frame 051455/0749 →