IP Library Granted Patent US 11,509,458
Granted Patent B2
US 11,509,458 · App. 16/931,582 · Granted Nov 22, 2022

Method and system for securely replicating encrypted deduplicated storages

Inventors: Jehuda Shemer (Kfar Saba, IL); Assaf Natanzon (Tel Aviv, IL)
Assignee: EMC IP HOLDING COMPANY LLC
H04L9/0825G06F16/27H04L9/083H04L9/14H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,458
App. No.
16/931,582
Granted
Nov 22, 2022
Kind
B2
Abstract

A method and system for securely replicating encrypted deduplicated storages. Specifically, the method and system disclosed herein entail the replication and migration of encrypted data between storage systems that support deduplication. More specifically, a first encrypted data, which may have been encrypted using a first public cryptographic key and consolidated on a source storage system, may be translated into an interim (yet still encrypted) state using a first split private cryptographic key. Thereafter, using a compound conversion key, the interim state data may be further translated into a second encrypted data, which may be characterized as being encrypted by a second public cryptographic key. Therefore, substantively, the method and system disclosed herein may be directed to the translation of encrypted data from one encryption scheme to another while in-flight from a source storage system to a target storage system.

Claims (60)

1. A method for provisioning cryptographic keys to facilitate encrypted data replication across storage systems, comprising:

receiving a first key provision request comprising a source storage identifier (SSID) and a target storage identifier (TSID);

in response to receiving the first key provision request:

generating a target-source private key compatible with a host-source public key;

splitting the target-source private key into a source entrusted target-source split private key and a target entrusted target-source split private key;

providing the source entrusted target-source split private key to a source storage system associated with the SSID;

combining the target entrusted target-source split private key and a host-target public key to obtain a target entrusted compound conversion key; and

providing the target entrusted compound conversion key to a target storage system associated with the TSID.

2. The method of claim 1 , wherein the host-source public key is associated with the SSID.

3. The method of claim 1 , wherein the target entrusted compound conversion key is used to translate interim state host data (ISHD) migrated from the source storage system into host-target encrypted host data (EHD) to be stored on the target storage system during an encrypted data replication operation.

4. The method of claim 3 , wherein the source entrusted target-source split private key is used to translate host-source EHD stored on the source storage system into the ISHD to be migrated to the target storage system during the encrypted data replication operation.

5. The method of claim 1 , wherein the first key provision request further comprises a host identifier.

6. The method of claim 5 , further comprising:

prior to receiving the first key provision request:

receiving a second key provision request comprising the SSID and the host identifier;

in response to receiving the second key provision request:

generating the host-source public key;

generating a host-source private key compatible with the host-source public key;

splitting the host-source private key into a host entrusted host-source split private key and a source entrusted host-source split private key;

providing the host-source public key and the host entrusted host-source split private key to a host associated with the host identifier; and

providing the source entrusted host-source split private key to the source storage system associated with the SSID.

7. The method of claim 6 , wherein the host-source public key is used to translate plain host data (PHD) stored on the host into host-source encrypted host data (EHD) to be migrated to the source storage system during an encrypted data backup operation prior to a failure event.

8. The method of claim 7 , wherein the source entrusted host-source split private key is used to translate the host-source EHD stored on the source storage system into interim state host data (ISHD) to be migrated to the host during an encrypted data recovery operation after the failure event.

9. The method of claim 8 , wherein the host entrusted host-source split private key is used to translate the ISHD migrated from the source storage system into the PHD to be recovered on the host during the encrypted data recovery operation after the failure event.

10. The method of claim 5 , further comprising:

after providing the target entrusted compound conversion key to the target storage system:

generating a host-target private key compatible with the host-target public key;

splitting the host-target private key into a host entrusted host-target split private key and a target entrusted host-target split private key;

providing the target entrusted host-target split private key to the target storage system; and

providing the host-target public key and the host entrusted host-target split private key to a host associated with the host identifier.

11. A non-transitory computer readable medium (CRM) comprising computer readable program code, which when executed by a computer processor, enables the computer processor to:

receive a first key provision request comprising a source storage identifier (SSID) and a target storage identifier (TSID);

in response to receiving the first key provision request:

generate a target-source private key compatible with a host-source public key;

split the target-source private key into a source entrusted target-source split private key and a target entrusted target-source split private key;

provide the source entrusted target-source split private key to a source storage system associated with the SSID;

combine the target entrusted target-source split private key and a host-target public key to obtain a target entrusted compound conversion key; and

provide the target entrusted compound conversion key to a target storage system associated with the TSID.

12. The non-transitory CRM of claim 11 , wherein the host-source public key is associated with the SSID.

13. The non-transitory CRM of claim 11 , wherein the target entrusted compound conversion key is used to translate interim state host data (ISHD) migrated from the source storage system into host-target encrypted host data (EHD) to be stored on the target storage system during an encrypted data replication operation.

14. The non-transitory CRM of claim 13 , wherein the source entrusted target-source split private key is used to translate host-source EHD stored on the source storage system into the ISHD to be migrated to the target storage system during the encrypted data replication operation.

15. The non-transitory CRM of claim 11 , wherein the first key provision request further comprises a host identifier.

16. The non-transitory CRM of claim 15 , comprising additional computer readable program code, which when executed by the computer processor, further enables the computer processor to:

prior to receiving the first key provision request:

receive a second key provision request comprising the SSID and the host identifier;

in response to receiving the second key provision request:

generate the host-source public key;

generate a host-source private key compatible with the host-source public key;

split the host-source private key into a host entrusted host-source split private key and a source entrusted host-source split private key;

provide the host-source public key and the host entrusted host-source split private key to a host associated with the host identifier; and

provide the source entrusted host-source split private key to the source storage system associated with the SSID.

17. The non-transitory CRM of claim 16 , wherein the host-source public key is used to translate plain host data (PHD) stored on the host into host-source encrypted host data (EHD) to be migrated to the source storage system during an encrypted data backup operation prior to a failure event.

18. The non-transitory CRM of claim 17 , wherein the source entrusted host-source split private key is used to translate the host-source EHD stored on the source storage system into interim state host data (ISHD) to be migrated to the host during an encrypted data recovery operation after the failure event.

19. The non-transitory CRM of claim 18 , wherein the host entrusted host-source split private key is used to translate the ISHD migrated from the source storage system into the PHD to be recovered on the host during the encrypted data recovery operation after the failure event.

20. The non-transitory CRM of claim 15 , comprising additional computer readable program code, which when executed by the computer processor, further enables the computer processor to:

after providing the target entrusted compound conversion key to the target storage system:

generate a host-target private key compatible with the host-target public key;

split the host-target private key into a host entrusted host-target split private key and a target entrusted host-target split private key;

provide the target entrusted host-target split private key to the target storage system; and

provide the host-target public key and the host entrusted host-target split private key to a host associated with the host identifier.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053574/0221) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060333/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053578/0183) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060332/0864 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053573/0535) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060333/0106 →
RELEASE OF SECURITY INTEREST AT REEL 053531 FRAME 0108 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0371 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053578/0183 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053573/0535 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053574/0221 →
SECURITY AGREEMENT Recorded Aug 18, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 053531/0108 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2020
From: SHEMER, JEHUDA; NATANZON, ASSAF
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 053508/0797 →