IP Library Granted Patent US 12,093,402
Granted Patent B2
US 12,093,402 · App. 16/937,958 · Granted Sep 17, 2024

Replicating data to a storage system that has an inferred trust relationship with a client

Inventors: Ronald Karr (Palo Alto, CA); Constantine Sapuntzakis (Mountain View, CA); John Colgrove (Los Altos, CA)
Assignee: PURE STORAGE, INC.
G06F21/602G06F3/0604G06F3/0619G06F3/0622G06F3/0623G06F3/065G06F3/0659G06F3/067G06F3/0673G06F11/1453G06F11/1464G06F16/164G06F16/1748G06F16/1824G06F21/6218H04L9/0816H04L9/14H04L67/1097G06F21/107H04L2209/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,093,402
App. No.
16/937,958
Granted
Sep 17, 2024
Kind
B2
Abstract

Replicating data using inferred trust, including: receiving, by a first storage system from a computing device, data encrypted using a first encryption key; decrypting, by the first storage system, the encrypted data using the first encryption key; encrypting, by the first storage system, the decrypted data using a second encryption key; storing, on the first storage system, the data encrypted using the second encryption key; sending, from the first storage system to the second storage system, the data; and servicing, by the second storage system, an input/output (‘I/O’) operation directed to the data.

Claims (42)

1. A method comprising:

receiving, by a first storage system from a client computing device, data encrypted using a first encryption key;

storing, on the first storage system, the data encrypted using a second encryption key;

receiving an indication that a second storage system has access to the first encryption key;

determining, by the first storage system, that a trust relationship exists between the client computing device and the second storage system based on the indication that the second storage system has access to the first encryption key, wherein the trust relationship indicates that the second storage system is trusted to decrypt information encrypted by the client computing device using the first encryption key; and

based on the determination that the trust relationship exists, sending, from the first storage system to the second storage system, the data, wherein sending the data causes the second storage system to service an input/output (‘I/O’) operation directed to the data and wherein the data sent from the first storage system to the second storage system is unencrypted in response to receiving a signed certificate from a key server authorizing the second storage system.

2. The method of claim 1 , further comprising determining, by the first storage system, that the second storage system has access to the first encryption key.

3. The method of claim 1 , wherein the data sent from the first storage system to the second storage system is encrypted using the second encryption key.

4. The method of claim 1 , wherein the data stored on the second storage system is encrypted using a third encryption key.

5. The method of claim 1 , wherein the second storage system is to send the data encrypted using the first encryption key to the client computing device.

6. The method of claim 1 , further comprising:

decrypting, by the first storage system, the encrypted data using the first encryption key; and

encrypting, by the first storage system, the decrypted data using the second encryption key.

7. A first storage system comprising:

a memory; and

a processing device, operatively coupled to the memory, configured to:

receive, by the first storage system from a client computing device, data encrypted using a first encryption key;

store, on the first storage system, the data encrypted using a second encryption key;

receive an indication that a second storage system has access to the first encryption key;

determine that a trust relationship exists between the client computing device and a second storage system based on the indication that the second storage system has access to the first encryption key, wherein the trust relationship indicates that the second storage system is trusted to decrypt information encrypted by the client computing device using the first encryption key; and

based on the determination that the trust relationship exists, send, from the first storage system to the second storage system, the data, wherein sending the data causes the second storage system to service an input/output (‘I/O’) operation directed to the data and wherein the data sent from the first storage system to the second storage system is unencrypted in response to receiving a signed certificate from a key server authorizing the second storage system.

8. The first storage system of claim 7 , wherein the processing device is further configured to:

determine, by the first storage system, that the second storage system has access to the first encryption key.

9. The first storage system of claim 7 , wherein the data sent from the first storage system to the second storage system is encrypted using the second encryption key.

10. The first storage system of claim 7 , wherein the data stored on the second storage system is encrypted using a third encryption key.

11. The first storage system of claim 7 , wherein the second storage system is to send the data encrypted using the first encryption key to the client computing device.

12. The first storage system of claim 7 , wherein the processing device is further configured to:

decrypt, by the first storage system, the encrypted data using the first encryption key; and

encrypt, by the first storage system, the decrypted data using the second encryption key.

13. A non-transitory computer readable storage medium storing instructions which, when executed, cause a processing device to:

receive, by a first storage system from a client computing device, data encrypted using a first encryption key;

store, on the first storage system, the data encrypted using a second encryption key;

receive an indication that a second storage system has access to the first encryption key;

determine, by the first storage system, that a trust relationship exists between the client computing device and a second storage system based on the indication that the second storage system has access to the first encryption key, wherein the trust relationship indicates that the second storage system is trusted to decrypt information encrypted by the client computing device using the first encryption key; and

based on the determination that the trust relationship exists, send, from the first storage system to the second storage system, the data, wherein sending the data causes the second storage system to service an input/output (‘I/O’) operation directed to the data and wherein the data sent from the first storage system to the second storage system is unencrypted in response to receiving a signed certificate from a key server authorizing the second storage system.

14. The non-transitory computer readable storage medium of claim 13 , wherein the processing device is further to:

determine that the second storage system has access to the first encryption key.

15. The non-transitory computer readable storage medium of claim 13 , wherein the data sent from the first storage system to the second storage system is encrypted using the second encryption key.

16. The non-transitory computer readable storage medium of claim 13 , wherein the second storage system is to send the data encrypted using the first encryption key to the client computing device.

17. The non-transitory computer readable storage medium of claim 13 , wherein the processing device is further to:

decrypt the encrypted data using the first encryption key; and

encrypt the decrypted data using the second encryption key.

Assignments (3)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2020
From: KARR, RONALD; SAPUNTZAKIS, CONSTANTINE; COLGROVE, JOHN
To: PURE STORAGE, INC.
Reel/Frame 053302/0918 →
Continuity (2)
Provisional Application 62944617 · Dec 6, 2019
Related Publication 20210173945A1 · Jun 10, 2021