IP Library Granted Patent US 12,407,495
Granted Patent B2
US 12,407,495 · App. 17/019,764 · Granted Sep 2, 2025

Encryption keys from storage systems

Inventors: Christopher Anthony Grant Hillier (Ft. Collins, CO); Curtis C. Ballard (Eaton, CO)
Assignee: Hewlett Packard Enterprise Development LP
H04L9/0825H04L9/083H04L9/0866H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,495
App. No.
17/019,764
Granted
Sep 2, 2025
Kind
B2
Abstract

In some examples, a storage system includes a controller to receive a request for a data encryption key from the host system, in response to the request, retrieve, from a key manager system, the data encryption key for the host system, and encrypt the data encryption key retrieved from the key manager system using a first key, to produce an encrypted data encryption key. The controller sends the encrypted data encryption key to the host system, and receives, from the host system, encrypted data encrypted using the data encryption key.

Claims (46)

1. A storage system comprising:

a communication interface to communicate with a host system that is able to access data stored by the storage system; and

a controller to:

receive a request for a data encryption key from the host system over a network, the request comprising an identifier of the host system or an identifier of a storage object to be accessed;

in response to the request, retrieve, from a key manager system, the data encryption key for the host system, wherein the controller is to retrieve the data encryption key for the host system from the key manager system by sending, to the key manager system, a request including a key identifier that is based on the identifier of the host system or the identifier of the storage object to be accessed, and wherein the storage system is separate from each of the host system and the key manager system;

encrypt the data encryption key retrieved from the key manager system using a first key, to produce an encrypted data encryption key;

send the encrypted data encryption key to the host system; and

receive, from the host system, encrypted data encrypted using the data encryption key.

2. The storage system of claim 1 , wherein the encrypted data encryption key is sent to a network interface controller or a storage driver of the host system, and wherein the encrypted data received from the host system is encrypted by the network interface controller or the storage driver using the data encryption key.

3. The storage system of claim 1 , wherein the controller is to translate the identifier of the host system to the key identifier included in the request sent to the key manager system.

4. The storage system of claim 1 , wherein the controller is to translate the identifier of the storage object to the key identifier included in the request sent to the key manager system.

5. The storage system of claim 1 , wherein the controller is to look up the key identifier included in the request sent to the key manager system from the identifier of the host system or the identifier of the storage object.

6. The storage system of claim 1 , wherein the first key is from the host system and is a public key of the host system.

7. The storage system of claim 6 , wherein the encrypted data is encrypted using the data encryption key determined by the host system from the encrypted data encryption key by decrypting the encrypted data encryption key using a private key of the host system.

8. The storage system of claim 1 , wherein the data encryption key retrieved by the storage system from the key manager system is obtained by the key manager system by accessing a key repository that correlates key identifiers to corresponding data encryption keys, wherein the key identifier included in the request from the storage system to the key manager system correlates to the data encryption key in the key repository.

9. The storage system of claim 1 , wherein the controller is to:

receive, from the host system, information associated with the data encryption key as part of an access of data by the host system; and

decrypt encrypted data associated with a data service of the storage system in response to receiving the information associated with the data encryption key.

10. The storage system of claim 9 , wherein the information associated with the data encryption key comprises the key identifier of the data encryption key.

11. The storage system of claim 10 , wherein the controller does not decrypt the encrypted data associated with the data service if the host system does not provide the information associated with the data encryption key as part of the access of data by the host system.

12. The storage system of claim 9 , wherein the information associated with the data encryption key comprises the identifier of the host system.

13. The storage system of claim 1 , wherein the controller is to manage access of the data encryption key responsive to the request for the data encryption key based on whether the host system is authorized.

14. A method of a storage system comprising a hardware processor, comprising:

receiving, at the storage system, a first key from a host system;

receiving, at the storage system, a request for a data encryption key from the host system, the request comprising an identifier of the host system or an identifier of a storage object to be accessed by the host system;

in response to the request, sending, from the storage system over a network to a key manager system, a key identifier for the data encryption key, the key identifier being based on the identifier of the host system or the identifier of the storage object to be accessed, wherein the storage system is separate from each of the host system and the key manager system;

receiving, at the storage system over the network from the key manager system, the data encryption key obtained by the key manager system by accessing a key repository that correlates key identifiers to corresponding data encryption keys, wherein the key identifier sent from the storage system to the key manager system correlates to the data encryption key in the key repository;

encrypting, at the storage system, the data encryption key using the first key, to produce an encrypted data encryption key;

sending the encrypted data encryption key from the storage system to the host system; and

receiving, at the storage system from the host system, encrypted data encrypted using the data encryption key derived by the host system based on decrypting the encrypted data encryption key.

15. The method of claim 14 , wherein the first key is a public key.

16. The method of claim 15 , wherein the encrypted data is encrypted using the data encryption key derived by the host system based on decrypting the encrypted data encryption key with a private key.

17. The method of claim 14 , further comprising:

receiving, from the host system, information associated with the data encryption key as part of an access of data by the host system; and

decrypting, by the storage system, encrypted data associated with a data service of the storage system in response to receiving the information associated with the data encryption key.

18. A non-transitory machine-readable storage medium comprising instructions that upon execution cause a storage system to:

receive a public key from a host system;

receive, at the storage system, a request for a data encryption key from the host system, the request comprising an identifier of the host system or an identifier of a storage object to be accessed by the host system;

in response to the request, send, from the storage system over a network to a key manager system, a key identifier for the data encryption key, the key identifier being based on the identifier of the host system or the identifier of the storage object to be accessed by the storage system, wherein the storage system is separate from each of the host system and the key manager system;

receive, at the storage system over the network from the key manager system, the data encryption key obtained by the key manager system by accessing a key repository that correlates key identifiers to corresponding data encryption keys, wherein the key identifier sent from the storage system to the key manager system correlates to the data encryption key in the key repository;

encrypt the data encryption key using the public key, to produce an encrypted data encryption key;

send, from the storage system, the encrypted data encryption key to the host system;

receive, from the host system, encrypted data encrypted using the data encryption key derived by the host system based on decrypting the encrypted data encryption key using a private key of the host system; and

store the encrypted data in a storage medium of the storage system.

19. The non-transitory machine-readable storage medium of claim 18 , wherein the instructions upon execution cause the storage system to:

manage access of the data encryption key responsive to the request for the data encryption key based on whether the host system is authorized.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2020
From: HILLIER, CHRISTOPHER ANTHONY GRANT; BALLARD, CURTIS C.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 053759/0982 →
Continuity (1)
Related Publication 20220085983A1 · Mar 17, 2022
References Cited (52)
US 6708272B1 · McCown · 2004 [cited by examiner]
US 8295490B1 · McCoy · 2012 [cited by examiner]
US 8417967B2 · Foster et al. · 2013 [cited by applicant]
US 9031233B2 · Kang · 2015 [cited by examiner]
US 9830278B1 · Harwood · 2017 [cited by examiner]
US 9954678B2 · Mosko · 2018 [cited by examiner]
US 9973481B1 · Sharifi Mehr · 2018 [cited by examiner]
US 10372926B1 · Leshinsky · 2019 [cited by examiner]
US 10402573B1 · Galligan · 2019 [cited by examiner]
US 10963593B1 · Campagna · 2021 [cited by examiner]
US 20030041221A1 · Okada et al. · 2003 [cited by applicant]
US 20050089165A1 · Kitani et al. · 2005 [cited by applicant]
US 20050091491A1 · Lee · 2005 [cited by examiner]
US 20060050870A1 · Kimmel · 2006 [cited by examiner]
US 20080260159A1 · Osaki · 2008 [cited by examiner]
US 20080294894A1 · Dubhashi · 2008 [cited by examiner]
US 20090067633A1 · Dawson · 2009 [cited by examiner]
US 20130227303A1 · Kadatch · 2013 [cited by examiner]
US 20140310536A1 · Shacham · 2014 [cited by applicant]
US 20180225179A1 · Donaghy et al. · 2018 [cited by applicant]
US 20190097791A1 · Hersans · 2019 [cited by examiner]
US 20190296896A1 · Resch · 2019 [cited by examiner]
US 20200067699A1 · Resch · 2020 [cited by examiner]
US 20200076580A1 · Driever · 2020 [cited by examiner]
US 20200076585A1 · Sheppard · 2020 [cited by examiner]
US 20210036851A1 · Villapakkam · 2021 [cited by examiner]
US 20210184840A1 · Yeo · 2021 [cited by examiner]
US 20210334416A1 · Jung · 2021 [cited by examiner]
US 20220069983A1 · Yoshida · 2022 [cited by examiner]
US 20240171381A1 · Shveykin · 2024 [cited by examiner]
Amazon Web Services, Inc., “Protecting data using encryption,” retrieved Aug. 19, 2020, Amazon Simple Storage Service, Developer Guide, API Version Mar. 1, 2006, pp. 279-313. [cited by applicant]
Amazon Web Services, Inc., “Security in Amazon EFS,” retrieved Aug. 19, 2020, Amazon Elastic File System, User Guide, pp. 140-144. [cited by applicant]
Amazon; “How Amazon Elastic Block Store (Amazon EBS) Uses AWS KMS”; 4 pages printed on Oct. 22, 2019 from webpage: https://docs.aws.amazon.com/kms/latest/developerguide/services-ebs.html. [cited by applicant]
Canonical Ltd., “nvme-security-recv—Security Recv command,” Ubuntu Manpage, <http://manpages.ubuntu.com/manpages/xenial/man1/nvme-security-recv.1.html>, Retrieved Aug. 27, 2020 (3 pages). [cited by applicant]
Gemalto, Product Brief, SafeNet KeySecure™ downloaded Jul. 28, 2020 (2 pages). [cited by applicant]
HP Enterprise Secure Key Manager 4.0, Datasheet, Manage business-critical encryption keys for OASIS KMIP clients, Feb. 2014 (4 pages). [cited by applicant]
IBM Research Lab in Haifa, “Capability based Command Security,” Feb. 2007, SCSI commands standard proposal, 07-069r1, pp. i-iii and 1-46. [cited by applicant]
Jim Hatfield, “Assignments for Trusted Computing Group,” Feb. 22, 2006, e05139r7, <http://www.t13.org/documents/UploadedDocuments/docs2006/e05139r7-ACS-TrustedComputingCommands.pdf> (13 pages). [cited by applicant]
Systutorials, “nvme-security-send (1)—Linux Man Pages,” retrieved Aug. 27, 2020, <http://manpages.ubuntu.com/manpages/xenial/man1/nvme-security-recv.1.html> (2 pages). [cited by applicant]
Trusted Computing Group, Incorporated, “TCG Storage Interface Interactions Specification (SIIS),” Specification Version 1.08, Revision 1.00, Oct. 26, 2018, pp. i-vii and 1-51. [cited by applicant]
Amazon Web Services, “Protecting data using client-side encryption,” Aug. 8, 2020, <http://web.archive.org/web/20200808162333/http://docs.aws.amazon.com/AmazonS3/latest/dev/UsingClientSideEncryption.html>, 5 pages. [cited by applicant]
Chalmers et al., “What exactly is client-side encryption?,” 2017, Stack Exchange, <https://security.stackexchange.com/questions/176376/what-exactly-is-client-side-encryption>, 3 pages. [cited by applicant]
Hewlett Packard Enterprise Development LP, “Encryption technology for HPE StoreEver LTO Ultrium Tape Drives,” Dec. 2015, Rev. 1, <https://www.tapetember.com/portals/0/tapetember/lto-7/4aa5-2801enw.pdf>, 19 pages. [cited by applicant]
NVM Express Workgroup, “NVM Express™: Base Specification,” Revision 1.4, Jun. 10, 2019, <https://nvmexpress.org/wp-content/uploads/NVM-Express-1_4-2019.06.10-Ratified.pdf>, 403 pages. [cited by applicant]
Scott Schweitzer, “Why is a SmartNIC Better than a Regular NIC?,” Jun. 30, 2020, Electronic Design, <https://www.electronicdesign.com/markets/automation/article/21134459/xilinx-why-is-a-smartnic-better-than-a-regular-ni… [cited by applicant]
Seagate Technology LLC, “SCSI Commands Reference Manual,” Oct. 2016, 100293068, Rev. J, <https://www.seagate.com/files/staticfiles/support/docs/manual/Interface%20manuals/100293068j.pdf>. 518 pages. [cited by applicant]
Wikipedia, “Capability-based security,” Aug. 16, 2020, <https://en.wikipedia.org/w/index.php?title=Capability-based_security&oldid=973273333>, 5 pages. [cited by applicant]
Wikipedia, “Data Encryption Standard,” Aug. 28, 2020, <https://en.wikipedia.org/w/index.php?title=Data_Encryption_Standard&oldid=975385193>, 16 pages. [cited by applicant]
Wikipedia, “IPsec,” Aug. 31, 2020, <https://en.wikipedia.org/w/index.php?title=IPsec&oldid=975901389>, 8 pages. [cited by applicant]
Wikipedia, “Key Management Interoperability Protocol,” Feb. 10, 2020, <https://en.wikipedia.org/w/index.php?title=Key_Management_Interoperability_Protocol&oldid=940121133>. 5 pages. [cited by applicant]
Wikipedia, “RSA (cryptosystem),” Aug. 19, 2020, <https://en.wikipedia.org/w/index.php?title=RSA_(cryptosystem) &oldid=973884875>, 18 pages. [cited by applicant]
Wikipedia, “Trusted Platform Module,” Aug. 31, 2020, <https://en.wikipedia.org/w/index.php?title=Trusted_Platform_Module&oldid=975959444>. 13 pages. [cited by applicant]