IP Library Granted Patent US 11,496,284
Granted Patent B2
US 11,496,284 · App. 17/083,423 · Granted Nov 8, 2022

Detection of unauthorized encryption using key length evaluation

Inventors: Yevgeni Gehtman (Modi'In, IL); Maxim Balin (Gan Yavne, IL); Tomer Shachar (Omer, IL)
Assignee: EMC IP Holding Company LLC
H04L9/002G06F21/602H04L9/088
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,496,284
App. No.
17/083,423
Granted
Nov 8, 2022
Kind
B2
Abstract

Techniques are provided for detection of unauthorized encryption in a storage system using key length evaluation. One method comprises determining a key length of an encryption key used to encrypt data associated with one or more write commands in a storage system; evaluating the key length relative to an expected key length; and performing one or more automated remedial actions, such as generating an alert notification, in response to the key length being different than the expected key length. A count of a number of write operations in a given folder can be compared to a number of files in the given folder and an alert notification can be generated in response to the count of the number of write operations in the given folder having a same value as the number of files in the given folder.

Claims (35)

1. A method, comprising:

determining a key length of an encryption key used to encrypt data associated with one or more write commands in a storage system;

obtaining an expected encryption key length of at least one encryption process used to encrypt data in the storage system;

evaluating the key length relative to the expected encryption key length; and

performing one or more automated remedial actions in response to the key length being different than the expected encryption key length;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 , wherein the expected encryption key length is based at least in part on an expected encryption key length for an encryption in one or more of an operating system of the storage system, a network environment of the storage system and system configuration data of the storage system.

3. The method of claim 1 , wherein the determining the key length of the encryption key further comprises determining the key length of the encryption key used for an encryption by an operating system portion of the storage system and determining the key length of the encryption key for an encryption used by at least one additional portion of the storage system.

4. The method of claim 1 , further comprising comparing a count of a number of write operations in a given folder to a number of files in the given folder.

5. The method of claim 4 , wherein the comparing the count of the number of write operations is performed in response to the key length having a same value as the expected encryption key length.

6. The method of claim 4 , further comprising generating an alert notification in response to the count of the number of write operations in the given folder having a same value as the number of files in the given folder.

7. The method of claim 1 , wherein the one or more automated remedial actions comprise generating an alert notification in response to the key length being different than the expected encryption key length.

8. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured to implement the following steps:

determining a key length of an encryption key used to encrypt data associated with one or more write commands in a storage system;

obtaining an expected encryption key length of at least one encryption process used to encrypt data in the storage system;

evaluating the key length relative to the expected encryption key length; and

performing one or more automated remedial actions in response to the key length being different than the expected encryption key length.

9. The apparatus of claim 8 , wherein the expected encryption key length is based at least in part on an expected encryption key length for an encryption in one or more of an operating system of the storage system, a network environment of the storage system and system configuration data of the storage system.

10. The apparatus of claim 8 , wherein the determining the key length of the encryption key further comprises determining the key length of the encryption key used for an encryption by an operating system portion of the storage system and determining the key length of the encryption key for an encryption used by at least one additional portion of the storage system.

11. The apparatus of claim 8 , further comprising comparing a count of a number of write operations in a given folder to a number of files in the given folder.

12. The apparatus of claim 11 , wherein the comparing the count of the number of write operations is performed in response to the key length having a same value as the expected encryption key length.

13. The apparatus of claim 11 , further comprising generating an alert notification in response to the count of the number of write operations in the given folder having a same value as the number of files in the given folder.

14. The apparatus of claim 8 , wherein the one or more automated remedial actions comprise generating an alert notification in response to the key length being different than the expected encryption key length.

15. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:

determining a key length of an encryption key used to encrypt data associated with one or more write commands in a storage system;

obtaining an expected encryption key length of at least one encryption process used to encrypt data in the storage system;

evaluating the key length relative to the expected encryption key length; and

performing one or more automated remedial actions in response to the key length being different than the expected encryption key length.

16. The non-transitory processor-readable storage medium of claim 15 , wherein the expected encryption key length is based at least in part on an expected encryption key length for an encryption in one or more of an operating system of the storage system, a network environment of the storage system and system configuration data of the storage system.

17. The non-transitory processor-readable storage medium of claim 15 , wherein the determining the key length of the encryption key further comprises determining the key length of the encryption key used for an encryption by an operating system portion of the storage system and determining the key length of the encryption key for an encryption used by at least one additional portion of the storage system.

18. The non-transitory processor-readable storage medium of claim 15 , further comprising comparing a count of a number of write operations in a given folder to a number of files in the given folder and generating an alert notification in response to the count of the number of write operations in the given folder having a same value as the number of files in the given folder.

19. The non-transitory processor-readable storage medium of claim 18 , wherein the comparing the count of the number of write operations is performed in response to the key length having a same value as the expected encryption key length.

20. The non-transitory processor-readable storage medium of claim 15 , wherein the one or more automated remedial actions comprise generating an alert notification in response to the key length being different than the expected encryption key length.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2020
From: GEHTMAN, YEVGENI; BALIN, MAXIM; SHACHAR, TOMER
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 054207/0066 →