IP Library Granted Patent US 11,677,551
Granted Patent B2
US 11,677,551 · App. 17/085,506 · Granted Jun 13, 2023

Encryption at rest using KMS and TPM

Inventors: Senthil Ponnuswamy (San Jose, CA); Kalidas Balakrishnan (San Jose, CA); Mahadev Karadigudda (San Jose, CA)
Assignee: EMC IP HOLDING COMPANY LLC
H04L9/0877G06F21/602H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,677,551
App. No.
17/085,506
Granted
Jun 13, 2023
Kind
B2
Abstract

One example method includes receiving clear text data at a storage system, generating, at the storage system, a clear text data encryption key, requesting a key management system to encrypt the clear text data encryption key with a master key to create an encrypted data encryption key, and the requesting is performed by the storage system, receiving, at the storage system, the encrypted data encryption key from the key management system, encrypting, at the storage system, the clear text data with the clear text data encryption key to create encrypted data, and storing, together, the encrypted data and the encrypted data encryption key.

Claims (38)

1. A method, comprising:

receiving clear text data at a storage system;

generating, at the storage system, which is separate from a key management system, a plain text data encryption key;

sending, by the storage system, the plain text data encryption key to the key management system to enable the key management system to encrypt the plain text data encryption key with a master key, wherein the master key is located in the key management system, to create an encrypted data encryption key;

receiving, at the storage system, the encrypted data encryption key from the key management system;

encrypting, at the storage system, the clear text data with the encrypted data encryption key to create encrypted data; and

storing, together, the encrypted data and the encrypted data encryption key in the storage system.

2. The method as recited in claim 1 , wherein the master key is an unexportable key that is stored only at the key management system and not at the storage system.

3. The method as recited in claim 1 , further comprising using a Trusted Platform Module (TPM) chip to wrap the encrypted data encryption key received from the key management system to create a TPM wrapped key.

4. The method as recited in claim 3 , further comprising storing the TPM wrapped key in a key table at the storage system.

5. The method as recited in claim 1 , further comprising receiving a read request at the storage system and, in response to receipt of the read request, reading out, at the storage system, the encrypted data and the encrypted data encryption key.

6. The method as recited in claim 5 , further comprising obtaining the plain text data encryption key which was used to create the encrypted data encryption key, and decrypting the encrypted data with the plain text data encryption key.

7. The method as recited in claim 6 , wherein obtaining the plain text data encryption key comprises one of:

obtaining, from memory of the storage system, the plain text data encryption key;

unwrapping a Trusted Platform Module (TPM) wrapped key stored in a key table at the storage system, transmitting the resulting unwrapped key to the key management system and, receiving from the key management system, the plain text data encryption key; or

obtaining, from a Least Recently Used (LRU) memory cache of the key management system, the plain text data encryption key.

8. The method as recited in claim 1 , further comprising performing a pre-fetch process to gather metadata relating to one or more containers and/or metadata relating to one or more keys, and populating a Least Recently Used (LRU) memory cache at the key management system with the pre-fetched metadata.

9. The method as recited in claim 8 , wherein the pre-fetched metadata is read out from the LRU memory cache and/or from a Trusted Platform Module (TPM) cache.

10. The method as recited in claim 8 , wherein the storage system is operable to perform deduplication on the clear text data, and to perform a garbage collection process to avoid eviction of hot keys from the LRU memory cache by copying forward a batch of live data and sub-batching the live data together with a key-space specific to the batch of data.

11. A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

receiving clear text data at a storage system;

generating, at the storage system, which is separate from a key management system, a plain text data encryption key;

sending, by the storage system, the plain text data encryption key to the key management system to enable the key management system to encrypt the plain text data encryption key with a master key, wherein the master key is located in the key management system, to create an encrypted data encryption key;

receiving, at the storage system, the encrypted data encryption key from the key management system;

encrypting, at the storage system, the clear text data with the encrypted data encryption key to create encrypted data; and

storing, together, the encrypted data and the encrypted data encryption key in the storage system.

12. The non-transitory storage medium as recited in claim 11 , wherein the master key is an unexportable key that is stored only at the key management system and not at the storage system.

13. The non-transitory storage medium as recited in claim 11 , wherein the operations further comprise using a Trusted Platform Module (TPM) chip to wrap the encrypted data encryption key received from the key management system to create a TPM wrapped key.

14. The non-transitory storage medium as recited in claim 13 , wherein the operations further comprise storing the TPM wrapped key in a key table at the storage system.

15. The non-transitory storage medium as recited in claim 11 , wherein the operations further comprise receiving a read request at the storage system and, in response to receipt of the read request, reading out, at the storage system, the encrypted data and the encrypted data encryption key.

16. The non-transitory storage medium as recited in claim 15 , wherein the operations further comprise obtaining the plain text data encryption key which was used to create the encrypted data encryption key, and decrypting the encrypted data with the plain text data encryption key.

17. The non-transitory storage medium as recited in claim 16 , wherein obtaining the plain text data encryption key comprises one of:

obtaining, from memory of the storage system, the plain text data encryption key;

unwrapping a Trusted Platform Module (TPM) wrapped key stored in a key table at the storage system, transmitting the resulting unwrapped key to the key management system and, receiving from the key management system, the plain text data encryption key; or

obtaining, from a Least Recently Used (LRU) memory cache of the key management system, the plain text data encryption key.

18. The non-transitory storage medium as recited in claim 11 , wherein the operations further comprise performing a pre-fetch process to gather metadata relating to one or more containers and/or metadata relating to one or more keys, and populating a Least Recently Used (LRU) memory cache at the key management system with the pre-fetched metadata.

19. The non-transitory storage medium as recited in claim 18 , wherein the pre-fetched metadata is read out from the LRU memory cache and/or from a Trusted Platform Module (TPM) cache.

20. The non-transitory storage medium as recited in claim 18 , wherein the operations further comprise performing deduplication on the clear text data, and performing a garbage collection process to avoid eviction of hot keys from the LRU memory cache by copying forward a batch of live data and sub-batching the live data together with a key-space specific to the batch of data.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2022
From: PONNUSWAMY, SENTHIL; KARADIGUDDA, MAHADEV; BALAKRISHNAN, KALIDAS
To: EMC IP HOLDING COMPANY
Reel/Frame 059236/0452 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →