IP Library Granted Patent US 11,640,245
Granted Patent B2
US 11,640,245 · App. 17/177,821 · Granted May 2, 2023

Logical storage device access in an encrypted storage environment

Inventors: Vinay G. Rao (Bangalore, IN); Sanjib Mallick (Bangalore, IN); Arieh Don (Newton, MA)
Assignee: EMC IP Holding Company LLC
G06F3/0611G06F3/065G06F3/0619G06F3/0622G06F3/0659G06F3/0665G06F3/0688
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,640,245
App. No.
17/177,821
Granted
May 2, 2023
Kind
B2
Abstract

A method comprises associating a first logical storage device with a first host device, wherein data encrypted using a private key of the first host device is written to the first logical storage device, generating a copy of the first logical storage device, associating the copy of the first logical storage device with a second logical storage device, wherein data encrypted using a private key of a second host device is written to the second logical storage device, and providing the second host device with access to an encrypted version of a public key of the first host device, encrypted using a public key of the second host device, to allow the second host device to obtain the public key of the first host device. The second host device can thereby access particular data of the second logical storage device written using the private key of the first host device.

Claims (44)

1. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

wherein the at least one processing device is configured:

to associate a first logical storage device of a storage system with a first host device, wherein data encrypted using a private key of the first host device is written to the first logical storage device;

to generate a copy of the first logical storage device in the storage system;

to associate the copy of the first logical storage device with a second logical storage device of the storage system, wherein data encrypted using a private key of a second host device is written to the second logical storage device; and

to provide the second host device with access to an encrypted version of a public key of the first host device, encrypted using a public key of the second host device, to allow the second host device to obtain therefrom the public key of the first host device, so that the second host device can access particular data of the second logical storage device that was written using the private key of the first host device;

wherein responsive to a request from the second host device for particular data of the second logical storage device, the at least one processing device is further configured to determine if the particular data was encrypted using the private key of the first host device or the private key of the second host device, and to provide the second host device with the particular data and an indication of a result of the determination; and

wherein the indication provided to the second host device is configured to selectively incorporate a particular one of at least first and second possible values, the first value directing the second host device to decrypt the particular data using the public key of the first host device and the second value directing the second host device to decrypt the particular data using the public key of the second host device.

2. The apparatus of claim 1 wherein the at least one processing device comprises at least a portion of the storage system.

3. The apparatus of claim 1 generating a copy of the first logical storage device comprises generating a snapshot of the first logical storage device.

4. The apparatus of claim 1 wherein the result of the determination is that the particular data was encrypted using the private key of the first host device, and the indication directs the second host device to decrypt the particular data using the public key of the first host device, which is obtained by the second host device decrypting the encrypted version of the public key of the first host device using the private key of the second host device.

5. The apparatus of claim 1 wherein the result of the determination is that the particular data was encrypted using the private key of the second host device, and the indication directs the second host device to decrypt the particular data using the public key of the second host device.

6. The apparatus of claim 1 wherein the at least one processing device is configured to store the public key of the first host device for use in decrypting encrypted data written by the first host device to the first logical storage device.

7. The apparatus of claim 1 wherein the at least one processing device is configured to store the public key of the second host device for use in decrypting encrypted data written by the second host device to the second logical storage device.

8. The apparatus of claim 1 wherein providing the second host device with access to an encrypted version of a public key of the first host device comprises providing the encrypted version of the public key of the first host device to the second host device in response to a command received from the second host device.

9. The apparatus of claim 8 wherein the command comprises a vendor unique command of a storage access protocol utilized by the first and second host devices to access the storage system over a network.

10. The apparatus of claim 8 wherein the command is received in the storage system from a multi-path input-output driver of the second host device.

11. The apparatus of claim 10 wherein the encrypted version of the public key of the first host device is decrypted, using the private key of the second host device, to obtain the public key of the first host device in a kernel-space portion of the multi-path input-output driver of the second host device.

12. The apparatus of claim 1 wherein the indication of the result of the determination comprises a check condition notification sent by the storage system to the second host device to direct the second host device to perform one of the following operations:

to decrypt the particular data using the public key of the first host device; and

to decrypt the particular data using the public key of the second host device.

13. The apparatus of claim 1 wherein the indication of the result of the determination comprises a status value sent by the storage system to the second host device to direct the second host device to perform one of the following operations:

to decrypt the particular data using the public key of the first host device; and

to decrypt the particular data using the public key of the second host device.

14. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code, when executed by at least one processing device comprising a processor coupled to a memory, causes the at least one processing device:

to associate a first logical storage device of a storage system with a first host device, wherein data encrypted using a private key of the first host device is written to the first logical storage device;

to generate a copy of the first logical storage device in the storage system;

to associate the copy of the first logical storage device with a second logical storage device of the storage system, wherein data encrypted using a private key of a second host device is written to the second logical storage device;

to provide the second host device with access to an encrypted version of a public key of the first host device, encrypted using a public key of the second host device, to allow the second host device to obtain therefrom the public key of the first host device, so that the second host device can access particular data of the second logical storage device that was written using the private key of the first host device;

wherein the program code, when executed by the at least one processing device, further causes the at least one processing device, responsive to a request from the second host device for particular data of the second logical storage device, to determine if the particular data was encrypted using the private key of the first host device or the private key of the second host device, and to provide the second host device with the particular data and an indication of a result of the determination; and

wherein the indication provided to the second host device is configured to selectively incorporate a particular one of at least first and second possible values, the first value directing the second host device to decrypt the particular data using the public key of the first host device and the second value directing the second host device to decrypt the particular data using the public key of the second host device.

15. The computer program product of claim 14 wherein the result of the determination is that the particular data was encrypted using the private key of the first host device, and the indication directs the second host device to decrypt the particular data using the public key of the first host device, which is obtained by the second host device decrypting the encrypted version of the public key of the first host device using the private key of the second host device.

16. A method comprising:

associating a first logical storage device of a storage system with a first host device, wherein data encrypted using a private key of the first host device is written to the first logical storage device;

generating a copy of the first logical storage device in the storage system;

associating the copy of the first logical storage device with a second logical storage device of the storage system, wherein data encrypted using a private key of a second host device is written to the second logical storage device;

providing the second host device with access to an encrypted version of a public key of the first host device, encrypted using a public key of the second host device, to allow the second host device to obtain therefrom the public key of the first host device, so that the second host device can access particular data of the second logical storage device that was written using the private key of the first host device; and

responsive to a request from the second host device for particular data of the second logical storage device, determining if the particular data was encrypted using the private key of the first host device or the private key of the second host device, and providing the second host device with the particular data and an indication of a result of the determination;

wherein the indication provided to the second host device is configured to selectively incorporate a particular one of at least first and second possible values, the first value directing the second host device to decrypt the particular data using the public key of the first host device and the second value directing the second host device to decrypt the particular data using the public key of the second host device.

17. The method of claim 16 wherein the result of the determination is that the particular data was encrypted using the private key of the first host device, and the indication directs the second host device to decrypt the particular data using the public key of the first host device, which is obtained by the second host device decrypting the encrypted version of the public key of the first host device using the private key of the second host device.

18. The method of claim 16 wherein the result of the determination is that the particular data was encrypted using the private key of the second host device, and the indication directs the second host device to decrypt the particular data using the public key of the second host device.

19. The method of claim 16 wherein providing the second host device with access to an encrypted version of a public key of the first host device comprises providing the encrypted version of the public key of the first host device to the second host device in response to a command received from the second host device.

20. The method of claim 19 wherein the command is received in the storage system from a multi-path input-output driver of the second host device.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2021
From: RAO, VINAY G.; MALLICK, SANJIB; DON, ARIEH
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 055298/0802 →