IP Library Granted Patent US 11,838,408
Granted Patent B2
US 11,838,408 · App. 17/243,253 · Granted Dec 5, 2023

Managing migration of self encrypted drive within a single key management system user group

Inventors: Karthik Arunachalam (Round Rock, TX); Vigneswaran Ponnusamy (Round Rock, TX); Karthikeyan Rajagopalan (Austin, TX); Sanjeev Dambal (Austin, TX); Kumaran Palaniappan Thangavelu (Austin, TX)
Assignee: Dell Products L.P.
H04L9/083H04L9/0866H04L9/0894H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,838,408
App. No.
17/243,253
Granted
Dec 5, 2023
Kind
B2
Abstract

A disclosed method for managing encryption keys, which may be performed by a key management server, responds to receiving, from a first client, a request to create a new key for a self-encrypting drive (SED) associated with the first client by retrieving unique identifiers of the first client and the SED, generating and storing the new key and a corresponding key identifier (KeyID), and associating the unique identifiers of the SED and first client with the new key. Upon receiving, from a second client, a locate key request that includes the SED identifier, providing the new key, the KeyID, and the first client identifier to the second client. Associating the SED and first client identifiers with the new key may include adding the identifiers as attributes of the KeyID. Embodiments may be implemented in accordance with a key management interoperability protocol (KMIP) standard.

Claims (22)

1. A method for managing encryption keys, the method comprising:

responsive to receiving, from a first client, a request to create a new key for encrypting a storage drive associated with the first client:

retrieving an identifier of the first client and an identifier of the storage drive;

generating and storing the new key and a corresponding key identifier (KeyID); and

associating the identifier of the storage drive and the identifier of the first client with the new key; and

responsive to receiving, from a second client, a locate key request, wherein the locate key request is indicative of the identifier of the storage drive, providing, to the second client, information indicative of the new key, the KeyID, and the identifier of the first client, wherein the first client comprises a first key management interoperability protocol (KMIP) client executing on a baseboard management controller (BMC) of a first managed server and the second client comprises a second KMIP client executing on a BMC of a second managed server.

2. The method of claim 1 , further comprising: determining that the storage drive comprises a self-encrypting drive (SED).

3. The method of claim 1 , further comprising: determining that the SED comprises an SED configured not to store KeyIDs internally.

4. The method of claim 1 , wherein associating the identifier of the storage drive and the identifier of the first client with the new key comprises adding the identifier of the storage drive and the identifier of the first client as attributes of the KeyID.

5. The method of claim 1 , further comprising: determining that the first client and the second client communicate with the same key management server.

6. The method of claim 1 , further comprising: caching, by the second client, the new key, the KeyID, and the identifier of the first client.

7. A key management server for managing encryption keys, wherein the key management server is configured to perform key management operations comprising:

responsive to receiving, from a first client, a request to create a new key for encrypting a storage drive associated with the first client:

retrieving an identifier of the first client and an identifier of the storage drive;

generating and storing the new key and a corresponding key identifier (KeyID); and

associating the identifier of the storage drive and the identifier of the first client with the new key; and

responsive to receiving, from a second client, a locate key request, wherein the locate key request is indicative of the identifier of the storage drive, providing, to the second client, information indicative of the new key, the KeyID, and the identifier of the first client, wherein the first client comprises a first key management interoperability protocol (KMIP) client executing on a baseboard management controller (BMC) of a first managed server and the second client comprises a second KMIP client executing on a BMC of a second managed server.

8. The key management server of claim 7 , further comprising: determining that the storage drive comprises a self-encrypting drive (SED).

9. The key management server of claim 7 , further comprising: determining that the SED comprises an SED configured not to store KeyIDs internally.

10. The key management server of claim 7 , wherein associating the identifier of the storage drive and the identifier of the first client with the new key comprises adding the identifier of the storage drive and the identifier of the first client as attributes of the KeyID.

11. The key management server of claim 7 , further comprising: determining that the first client and the second client communicate with the same key management server.

12. The key management server of claim 7 , further comprising: caching, by the second client, the new key, the KeyID, and the identifier of the first client.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2021
From: ARUNACHALAM, KARTHIK; PONNUSAMY, VIGNESWARAN; RAJAGOPALAN, KARTHIKEYAN; DAMBAL, SANJEEV; THANGAVELU, KUMARAN PALANIAPPAN
To: DELL PRODUCTS L.P.
Reel/Frame 056643/0706 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
Continuity (1)
Related Publication 20220353057A1 · Nov 3, 2022