IP Library Granted Patent US 11,924,183
Granted Patent B2
US 11,924,183 · App. 17/322,958 · Granted Mar 5, 2024

Encrypting data in a non-volatile memory express (‘NVMe’) storage device

Inventors: Andrew Bernat (Mountain View, CA); Timothy Brennan (San Francisco, CA); Ethan Miller (Santa Cruz, CA); John Colgrove (Los Altos, CA)
Assignee: PURE STORAGE, INC.
H04L63/061G06F21/78H04L9/085G06F2221/2107G06F2221/2131
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,183
App. No.
17/322,958
Filed
May 18, 2021
Granted
Mar 5, 2024
Kind
B2
Art Unit
2435
USPC
713/171
Abstract

Data protection in a storage system that includes a plurality of Non-Volatile Memory Express (‘NVMe’) Solid State Drives (‘SSDs’), including: retrieving, from a plurality of NVMe SSDs (‘Non-Volatile Memory Express Solid State Drives’) of a storage system, one or more unencrypted shares of a master secret; reconstructing the master secret using the shares of the master secret; decrypting one or more encrypted device keys using the master secret; and using the decrypted device keys to perform a plurality of accesses to one or more of the NVMe SSDs.

Claims (48)

1. A storage system that includes a plurality of Non-Volatile Memory Express (‘NVMe’) Solid State Drives (‘SSDs’) and a controller, wherein the controller is configured to carry out the steps of:

retrieving, from non-encrypted namespaces of the plurality of NVMe SSDs of the storage system, a plurality of unencrypted shares of a master secret;

reconstructing the master secret using the plurality of unencrypted shares of the master secret;

decrypting one or more encrypted device keys using the master secret; and

using the decrypted device keys to perform a plurality of accesses to one or more of the plurality of NVMe SSDs.

2. The storage system of claim 1 , wherein the controller is further configured to carry out the step of storing the decrypted device keys in a volatile memory.

3. The storage system of claim 1 , wherein the controller is further configured to carry out the steps of:

for each of the plurality of NVMe SSDs, encrypting a device key using a master secret, wherein the device key, when not encrypted, is used to encrypt and decrypt data in one or more namespaces on the NVMe SSD;

generating a plurality of shares from the master secret; and

storing a separate share of the plurality of shares in a namespace prohibited from encryption on each NVMe SSD.

4. The storage system of claim 3 , wherein each namespace other than the namespace that is prohibited from encryption is accessible for writing only with a device key and accessible for reading without the device key.

5. The storage system of claim 4 , wherein encrypting, for each NVMe SSD, the device key further comprises encrypting the device key using the master secret and a value unique to the corresponding NVMe SSD.

6. The storage system of claim 1 , wherein a number of shares needed to reconstruct the master secret is greater than a number of shares associated with any single physical grouping of the NVMe SSDs.

7. The storage system of claim 6 , wherein after detecting a failed NVMe SSD, the controller is further configured to carry out the steps of:

generating a new master secret;

encrypting each device key using the new master secret;

generating a plurality of new shares from the new master secret; and

storing a separate new share of the plurality of new shares in a namespace prohibited from encryption on each NVMe SSD.

8. The storage system of claim 7 , wherein generating a new master secret further comprises generating the new master secret periodically on a predetermined schedule.

9. A method of data protection in a storage system, the storage system comprising a plurality of Non-Volatile Memory Express (‘NVMe’) Solid State Drives (‘SSDs’), the method comprising:

retrieving, from non-encrypted namespaces of the plurality of NVMe SSDs of the storage system, a plurality of unencrypted shares of a master secret;

reconstructing the master secret using the plurality of unencrypted shares of the master secret;

decrypting one or more encrypted device keys using the master secret; and

using the decrypted device keys to perform a plurality of accesses to one or more of the plurality of NVMe SSDs.

10. The method of claim 9 further comprising storing the decrypted device keys in a volatile memory.

11. The method as recited in claim 9 further comprising:

for each of the plurality of NVMe SSDs, encrypting a device key using a master secret, wherein the device key, when not encrypted, is used to encrypt and decrypt data in one or more namespaces on the NVMe SSD;

generating a plurality of shares from the master secret; and

storing a separate share of the plurality of shares in a namespace prohibited from encryption on each NVMe SSD.

12. The method of claim 11 , wherein each namespace other than the namespace that is prohibited from encryption is accessible for writing only with a device key and accessible for reading without the device key.

13. The method of claim 12 , wherein encrypting, for each NVMe SSD, the device key further comprises encrypting the device key using the master secret and a value unique to the corresponding NVMe SSD.

14. The method of claim 9 , wherein a number of shares needed to reconstruct the master secret is greater than a number of shares associated with any single physical grouping of the NVMe SSDs.

15. The method of claim 14 further comprising:

generating a new master secret;

encrypting each device key using the new master secret;

generating a plurality of new shares from the new master secret; and

storing a separate new share of the of the plurality of new shares in a namespace prohibited from encryption on each NVMe SSD.

16. The method of claim 15 , wherein generating a new master secret further comprises generating the new master secret periodically on a predetermined schedule.

17. A storage system that includes a plurality of storage devices and a controller, wherein each storage device includes an interposer that couples the plurality of storage devices to the controller, and wherein the controller is configured to carry out the steps of:

reconstructing a master secret using a plurality of shares of the master secret, wherein one or more of the shares is stored in one or more of the interposers;

decrypting one or more encrypted device keys using the master secret; and

using the decrypted device keys to perform a plurality of accesses to one or more of the plurality of storage devices.

18. The storage system of claim 17 , wherein the controller is further configured to carry out the step of storing the decrypted device keys in a volatile memory.

19. The storage system as recited in claim 17 , wherein the controller is further configured to carry out the steps of:

for each Non-Volatile Memory Express (‘NVMe’) Solid State Drive (‘SSD’) of a plurality of NVMe SSDs, encrypting a device key using a master secret, wherein the device key, when not encrypted, is used to encrypt and decrypt data in one or more namespaces on the NVMe SSD;

generating a plurality of shares from the master secret; and

storing a separate share of the plurality of shares in memory of each storage device's interposer.

20. The storage system of claim 19 , wherein encrypting, for each NVMe SSD, the device key further comprises encrypting the device key using the master secret and a value unique to the corresponding NVMe SSD.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: BERNAT, ANDREW; BRENNAN, TIMOTHY; MILLER, ETHAN; COLGROVE, JOHN
To: PURE STORAGE, INC.
Reel/Frame 056269/0220 →
Continuity (5)
Continuation 16167789 · Oct 23, 2018
Continuation In Part 15398898 · Jan 5, 2017
Continuation 14258826 · Apr 22, 2014
Continuation 13627444 · Sep 26, 2012
Related Publication 20210273929A1 · Sep 2, 2021