IP Library Granted Patent US 11,983,281
Granted Patent B2
US 11,983,281 · App. 17/343,532 · Granted May 14, 2024

Using INQ to optimize end-to-end encryption management with backup appliances

Inventors: Jehuda Shemer (Kfra Saba, IL); Arieh Don (Newton, MA); Krishna Deepak Nuthakki (Bangalore, IN)
Assignee: EMC IP HOLDING COMPANY LLC
G06F21/602G06F11/1453G06F11/1469H04L9/0894G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,983,281
App. No.
17/343,532
Granted
May 14, 2024
Kind
B2
Abstract

One example method includes receiving, by a backup appliance, a request concerning a dataset, performing, by the backup appliance, an inquiry to determine if end-to-end encryption is enabled for a volume of a target storage array, receiving, by the backup appliance, confirmation from the storage array that end-to-end encryption is enabled for the volume, and based on the confirmation that end-to-end encryption is enabled for the volume, storing the dataset in the volume without performing encryption, compression, or deduplication, of the dataset prior to storage of the dataset in the volume.

Claims (40)

1. A method, comprising:

receiving, by a backup appliance, a dataset for backup from a volume of a storage array;

performing, by the backup appliance, an inquiry to determine if end-to-end encryption is enabled for the volume of the storage array;

receiving, by the backup appliance, confirmation from the storage array that end-to-end encryption is enabled for the volume; and

based on the confirmation that end-to-end encryption is enabled for the volume, storing the dataset in a backup volume without performing encryption, compression, or deduplication, of the dataset prior to storing the dataset in the backup volume.

2. The method as recited in claim 1 , wherein the inquiry is performed using an INQ command.

3. The method as recited in claim 1 , further comprising marking, by the backup appliance, data in the dataset as end-to-end encryption enabled after receipt of confirmation from the storage array that end-to-end encryption is enabled for the volume.

4. The method as recited in claim 1 , further comprising processing, by the backup appliance, the dataset,

wherein the processing is performed in response to a restore request, and

wherein the method further comprises restoring the dataset to a volume.

5. The method as recited in claim 1 , further comprising, in response to an access request, enabling, by the backup appliance, user access to a backup image of the dataset.

6. The method as recited in claim 1 , wherein the dataset is encrypted, and

wherein the method further comprises:

after the receiving of the confirmation, receiving, by the backup appliance from the storage array, an encryption/decryption key for the encrypted dataset; and

storing, at the backup appliance, the encrypted dataset.

7. The method as recited in claim 6 , further comprising storing the encryption/decryption key together with the encrypted dataset.

8. The method as recited in claim 1 , further comprising:

receiving, by the backup appliance, a restore request to restore a backup dataset to a target storage array;

notifying, by the backup appliance, the storage array that data in the backup dataset is marked as end-to-end encryption enabled; and

transmitting, by the backup appliance, an encrypted backup dataset and an encryption/decryption key to the storage array.

9. A non-transitory computer readable storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

receiving, by a backup appliance, a dataset for backup from a volume of a storage array;

performing, by the backup appliance, an inquiry to determine if end-to-end encryption is enabled for the volume of the storage array;

receiving, by the backup appliance, confirmation from the storage array that end-to-end encryption is enabled for the volume; and

based on the confirmation that end-to-end encryption is enabled for the volume, storing the dataset in a backup volume without performing encryption, compression, or deduplication, of the dataset prior to storing the dataset in the backup volume.

10. The non-transitory computer readable storage medium as recited in claim 9 , wherein the inquiry is performed using an INQ command.

11. The non-transitory computer readable storage medium as recited in claim 9 , wherein the operations further comprise marking, by the backup appliance, data in the dataset as end-to-end encryption enabled after receipt of confirmation from the storage array that end-to-end encryption is enabled for the volume.

12. The non-transitory computer readable storage medium as recited in claim 9 , wherein the operations further comprise processing, by the backup appliance, the dataset,

wherein the processing is performed in response to a restore request, and

wherein the operations further comprise restoring the dataset to a volume.

13. The non-transitory computer readable storage medium as recited in claim 9 , wherein the operations further comprise, in response to an access request, the backup appliance enabling user access to a backup image of the dataset.

14. The non-transitory computer readable storage medium as recited in claim 9 , wherein the dataset is encrypted, and

wherein the operations further comprise:

after the receiving of the confirmation, receiving, by the backup appliance from the storage array, an encryption/decryption key for the encrypted dataset; and

storing, at the backup appliance, the encrypted dataset.

15. The non-transitory computer readable storage medium as recited in claim 14 , wherein the operations further comprise storing the encryption/decryption key together with the encrypted dataset.

16. The non-transitory computer readable storage medium as recited in claim 9 , wherein the operations further comprise:

receiving, by the backup appliance, a restore request to restore a backup dataset to the storage array;

notifying, by the backup appliance, the storage array that data in the backup dataset is marked as end-to-end encryption enabled; and

transmitting, by the backup appliance, an encrypted backup dataset and an encryption/decryption key to the storage array.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2023
From: SHEMER, JEHUDA; DON, ARIEH; NUTHAKKI, KRISHNA DEEPAK
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 063287/0975 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
Continuity (1)
Related Publication 20220398326A1 · Dec 15, 2022