IP Library Granted Patent US 11,526,283
Granted Patent B1
US 11,526,283 · App. 17/375,641 · Granted Dec 13, 2022

Logical storage device access using per-VM keys in an encrypted storage environment

Inventors: Sanjib Mallick (Bangalore, IN); Amit Pundalik Anchi (Bangalore, IN)
Assignee: EMC IP Holding Company LLC
G06F3/0623G06F3/0664G06F3/0665G06F3/0673G06F9/45558G06F2009/45583
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,526,283
App. No.
17/375,641
Granted
Dec 13, 2022
Kind
B1
Abstract

An apparatus in an illustrative embodiment comprises at least one processing device comprising a processor and a memory, with the processor coupled to the memory. The at least one processing device is configured to receive in a storage system, from a host device, information that identifies (i) a particular virtual machine implemented by the host device and (ii) a key specific to the virtual machine, to utilize at least a portion of the received information to obtain in the storage system the key specific to the virtual machine from a key management server external to the storage system, to store the obtained key in the storage system in association with one or more parts of the received information, and to utilize the obtained key to process input-output operations that are received in the storage system from the host device and that are identified as being associated with the virtual machine.

Claims (57)

1. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

wherein the at least one processing device is configured:

to receive in a storage system, from a multi-path input-output driver of a host device, information that identifies (i) a particular virtual machine implemented by the host device and (ii) a key specific to the virtual machine;

to utilize at least a portion of the received information to obtain in the storage system the key specific to the virtual machine from a key management server external to the storage system;

to store the obtained key in the storage system in association with one or more parts of the received information; and

to utilize the obtained key to process input-output operations that are received in the storage system from the host device and that are identified as being associated with the virtual machine;

wherein the multi-path input-output driver of the host device is configured to obtain the key specific to the virtual machine from the key management server.

2. The apparatus of claim 1 wherein the at least one processing device comprises at least a portion of the storage system.

3. The apparatus of claim 2 wherein the at least one processing device further comprises at least a portion of at least one of the host device, one or more additional host devices, and a host management system that is configured to manage the host devices.

4. The apparatus of claim 1 wherein the virtual machine implemented by the host device comprises at least one virtual storage volume.

5. The apparatus of claim 1 wherein a user-space portion of the multi-path input-output driver of the host device obtains the key specific to the virtual machine and provides the key specific to the virtual machine to a kernel-space portion of the multi-path input-output driver of the host device.

6. The apparatus of claim 5 wherein the kernel-space portion of the multi-path input-output driver of the host device implements a host encryption engine configured to perform encryption and decryption of data of at least one logical storage volume associated with the virtual machine using the key specific to the virtual machine.

7. The apparatus of claim 1 wherein the received information comprises:

an identifier of the virtual machine;

an identifier of the key specific to the virtual machine; and

information characterizing an encryption status of the virtual machine.

8. The apparatus of claim 7 wherein the information characterizing the encryption status of the virtual machine comprises an encryption status indicator that is part of metadata of the virtual machine.

9. The apparatus of claim 7 wherein the at least one processing device is further configured to store one or more of the identifier of the virtual machine, the identifier of the key specific to the virtual machine, and the information characterizing the encryption status of the virtual machine in at least one of:

a data structure of the storage system; and

a self-describing header of at least one logical storage device associated with the virtual machine.

10. The apparatus of claim 7 wherein at least a portion of the received information is received in the storage system via an out-of-band mechanism comprising at least one application programming interface (API).

11. The apparatus of claim 7 wherein at least a portion of the received information is received in the storage system via an in-band mechanism comprising at least one command issued by the multi-path input-output driver of the host device.

12. The apparatus of claim 11 wherein the at least one command comprises at least one command of a storage access protocol utilized by the host device to access the storage system over a network.

13. The apparatus of claim 12 wherein the at least one command comprises a particular command descriptor block that is configured to include the identifier of the key specific to the virtual machine.

14. The apparatus of claim 1 wherein the at least one processing device is further configured:

to receive a given one of the input-output operations;

to determine a virtual machine identifier for the given input-output operation; and

to utilize the virtual machine identifier to access at least one data structure within the storage system to obtain the key specific to the virtual machine for use in processing the given input-output operation.

15. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code, when executed by at least one processing device comprising a processor coupled to a memory, causes the at least one processing device:

to receive in a storage system, from a multi-path input-output driver of a host device, information that identifies (i) a particular virtual machine implemented by the host device and (ii) a key specific to the virtual machine;

to utilize at least a portion of the received information to obtain in the storage system the key specific to the virtual machine from a key management server external to the storage system;

to store the obtained key in the storage system in association with one or more parts of the received information; and

to utilize the obtained key to process input-output operations that are received in the storage system from the host device and that are identified as being associated with the virtual machine;

wherein the multi-path input-output driver of the host device is configured to obtain the key specific to the virtual machine from the key management server.

16. The computer program product of claim 15 wherein the received information comprises:

an identifier of the virtual machine;

an identifier of the key specific to the virtual machine; and

information characterizing an encryption status of the virtual machine.

17. The computer program product of claim 15 wherein the program code, when executed by the at least one processing device, further causes the at least one processing device:

to receive a given one of the input-output operations;

to determine a virtual machine identifier for the given input-output operation; and

to utilize the virtual machine identifier to access at least one data structure within the storage system to obtain the key specific to the virtual machine for use in processing the given input-output operation.

18. A method comprising:

receiving in a storage system, from a multi-path input-output driver of a host device, information that identifies (i) a particular virtual machine implemented by the host device and (ii) a key specific to the virtual machine;

utilizing at least a portion of the received information to obtain in the storage system the key specific to the virtual machine from a key management server external to the storage system;

storing the obtained key in the storage system in association with one or more parts of the received information; and

utilizing the obtained key to process input-output operations that are received in the storage system from the host device and that are identified as being associated with the virtual machine;

wherein the multi-path input-output driver of the host device is configured to obtain the key specific to the virtual machine from the key management server.

19. The method of claim 18 wherein the received information comprises:

an identifier of the virtual machine;

an identifier of the key specific to the virtual machine; and

information characterizing an encryption status of the virtual machine.

20. The method of claim 18 further comprising:

receiving a given one of the input-output operations;

determining a virtual machine identifier for the given input-output operation; and

utilizing the virtual machine identifier to access at least one data structure within the storage system to obtain the key specific to the virtual machine for use in processing the given input-output operation.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2021
From: MALLICK, SANJIB; ANCHI, AMIT PUNDALIK
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 056854/0736 →
Priority Claims (1)
IN 202141025456 · Jun 8, 2021 · national
Cited By (4)
US 12,197,593 US 12,517,682 US 12,608,158 US 12,670,120