IP Library › Granted Patent US 12,135,656
Granted Patent B2
US 12,135,656 · App. 17/482,661 · Granted Nov 5, 2024

Re-keying the contents of a storage device

Inventors: Ethan Miller (Santa Cruz, CA); Andrew Bernat (Mountain View, CA)
Assignee: PURE STORAGE, INC.
G06F12/1408G06F3/061G06F3/0623G06F3/0656G06F3/0688G06F3/0689G06F21/6218G06F21/80H04L9/088H04L9/0891H04L9/0894H04L63/061H04L63/068G06F2221/2107H04L67/1097H04L2463/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,135,656
App. No.
17/482,661
Granted
Nov 5, 2024
Kind
B2
Abstract

Periodically re-encrypting user data stored on a storage device, including: determining that data stored in a first location of a storage device is encrypted with a data encryption key that has been decommissioned; re-encrypting the data utilizing a current data encryption key; and writing the data that is encrypted utilizing the current data encryption key to a second location of the storage device.

Claims (27)

1. A method comprising:

determining that data stored in a first location of a storage device is encrypted with a data encryption key that has been decommissioned, wherein the data is associated with a user-visible identifier; and

storing the data re-encrypted with the current data encryption key to a second location of the storage device that is different from the first location, wherein the data is associated with the user-visible identifier when stored at the second location.

2. The method of claim 1 further comprising reporting the first location of the storage device to a garbage collection process.

3. The method of claim 2 further comprising performing garbage collection operations on the first location of the storage device.

4. The method of claim 1 further comprising decrypting the data that is encrypted with the data encryption key that has been decommissioned.

5. The method of claim 1 further comprising detecting that the data encryption key should be decommissioned, including detecting that the data encryption key has been utilized for a predetermined period of time.

6. The method of claim 1 further comprising detecting that the data encryption key should be decommissioned, including detecting that the data encryption key has been utilized to encrypt a predetermined amount of data.

7. The method of claim 1 wherein each data encryption key is encrypted with a key encryption key.

8. The method of claim 7 further comprising:

detecting that the key encryption key should be decommissioned; and

re-encrypting one or more data encryption keys with a new key encryption key.

9. A storage device that includes a computer processor and a computer memory, the computer memory including computer program instructions that, when executed by the computer processor, cause the storage device to carry out the steps of:

determining that data stored in a first location of a storage device is encrypted with a data encryption key that has been decommissioned, wherein the data is associated with a user-visible identifier; and

storing the data re-encrypted with the current data encryption key to a second location of the storage device that is different from the first location, wherein the data is associated with the user-visible identifier when stored at the second location.

10. The storage device of claim 9 further comprising computer program instructions that, when executed by the computer processor, cause the storage device to carry out the step of reporting the first location of the storage device to a garbage collection process.

11. The storage device of claim 10 further comprising computer program instructions that, when executed by the computer processor, cause the storage device to carry out the step of performing garbage collection operations on the first location of the storage device.

12. The storage device of claim 9 further comprising computer program instructions that, when executed by the computer processor, cause the storage device to carry out the step of decrypting the data that is encrypted with the data encryption key that has been decommissioned.

13. The storage device of claim 9 further comprising computer program instructions that, when executed by the computer processor, cause the storage device to carry out the step of detecting that the data encryption key should be decommissioned, including detecting that the data encryption key has been utilized for a predetermined period of time.

14. The storage device of claim 9 further comprising computer program instructions that, when executed by the computer processor, cause the storage device to carry out the step of detecting that the data encryption key should be decommissioned, including detecting that the data encryption key has been utilized to encrypt a predetermined amount of data.

15. The storage device of claim 9 wherein each data encryption key is encrypted with a key encryption key.

16. The storage device of claim 15 further comprising computer program instructions that, when executed by the computer processor, cause the storage device to carry out the steps of:

detecting that the key encryption key should be decommissioned; and

re-encrypting one or more data encryption keys with a new key encryption key.

17. A storage system that includes a plurality of storage devices, the storage system including a computer processor and a computer memory, the computer memory including computer program instructions that, when executed by the computer processor, cause the computer processor to carry out the steps of:

determining that data stored in a first location of a storage device is encrypted with a data encryption key that has been decommissioned, wherein the data is associated with a user-visible identifier; and

storing the data re-encrypted with the current data encryption key to a second location of the storage device that is different from the first location, wherein the data is associated with the user-visible identifier when stored at the second location.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2021
From: MILLER, ETHAN; BERNAT, ANDREW
To: PURE STORAGE, INC.
Reel/Frame 057572/0899 →
Continuity (4)
Continuation 16701852 · Dec 3, 2019
Continuation 15402954 · Jan 10, 2017
Continuation 15399539 · Jan 5, 2017
Related Publication 20220014369A1 · Jan 13, 2022