IP Library Granted Patent US 12,362,930
Granted Patent B2
US 12,362,930 · App. 17/649,699 · Granted Jul 15, 2025

Data protection service using isolated, encrypted backup data

Inventors: Lawrence Chang (San Jose, CA); Xia Hua (Mountain View, CA); Woonho Jung (Cupertino, CA); Rajeev Kumar (Sunnyvale, CA); Douglas Qian (Mountain View, CA); Abdul Jabbar Abdul Rasheed (San Jose, CA)
Assignee: Commvault Systems, Inc.
H04L9/14G06F11/1469G06F21/602H04L9/0861H04L9/0891G06F21/606G06F21/6218H04L9/0894H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,362,930
App. No.
17/649,699
Granted
Jul 15, 2025
Kind
B2
Abstract

Disclosed techniques relate to security of backup data. In some embodiments, a method includes receiving, by data protection service running on a cloud computing system, a first encrypted copy of a backup of a first data store that is associated with a first account of an organization, where the first encrypted copy is encrypted using a first custodian cryptographic key that is shared between the organization and the data protection service that is different than a first production cryptographic key that is private and used by the organization to encrypt a non-backup version of the first data store. The method may include generating a second encrypted copy of the backup, including by encrypting the backup using a storage cryptographic key. The method may include storing the second encrypted copy of the backup in a second data store that is associated with the data protection service.

Claims (31)

1. A method, comprising:

receiving, by a data protection service running in a cloud computing system, a first encrypted copy of a backup version of a first data store, wherein the first data store operates in the cloud computing system in a first account of an organization,

wherein the first encrypted copy is encrypted using a first custodian cryptographic key that is shared between the organization and the data protection service,

wherein the first custodian cryptographic key is different from a first production cryptographic key that is used by the organization to encrypt a non-backup version of the first data store within the first account, and

wherein the first production cryptographic key is not shared with the data protection service;

receiving, by the data protection service, a storage cryptographic key from the organization via another account of the organization, wherein the storage cryptographic key is different from the first custodian cryptographic key and is not shared with the first account;

generating, by the data protection service, a second encrypted copy of the backup version by encrypting the backup version using the storage cryptographic key;

storing, by the data protection service, the second encrypted copy of the backup version in a second data store that is associated with the data protection service, wherein the second data store operates in the cloud computing system and is not accessible to the organization from the first account;

subsequent to storing the second encrypted copy of the backup version, receiving, by the data protection service, a second custodian cryptographic key issued by the organization, wherein the second custodian cryptographic key is shared by the organization and the data protection service;

receiving, by the data protection service, a restore request from the organization to restore the backup version of the first data store; and

in response to the restore request, generating, by the data protection service, a third encrypted copy of the backup version by encrypting the backup version using the second custodian cryptographic key.

2. The method of claim 1 , wherein the storage cryptographic key is managed by the organization and is not shared with the data protection service such that the data protection service does not have access to a plaintext version of the storage cryptographic key, and wherein the storage cryptographic key is revocable by the organization.

3. The method of claim 1 , wherein the storage cryptographic key is managed by the data protection service such that the organization does not have access to the storage cryptographic key.

4. The method of claim 1 , wherein the organization maintains the first account and a second account with a particular public cloud service that includes the cloud computing system, wherein the data protection service maintains a third account with the particular public cloud service, and wherein the first data store is a first database hosted by a database service provided by the particular public cloud service.

5. The method of claim 4 , further comprising:

determining, by the data protection service, that a particular threshold number of backups are saved using the database service via a particular account; and

in response to the determining, initiating, by the data protection service, creation of a new account with the particular public cloud service.

6. A non-transitory computer-readable medium having program instructions stored thereon that are executable by one or more computer systems to perform operations comprising:

receiving, by a data protection service that executes in a cloud service, a first encrypted copy of fail backup data of a first data store, wherein the first data store operates in the cloud service in a first account of an organization,

wherein the first encrypted copy is encrypted using a first custodian cryptographic key that is shared between the organization and the data protection service,

wherein the first custodian cryptographic key is different from a first production cryptographic key that is used by the organization to encrypt a non-backup version of the first data store within the first account of the cloud service, and

wherein the first production cryptographic key is not shared with the data protection service;

receiving, by the data protection service, a storage cryptographic key from the organization via another account of the organization, wherein the storage cryptographic key is different from the first custodian cryptographic key and is not shared with the first account;

generating a second encrypted copy of the backup data, which comprises encrypting the backup data using the storage cryptographic key;

storing the second encrypted copy of the backup data in a second data store that is associated with the data protection service, wherein the second data store operates in the cloud service and is not accessible to the organization from the first account;

subsequent to storing the second encrypted copy of the backup data, receiving a second custodian cryptographic key issued by the organization, wherein the second custodian cryptographic key is shared by the organization and the data protection service;

receiving a restore request from the organization to restore the backup data of the first data store; and

in response to the restore request, generating a third encrypted copy of the backup data by encrypting the backup data using the second custodian cryptographic key.

7. The non-transitory computer-readable medium of claim 6 , wherein the storage cryptographic key is managed by the organization and is not shared with the data protection service such that the data protection service does not have access to a plaintext version of the storage cryptographic key, and wherein the storage cryptographic key is revocable by the organization.

8. The non-transitory computer-readable medium of claim 6 , wherein the organization maintains the first account and a second account with the cloud service, wherein the data protection service maintains a third account with the cloud service, and wherein the first data store is a first database hosted by a database service provided by the cloud service.

9. The non-transitory computer-readable medium of claim 6 , wherein the storage cryptographic key is managed by the data protection service such that the organization does not have access to the storage cryptographic key.

Assignments (3)
SUPPLEMENTAL CONFIRMATORY GRANT OF SECURITY INTEREST IN UNITED STATES PATENTS Recorded Apr 16, 2025
From: COMMVAULT SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 070864/0344 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2024
From: CLUMIO, INC.
To: COMMVAULT SYSTEMS, INC.
Reel/Frame 068815/0722 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2022
From: CHANG, LAWRENCE; HUA, XIA; JUNG, WOONHO; KUMAR, RAJEEV; QIAN, DOUGLAS; ABDUL RASHEED, ABDUL JABBAR
To: CLUMIO, INC.
Reel/Frame 058859/0186 →
Cited By (1)
US 12,625,999