IP Library Granted Patent US 12,248,408
Granted Patent B2
US 12,248,408 · App. 17/938,996 · Granted Mar 11, 2025

Information processing system

Inventors: Tatsuya Hirai (Tokyo, JP); Hideo Saito (Tokyo, JP)
Assignee: HITACHI VANTARA, LTD.
G06F12/1408G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,408
App. No.
17/938,996
Granted
Mar 11, 2025
Kind
B2
Abstract

When having detected that key data set to an accelerator by command information is not key data permitted to use, a monitor unit issues, to a storage control unit, a suspension request for suspending processing related to writing of data, a compute unit having received an instruction from an application program reads data from the storage device, encrypts read data using the accelerator, and issues, to the storage control unit, an instruction to write encrypted data to the storage device, and when having received the suspension request, the storage control unit suspends processing related to writing of data to the storage device.

Claims (39)

1. An information processing system comprising:

an accelerator that is capable of encrypting data;

a storage device;

a compute unit that operates an application program, wherein the compute unit includes a plurality of virtual machines capable of operating the application program;

a storage control unit that processes a request for reading and writing data from and to a specific storage space issued by the compute unit in accordance with an instruction issued by the application program;

a monitor unit that monitors command information issued from the compute unit that sets, to the accelerator, key data used by the compute unit specified by the application program in order for the application program to encrypt data using the accelerator, wherein

when having detected that the key data set in the accelerator by the command information is not key data permitted to use, the monitor unit issues, to the storage control unit, a suspension request for suspending processing related to data writing,

the compute unit having received an instruction from the application program, reads data from the storage device, encrypts the read data using the accelerator, and issues, to the storage control unit, an instruction to write the encrypted data into the storage device, and

when having received the suspension request, the storage control unit suspends processing related to writing of data to the storage device; and

a virtual machine of the compute unit issues command information for setting, to the accelerator, key data used by the virtual machine specified by the application program provided in the virtual machine for the application program to encrypt data using the accelerator,

when having detected that the key data set by the command information issued from the virtual machine is not the key data permitted to use, the monitor unit issues, to the storage control unit, a suspension request for suspending processing related to writing of data by the virtual machine that has issued the command information, and

when having received the suspension request for suspending processing related to writing of data by the virtual machine, the storage control unit suspends processing related to writing of data by the virtual machine to the storage device.

2. An information processing system comprising:

an accelerator that is capable of encrypting data;

a storage device;

a storage control unit that processes data for reading from and writing to the storage device;

a compute unit that operates the storage control unit, wherein the compute unit includes at least one virtual machine capable of operating an application program;

a monitor unit that monitors command information issued from the compute unit that sets, to the accelerator, key data used by the storage control unit specified by the application program in order for the application program to encrypt the data using the accelerator, wherein

when having detected that the key data set in the accelerator by the command information is not key data permitted to use, the monitor unit issues, to the storage control unit, a suspension request for suspending processing related to data writing,

the compute unit having received an instruction from the application program, reads data from the storage device, encrypts the read data using the accelerator, and issues, to the storage control unit, an instruction to write the encrypted data into the storage device, and

when having received the suspension request, the storage control unit suspends processing related to writing of data to the storage device; and

a virtual machine of the at least one virtual machine of the compute unit issues command information for setting, to the accelerator, key data used by the virtual machine specified by the application program provided in the virtual machine for the application program to encrypt data using the accelerator,

when having detected that the key data set by the command information issued from the virtual machine is not the key data permitted to use, the monitor unit issues, to the storage control unit, a suspension request for suspending processing related to writing of data by the virtual machine that has issued the command information, and

when having received the suspension request for suspending processing related to writing of data by the virtual machine, the storage control unit suspends processing related to writing of data by the virtual machine to the storage device.

3. An information processing system comprising:

an accelerator that is capable of encrypting data;

a compute unit that operates an application program, the compute unit issuing to a storage control node that processes, a request for reading and writing data from and to a specific storage space issued by the compute unit in accordance with an instruction issued by the application program; and

a monitor unit that monitors command information issued from the compute unit that sets, to the accelerator, key data used by the compute unit specified by the application program in order for the application program to encrypt data using the accelerator, wherein

when having detected that the key data set in the accelerator by the command information is not key data permitted to use, the monitor unit issues, to the compute unit, a suspension request for suspending processing related to data writing,

the compute unit having received an instruction from the application program reads data from a storage device, encrypts the read data using the accelerator, and, when having received the suspension request, suspends issuance of an instruction to write the encrypted data into the storage device.

4. An information processing system comprising:

an accelerator that is capable of encrypting data;

a compute unit that operates an application program, the compute unit includes a plurality of virtual machines capable of operating the application program, and the compute unit issuing to a storage control node that processes, a request for reading and writing data from and to a specific storage space issued by the compute unit in accordance with an instruction issued by the application program;

a monitor unit that monitors command information issued from the compute unit that sets, to the accelerator, key data used by the compute unit specified by the application program in order for the application program to encrypt data using the accelerator, wherein

when having detected that the key data set in the accelerator by the command information is not key data permitted to use, the monitor unit issues, to the compute unit, a suspension request for suspending processing related to data writing,

the compute unit having received an instruction from the application program reads data from a storage device, encrypts the read data using the accelerator, and, when having received the suspension request, suspends issuance of an instruction to write the encrypted data into the storage device; and

a virtual machine of the compute unit issues command information for setting, to the accelerator, key data used by the virtual machine specified by the application program provided in the virtual machine for the application program to encrypt data using the accelerator,

when having detected that key data set by the command information issued from the virtual machine is not the key data permitted to use, the monitor unit issues, to the compute unit, a suspension request for suspending processing related to writing of data by the virtual machine that has issued the command information, and

when having received the suspension request for suspending processing related to writing of data by the virtual machine, the compute unit suspends issuance of an instruction for writing of data by the virtual machine to the storage device.

Assignments (2)
CHANGE OF NAME Recorded Sep 27, 2024
From: HITACHI, LTD.
To: HITACHI VANTARA, LTD.
Reel/Frame 069067/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2022
From: HIRAI, TATSUYA; SAITO, HIDEO
To: HITACHI, LTD.
Reel/Frame 061021/0398 →
Priority Claims (1)
JP 2022-004239 · Jan 14, 2022 · national
Continuity (1)
Related Publication 20230229600A1 · Jul 20, 2023
References Cited (10)
US 10389740B2 · Langton · 2019 [cited by applicant]
US 20160365150A1 · Tokiwa · 2016 [cited by examiner]
US 20180157600A1 · Lesartre · 2018 [cited by examiner]
US 20200159657A1 · Kida · 2020 [cited by examiner]
US 20200326889A1 · Norman · 2020 [cited by examiner]
US 20210357152A1 · Moriyasu · 2021 [cited by examiner]
US 20230152999A1 · Hyun · 2023 [cited by examiner]
JP 2019021131A · 2019 [cited by applicant]
WO 2014070499A1 · 2014 [cited by applicant]
Japanese Office Action issued on Oct. 22, 2024 for Japanese Patent Application No. 2022-004239. [cited by applicant]