Centrally managed remote storage encryption and decryption
Techniques are disclosed for centrally managing remote storage encryption and decryption. In some embodiments, to access an encrypted volume on a storage device connected to a computing device, a virtual private network (VPN) client authenticates a user of the computing device to a VPN. After authenticating the user and establishing a VPN connection, the VPN client launches a key management system (KMS) client that authenticates the user and requests an encryption key from a KMS server based on the user, a volume identifier (ID) of the encrypted volume, and a storage device ID of the storage device. The KMS server verifies that the user is allowed to access the encrypted volume having the volume ID, and that the encrypted volume is stored on the storage device having the storage device ID. Upon verification, the KMS server transmits the encryption key to the KMS client for decrypting the encrypted volume.
1 . A computer-implemented method for decrypting an encrypted volume, the method comprising:
identifying an encrypted volume stored on a storage device that is attached to a computing device, wherein the computing device is remote from a premises of an entity;
authenticating a user to a virtual private network that extends an on-premises network at the premises of the entity;
requesting, from a server via the virtual private network, an encryption key based on the user, an identifier (ID) associated with the encrypted volume, and an ID associated with the storage device; and
decrypting the encrypted volume based on the encryption key.
2 . The computer-implemented method of claim 1 ,
wherein the user is authenticated to the virtual private network via a VPN client running on the computing device, and further comprising further authenticating the user to a client application on the computing device prior to the client application requesting the encryption key from the server.
3 . The computer-implemented method of claim 1 , wherein the server stores one or more associations between each of one or more encryption keys and a corresponding user, a data set management group, a volume ID of an encrypted volume, and a storage device ID of a storage device.
4 . The computer-implemented method of claim 1 , wherein the encrypted volume stores a data set, and the user is assigned to a data set management group associated with the encrypted volume.
5 . The computer-implemented method of claim 1 , further comprising mounting the encrypted volume to create a mounted volume, wherein the mounted volume is decrypted.
6 . The computer-implemented method of claim 5 , further comprising, in response to one or more modifications to a data set stored on the mounted volume, synchronizing the data set with one or more data sets stored on one or more other volumes located on the premises of the entity.
7 . The computer-implemented method of claim 5 , further comprising unmounting the mounted volume in response to determining that at least one of the user is invalid or the user is not assigned to a data set management group associated with the mounted volume.
8 . The computer-implemented method of claim 5 , further comprising unmounting the mounted volume subsequent to termination of a virtual private network (VPN) connection with the on-premises network at the premises of the entity.
9 . The computer-implemented method of claim 1 , wherein the storage device comprises an external hard drive attached to a computing device.
10 . One or more non-transitory computer-readable storage media including instructions that, when executed by at least one processor, cause the at least one processor to perform steps comprising:
identifying an encrypted volume stored on a storage device that is attached to a computing device, wherein the computing device is remote from a premises of an entity;
authenticating a user to a virtual private network that extends an on-premises network at the premises of the entity;
requesting, from a server via the virtual private network, an encryption key based on the user, an identifier (ID) associated with the encrypted volume, and an ID associated with the storage device; and
decrypting the encrypted volume based on the encryption key.
11 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the step of authenticating the user to a client application on the computing device that requests the encryption key from the server.
12 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the server stores one or more associations between each of one or more encryption keys and a corresponding user, a data set management group, a volume ID of an encrypted volume, and a storage device ID of a storage device.
13 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the encrypted volume stores a data set, and the user is assigned to a data set management group associated with the encrypted volume.
14 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the step of mounting the encrypted volume to create a mounted volume, wherein the mounted volume is decrypted.
15 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the step of, in response to one or more modifications to a data set stored on the mounted volume, synchronizing the data set with one or more data sets stored on one or more other volumes.
16 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the step of unmounting the mounted volume in response to determining that at least one of the user is invalid or the user is not assigned to a data set management group associated with the mounted volume.
17 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the step of unmounting the mounted volume subsequent to termination of a virtual private network (VPN) connection between the computing device and the on-premises network.
18 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the storage device comprises an external hard drive attached to the computing device.
19 . A system, comprising:
one or more memories storing instructions; and
one or more processors that are coupled to the one or more memories and, when executing the instructions, are configured to:
identify an encrypted volume stored on a storage device that is attached to a computing device, wherein the computing device is remote from a premises of an entity,
authenticate a user to a virtual private network that extends an on-premises network at the premises of the entity,
request, from a server via the virtual private network, an encryption key based on the user, an identifier (ID) associated with the encrypted volume, and an ID associated with the storage device, and
decrypt the encrypted volume based on the encryption key.
20 . The system of claim 19 , wherein the one or more processors, when executing the instructions, are further configured to authenticate the user to a client application on the computing device that requests the encryption key from the server.