IP Library Patent Application 18356836
Patent Application
App. No. 18/356,836

CRYPTOGRAPHIC AGILITY FOR A VIRTUAL STORAGE AREA NETWORK (VSAN)

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/356,836
Abstract

The disclosure provides an approach for providing cryptographic agility for virtualized data storage. Embodiments include determining, by a hypervisor running on a host machine, one or more attributes of a virtual machine (VM) running on top of the hypervisor. Embodiments include sending, by the hypervisor, to a cryptographic provider component, a request to perform cryptographic functionality with respect to one or more virtual disks associated with the VM, wherein the request comprises the one or more attributes of the VM. Embodiments include selecting, by the cryptographic provider component, based on the one or more attributes of the VM and one or more cryptographic policies, one or more cryptographic techniques for handling the request from a set of possible cryptographic techniques. Embodiments include encrypting the one or more virtual disks in a virtual storage area network (VSAN) based on the selected one or more cryptographic techniques.

Claims (46)

1 . A method of cryptographic agility for virtualized data storage, comprising:

determining, by a hypervisor running on a host machine, one or more attributes of a virtual machine (VM) running on top of the hypervisor;

sending, by the hypervisor, to a cryptographic provider component, a request to perform cryptographic functionality with respect to one or more virtual disks associated with the VM, wherein the request comprises the one or more attributes of the VM;

selecting, by the cryptographic provider component, based on the one or more attributes of the VM and one or more cryptographic policies, one or more cryptographic techniques for handling the request from a set of possible cryptographic techniques; and

encrypting the one or more virtual disks in a virtual storage area network (VSAN) based on the selected one or more cryptographic techniques.

2 . The method of claim 1 , wherein the determining of the one or more attributes of the VM is based on one or more tags associated with the VM.

3 . The method of claim 1 , wherein:

the one or more virtual disks comprise a first virtual disk and a second virtual disk; and

the selecting of the one or more cryptographic techniques comprises:

selecting a first cryptographic technique for the first virtual disk based on the one or more attributes of the VM and one or more first attributes of the first virtual disk; and

selecting a second cryptographic technique for the second virtual disk based on the one or more attributes of the VM and one or more second attributes of the second virtual disk.

4 . The method of claim 3 , wherein the first cryptographic technique has a higher level of security than the second cryptographic technique.

5 . The method of claim 4 , wherein the one or more first attributes of the first virtual disk indicate that the first virtual disk is a primary storage disk of the VM and the one or more second attributes of the second virtual disk indicate that the second virtual disk is a scratch or paging disk.

6 . The method of claim 3 , wherein the first virtual disk and the second virtual disk are different disks in a redundant array of independent disks (RAID) configuration.

7 . The method of claim 3 , wherein the selecting of the second cryptographic technique for the second virtual disk based on the one or more attributes of the VM and the one or more second attributes of the second virtual disk comprises determining that the one or more second attributes of the second virtual disk override the one or more attributes of the VM based on a cryptographic policy of the one or more cryptographic policies.

8 . The method of claim 1 , further comprising:

determining, by the hypervisor, that a given virtual disk of the one or more virtual disks is to be moved or replicated to a different geographic location; and

selecting, by the cryptographic provider component, a different cryptographic technique for the given virtual disk based on the different geographic location.

9 . The method of claim 1 , wherein the selecting of the one or more cryptographic techniques is further based on one or more resource constraints associated with one or more devices related to the one or more virtual disks.

10 . The method of claim 1 , wherein the selecting of the one or more cryptographic techniques is further based on one or more geographic locations associated with the one or more virtual disks.

11 . A system for cryptographic agility for virtualized data storage, comprising:

at least one memory; and

at least one processor coupled to the at least one memory, the at least one processor and the at least one memory configured to:

determine, by a hypervisor running on a host machine, one or more attributes of a virtual machine (VM) running on top of the hypervisor;

send, by the hypervisor, to a cryptographic provider component, a request to perform cryptographic functionality with respect to one or more virtual disks associated with the VM, wherein the request comprises the one or more attributes of the VM;

select, by the cryptographic provider component, based on the one or more attributes of the VM and one or more cryptographic policies, one or more cryptographic techniques for handling the request from a set of possible cryptographic techniques; and

encrypt the one or more virtual disks in a virtual storage area network (VSAN) based on the selected one or more cryptographic techniques.

12 . The system of claim 11 , wherein the determining of the one or more attributes of the VM is based on one or more tags associated with the VM.

13 . The system of claim 11 , wherein:

the one or more virtual disks comprise a first virtual disk and a second virtual disk; and

the selecting of the one or more cryptographic techniques comprises:

selecting a first cryptographic technique for the first virtual disk based on the one or more attributes of the VM and one or more first attributes of the first virtual disk; and

selecting a second cryptographic technique for the second virtual disk based on the one or more attributes of the VM and one or more second attributes of the second virtual disk.

14 . The system of claim 13 , wherein the first cryptographic technique has a higher level of security than the second cryptographic technique.

15 . The system of claim 14 , wherein the one or more first attributes of the first virtual disk indicate that the first virtual disk is a primary storage disk of the VM and the one or more second attributes of the second virtual disk indicate that the second virtual disk is a scratch or paging disk.

16 . The system of claim 13 , wherein the first virtual disk and the second virtual disk are different disks in a redundant array of independent disks (RAID) configuration.

17 . The system of claim 13 , wherein the selecting of the second cryptographic technique for the second virtual disk based on the one or more attributes of the VM and the one or more second attributes of the second virtual disk comprises determining that the one or more second attributes of the second virtual disk override the one or more attributes of the VM based on a cryptographic policy of the one or more cryptographic policies.

18 . The system of claim 11 , wherein the at least one processor and the at least one memory are further configured to:

determine, by the hypervisor, that a given virtual disk of the one or more virtual disks is to be moved or replicated to a different geographic location; and

select, by the cryptographic provider component, a different cryptographic technique for the given virtual disk based on the different geographic location.

19 . The system of claim 11 , wherein the selecting of the one or more cryptographic techniques is further based on one or more resource constraints associated with one or more devices related to the one or more virtual disks.

20 . A non-transitory computer readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

determine, by a hypervisor running on a host machine, one or more attributes of a virtual machine (VM) running on top of the hypervisor;

send, by the hypervisor, to a cryptographic provider component, a request to perform cryptographic functionality with respect to one or more virtual disks associated with the VM, wherein the request comprises the one or more attributes of the VM;

select, by the cryptographic provider component, based on the one or more attributes of the VM and one or more cryptographic policies, one or more cryptographic techniques for handling the request from a set of possible cryptographic techniques; and

encrypt the one or more virtual disks in a virtual storage area network (VSAN) based on the selected one or more cryptographic techniques.

Assignments (2)
CHANGE OF NAME Recorded May 8, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067355/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2023
From: BEVERIDGE, DANIEL JAMES; HUNTLEY, SEAN; OTT, DAVID
To: VMWARE, INC.
Reel/Frame 064449/0010 →