IP Library Granted Patent US 8,687,814
Granted Patent B2
US 8,687,814 · App. 13/474,936 · Granted Apr 1, 2014

Securing encrypted virtual hard disks

Inventors: Joseph Harry Nord (Lighthouse Point, FL); Timothy Gaylor (Plantation, FL); Benjamin Elliot Tucker (Parkland, FL)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,687,814
App. No.
13/474,936
Filed
May 18, 2012
Granted
Apr 1, 2014
Kind
B2
Art Unit
2496
USPC
380/286
Abstract

Securing encrypted virtual hard disks may include a variety of processes. In one example, a virtual hard disk is created for a user and encrypted with a volume key, and the volume key placed in an administrator header. The administrator header may be encrypted with a protection key, the protection key created from a user identifier corresponding to the user, a volume identifier corresponding to the virtual hard disk, and two cryptographic secrets. The protection key may then destroyed after encrypting the administrator header and therefore, might never leave the encryption engine. The two cryptographic secrets may be stored in separate storage locations, one accessible to the user and the other accessible to administrators. Accordingly, the protection key might never transmitted or can be intercepted, and no single entity may be compromised to gain access to all of the information needed to recreate the protection key.

Claims (46)

1. A method comprising:

determining, by a computing device, a first encryption secret and a second encryption secret;

generating, by the computing device, an encryption key based on an encryption algorithm using the first encryption secret and the second encryption secret;

encrypting, by the computing device, a header of a data storage using the encryption key, wherein the encrypted header of the data storage stores a volume key used to encrypt at least a payload of the data storage, wherein the volume key is different from the encryption key;

deleting, by the computing device, the encryption key after encrypting the header; and

storing, by the computing device, the first encryption secret to a first storage location and the second encryption secret to a second storage location, wherein the first storage location and the second storage location correspond to different network locations.

2. The method of claim 1 , wherein the encryption key is deleted without allowing any transmission of the encryption key.

3. The method of claim 1 , wherein generating the encryption key based on the encryption algorithm further uses a volume identifier of the data storage.

4. The method of claim 1 , further comprising:

encrypting a second header of the data storage, different from the header encrypted using the encryption key, using a key different from the encryption key, wherein the second header stores the volume key.

5. The method of claim 4 , further comprising:

determining that the second header has been deleted;

in response to determining that the second header has been deleted, determining whether a user associated with the data storage has been authenticated; and

in response to determining that the user associated with the data storage has been authenticated, re-generating the second header.

6. The method of claim 4 , further comprising:

determining that at least one predefined condition has been satisfied; and

in response to determining that the at least one predefined condition has been satisfied, transmitting a command to delete the user header without deleting the header encrypted using the encryption key.

7. The method of claim 6 , wherein the at least one predefined condition includes expiration of a time period.

8. The method of claim 6 , wherein the at least one predefined condition includes a number of failed authentication attempts.

9. A method comprising:

receiving, by a computing device, a request to decrypt at least a payload of a data storage encrypted using a first key;

retrieving, by the computing device, a first encryption secret from a first network location and a second encryption secret from a second network location;

generating, by the computing device, a second key using the first and second encryption secrets, the second key being different from the first key;

decrypting, by the computing device, a header of the data storage using the second key, wherein the header of the data storage stores the first key;

retrieving, by the computing device, the first key from the decrypted header; and

decrypting, by the computing device, the at least a payload of the data storage.

10. The method of claim 9 , wherein the second key is further generated using at least one of: a volume identifier of the data storage and a user identifier of a user associated with the data storage.

11. The method of claim 9 , further comprising deleting the generated second key after decrypting the header of the data storage and without any transmission of the generated second key.

12. The method of claim 9 , wherein the first network location is a user storage location and the second network location is an administrator storage location.

13. The method of claim 9 , wherein the data storage is a virtual hard disk mountable to a user's computing device.

14. The method of claim 9 , wherein generating the second key is further performed using a cryptographic sale stored in a clear text header of the data storage.

15. A non-transitory computer readable medium storing computer readable instructions that, when executed, cause the apparatus to:

determine a first encryption secret and a second encryption secret;

generate an encryption key based on an encryption algorithm using the first encryption secret and the second encryption secret;

encrypt a header of a data storage using the encryption key, wherein the encrypted header of the data storage stores a volume key used to encrypt at least a payload of the data storage, and wherein the volume key is different from the encryption key;

delete the encryption key after encrypting the header; and

store the first encryption secret to a first storage location and the second encryption secret to a second storage location, wherein the first storage location and the second storage location correspond to different network locations.

16. The non-transitory computer readable medium of claim 15 , wherein the encryption key is deleted prior to any transmission of the encryption key.

17. The non-transitory computer readable medium of claim 15 , wherein generating the encryption key based on the encryption algorithm further uses a volume identifier of the data storage.

18. The non-transitory computer readable medium of claim 15 , further comprising instructions for:

encrypting a second header of the data storage, different from the header encrypted using the encryption key, using a key different from the encryption key, wherein the second header also stores the volume key.

19. The non-transitory computer readable medium of claim 18 , further comprising instructions for:

determining that the second header has been deleted;

in response to determining that the second header has been deleted, determining whether a user associated with the data storage has been authenticated; and

in response to determining that the user associated with the data storage has been authenticated, re-generating the second header.

20. The non-transitory computer readable medium of claim 19 , wherein the data storage is a virtual storage disk mounted to a computing device of the user and wherein the second header is re-generated to the user's computing device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2012
From: NORD, JOSEPH HARRY; GAYLOR, TIMOTHY; TUCKER, BENJAMIN ELLIOT
To: CITRIX SYSTEMS, INC.
Reel/Frame 028729/0044 →
Continuity (2)
Provisional Application 61488615 · May 20, 2011
Related Publication 20120297206A1 · Nov 22, 2012