IP Library › Granted Patent US 10,503,917
Granted Patent B2
US 10,503,917 · App. 16/186,893 · Granted Dec 10, 2019

Performing operations on intelligent storage with hardened interfaces

Inventors: Gregory B. Roth (Seattle, WA); Eric Jason Brandwine (Haymarket, VA)
Assignee: Amazon Technologies, Inc.
G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,503,917
App. No.
16/186,893
Granted
Dec 10, 2019
Kind
B2
Abstract

A storage device can include processing and cryptographic capability enabling the device to function as a hardware security module (HSM). This includes the ability to encrypt and decrypt data using a cryptographic key, as well as to perform processing using such a key, independent of whether that processing involves data stored on the device. An internal key can be provided to the drive, whether provided before customer software access or received wrapped in another key, etc. That key enables the device to perform secure processing on behalf of a user or entity, where that key is not exposed to other components in the network or environment. A key may have specified tasks that can be performed using that key, and can be discarded after use. In some embodiments, firmware is provided that can cause a storage device to function as an HSM and/or processing device with cryptographic capability.

Claims (58)

1. A storage device, comprising:

at least one non-transitory computer-readable storage medium for storing data;

at least one processor configured to perform cryptographic processing; and

memory including instructions that, when executed by the at least one processor, cause the storage device to:

operate in a key provisioning mode, during which access to at least a designated portion of the storage device is prevented while generating an internal key;

receive, at the storage device, data encrypted under the internal key;

determine, using the at least one processor, the internal key from a plurality of internal keys stored by the storage device; and

decrypt, in the storage device, at least a portion of the data using the internal key.

2. The storage device of claim 1 , wherein the instructions when executed further cause the storage device to:

prevent access to at least one of data or other keys stored on the storage device while the storage device is operating in the key provisioning mode.

3. The storage device of claim 1 , wherein the instructions when executed further cause the storage device to:

delete any previously-stored internal keys upon operating in the key provisioning mode.

4. The storage device of claim 1 , wherein the instructions when executed further cause the storage device to:

prevent access to the internal key by a provider of the storage device.

5. The storage device of claim 1 , wherein the instructions when executed further cause the storage device to:

receive a request to provision a new internal key; and

cause the storage device to operate in the key provisioning mode before at least one of receiving, reading, or decrypting the new internal key.

6. The storage device of claim 1 , wherein the instructions when executed further cause the storage device to:

perform at least one operation on the portion of the data; and

determine that each operation of the at least one operation corresponds to a respective allowable task, associated with the internal key, before performing the at least one operation.

7. A computer-implemented method, comprising:

causing a storage device of a resource environment to operate in a key provisioning mode wherein access to at least a designated portion of the storage device is prevented;

receiving, at the storage device of a resource environment, an internal key during the key provisioning mode, the storage device including at least one processor configured to perform cryptographic processing;

decrypting the internal key; and

causing the internal key to be securely stored in the storage device.

8. The computer-implemented method of claim 7 , further comprising:

preventing a provider of the storage device from having access to the internal key stored by the storage device.

9. The computer-implemented method of claim 7 , further comprising:

receiving a request associated with data encrypted under the internal key;

determining, in the storage device, the internal key from a plurality of internal keys stored by the storage device;

decrypting the data using the internal key;

performing at least one operation, associated with the request, on the data using at least one processor of the storage device; and

causing a result of the at least one operation to be transmitted to a destination associated with the request.

10. The computer-implemented method of claim 9 , further comprising:

transferring, as part of the at least one operation, at least a portion of the data between the storage device and at least one additional storage device in the resource environment.

11. The computer-implemented method of claim 9 , further comprising:

decrypting the data included with the request; and

returning the data, after the decrypting, without storing the data or causing the data to be available outside cryptographic hardware of the storage device.

12. The computer-implemented method of claim 7 , further comprising:

enabling at least one operation to be performed on the storage device;

determining the at least one operation is based at least in part upon the internal key, the at least one operation including at least one of a de-duplication operation, a replication operation, or a compression operation.

13. The computer-implemented method of claim 7 , wherein:

decrypting the internal key comprises decrypting the internal key using an external key, the internal key is exportable when encrypted, and once decrypted, unexportable from the storage device.

14. The computer-implemented method of claim 7 , further comprising:

causing the storage device to operate in the key provisioning mode for decrypting and storing the internal key; and

causing the storage device to operate in an operational mode for performing operations on behalf of the customer.

15. A computer-implemented method, comprising:

causing a storage device of a resource environment to operate in a key provisioning mode wherein access to at least a designated portion of the storage device is prevented;

receiving, at the storage device of a resource environment, data encrypted under an internal key during the key provisioning mode, the storage device including at least one processor configured to perform cryptographic processing; and

decrypting, in the storage device, the data using the internal key.

16. The computer-implemented method of claim 15 , further comprising:

causing the storage device to operate in an operational mode wherein the storage device is unable to receive new internal keys.

17. The computer-implemented method of claim 15 , wherein the internal key is exportable when encrypted, and once decrypted, unexportable from the storage device.

18. The computer-implemented method of claim 15 , further comprising:

performing, using the data, at least one operation, the at least one operation includes aggregating the data, after the decrypting, into a result without storing the data on the storage device or making the data accessible outside the storage device.

19. The computer-implemented method of claim 15 , wherein a provider of the storage device is prevented from having access to the internal key or the data after decrypting, in the storage device.

20. The computer-implemented method of claim 18 , further comprising:

encrypting the result, using at least one of the internal key or a second key, before the result is exported.

Continuity (2)
Continuation 14673350 · Mar 30, 2015
Related Publication 20190080099A1 · Mar 14, 2019
Cited By (4)
US 12,634,213 US 12,634,350 US 12,699,639 US 12,749,032