IP Library Granted Patent US 11,914,736
Granted Patent B2
US 11,914,736 · App. 17/961,981 · Granted Feb 27, 2024

Encryption for a distributed filesystem

Inventors: Maor Ben Dayan (Tel Aviv, IL); Omri Palmon (Tel Aviv, IL); Liran Zvibel (Tel Aviv, IL); Kanael Arditti (Tel Aviv, IL); Ori Peleg (Tel Aviv, IL)
Assignee: Weka.IO Ltd.
G06F21/6218G06F16/182G06F21/602H04L9/0838H04L9/0841H04L9/0891H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,914,736
App. No.
17/961,981
Granted
Feb 27, 2024
Kind
B2
Abstract

A computing device comprising a frontend and a backend is operably coupled to a plurality of storage devices. The backend comprises a plurality of buckets. Each bucket is operable to build a failure-protected stripe that spans two or more of the plurality of the storage devices. The frontend is operable to encrypt data as it enters the plurality of storage devices and decrypt data as it leaves the plurality of storage devices.

Claims (30)

1. A system comprises a cluster of computing devices, and wherein the cluster of computing devices is associated with a cluster key comprising:

a frontend to encrypt data as it enters the system; and a backend to build failure-protected stripes in a plurality of storage devices, wherein the frontend and backend are networked devices that run a virtual frontend and virtual backend, wherein:

the plurality of storage devices are distributed such that at most an allowed number of storage devices are within any particular node of a plurality of nodes; and

the frontend registers a long-term key with a leader of the cluster when the system joins the cluster of computing devices and wherein prior to a transfer of the data, a session key is negotiated using an ephemeral key pair signed with the long-term key.

2. The system of claim 1 , wherein the frontend is to decrypt data as it leaves the system.

3. The system of claim 1 , wherein the frontend is to encrypt the data according to a file key.

4. The system of claim 3 , wherein the file key is rotated when a file is copied.

5. The system of claim 3 , wherein all failure-protected stripes built by a plurality of buckets in the backend are associated with a filesystem key.

6. The system of claim 5 , wherein the file key is encrypted by the filesystem key.

7. The system of claim 5 , wherein the file key is re-encrypted when the filesystem key is rotated.

8. The system of claim 1 , wherein the system comprises a cluster of computing devices, and wherein the cluster of computing devices is associated with a cluster key.

9. The system of claim 8 , wherein the frontend registers a long-term key with a leader of the cluster when the system joins the cluster of computing devices.

10. The system of claim 9 , wherein prior to a transfer of the data, a session key is negotiated using an ephemeral key pair signed with the long-term key.

11. A method comprises a cluster of computing devices, and wherein the cluster of computing devices is associated with a cluster key comprising:

encrypting data, via a frontend, as it enters a computing device;

building, via a backend, failure-protected stripes in a plurality of storage devices, wherein the frontend and backend are networked devices that run a virtual frontend and virtual backend; and

distributing the plurality of storage devices such that at most an allowed number of storage devices are within any particular node of a plurality of nodes; and

the frontend registers a long-term key with a leader of the cluster when the system joins the cluster of computing devices and wherein prior to a transfer of the data, a session key is negotiated using an ephemeral key pair signed with the long-term key.

12. The method of claim 11 , wherein the method comprises:

decrypting data, via the frontend, as it leaves the computing device.

13. The method of claim 11 , wherein the frontend encrypts the data according to a file key.

14. The method of claim 13 , wherein the file key is rotated when a file is copied.

15. The method of claim 13 , wherein all failure-protected stripes built by a plurality of buckets in the backend are associated with a filesystem key.

16. The method of claim 15 , wherein the file key is encrypted by the filesystem key.

17. The method of claim 15 , wherein the file key is re-encrypted when the filesystem key is rotated.

18. The method of claim 11 , wherein a cluster of computing devices is associated with a cluster key.

19. The method of claim 18 , wherein the method comprises:

registering a long-term key with a leader of the cluster when the computing device joins the cluster of computing devices.

20. The method of claim 19 , wherein the method comprises:

negotiating a session key, prior to a transfer of the data, using an ephemeral key pair signed with the long-term key.

Continuity (4)
Continuation 17317086 · May 11, 2021
Continuation 16274541 · Feb 13, 2019
Provisional Application 62682198 · Jun 8, 2018
Related Publication 20230033729A1 · Feb 2, 2023