IP Library Granted Patent US 12,248,596
Granted Patent B2
US 12,248,596 · App. 18/411,699 · Granted Mar 11, 2025

Encryption for a distributed filesystem

Inventors: Maor Ben Dayan (Tel Aviv, IL); Omri Palmon (Tel Aviv, IL); Liran Zvibel (Tel Aviv, IL); Kanael Arditti (Tel Aviv, IL); Ori Peleg (Tel Aviv, IL)
Assignee: Weka.IO Ltd.
G06F21/6218G06F16/182G06F21/602H04L9/0838H04L9/0841H04L9/0891H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,596
App. No.
18/411,699
Granted
Mar 11, 2025
Kind
B2
Abstract

A computing device comprising a frontend and a backend is operably coupled to a plurality of storage devices. The backend comprises a plurality of buckets. Each bucket is operable to build a failure-protected stipe that spans two or more of the plurality of the storage devices. The frontend is operable to encrypt data as it enters the plurality of storage devices and decrypt data as it leaves the plurality of storage devices.

Claims (51)

1. A system comprising:

a processor operable to configure a plurality of failure-protected stripes in a plurality of storage devices, wherein:

the plurality of storage devices are distributed such that at most an allowed number of storage devices are within any particular node of a plurality of nodes,

the processor is operable to encrypt data according to a file key,

the file key is rotated when a file is copied, and

all failure-protected stripes built by a plurality of buckets are associated with a filesystem key.

2. The system of claim 1 , wherein the processor is operable to decrypt data as it leaves the system.

3. The system of claim 1 , wherein the file key is encrypted by the filesystem key.

4. The system of claim 1 , wherein the file key is re-encrypted when the filesystem key is rotated.

5. The system of claim 1 , wherein the system comprises a cluster of computing devices, and wherein the cluster of computing devices is associated with a cluster key.

6. The system of claim 5 , wherein the processor registers a long-term key with a leader of the cluster when the system joins the cluster of computing devices.

7. The system of claim 6 , wherein prior to a transfer of the data, a session key is negotiated using an ephemeral key pair signed with the long-term key.

8. A method comprising:

building, via a processor, a plurality of failure-protected stripes in a plurality of storage devices;

distributing the plurality of storage devices such that at most an allowed number of storage devices are within any particular node of a plurality of nodes

encrypting data, via the processor, according to a file key;

rotating the file key when a file is copied; and

associating all failure-protected stripes, built by a plurality of buckets, with a filesystem key.

9. The method of claim 8 , wherein the method comprises decrypting data, via the processor, as it leaves a storage device.

10. The method of claim 8 , wherein the file key is encrypted by the filesystem key.

11. The method of claim 8 , wherein the file key is re-encrypted when the filesystem key is rotated.

12. The method of claim 8 , wherein a cluster of computing devices is associated with a cluster key.

13. The method of claim 12 , wherein the method comprises:

registering a long-term key with a leader of the cluster when the computing device joins the cluster of computing devices.

14. The method of claim 13 , wherein the method comprises:

negotiating a session key, prior to a transfer of the data, using an ephemeral key pair signed with the long-term key.

15. A system comprising:

a processor operable to configure a plurality of failure-protected stripes in a plurality of storage devices; and

a cluster of computing devices associated with a cluster key, wherein:

the plurality of storage devices are distributed such that at most an allowed number of storage devices are within any particular node of a plurality of nodes, and

the processor is configured to register a long-term key with a leader of the cluster when the system joins the cluster of computing devices.

16. The system of claim 15 , wherein the processor is operable to decrypt data as it leaves the system.

17. The system of claim 15 , wherein the processor is operable to encrypt data according to a file key.

18. The system of claim 17 , wherein the file key is rotated when a file is copied.

19. The system of claim 17 , wherein all failure-protected stripes built by a plurality of buckets are associated with a filesystem key.

20. The system of claim 19 , wherein the file key is encrypted by the filesystem key.

21. The system of claim 19 , wherein the file key is re-encrypted when the filesystem key is rotated.

22. The system of claim 15 , wherein prior to a transfer of the data, a session key is negotiated using an ephemeral key pair signed with the long-term key.

23. A method comprising:

building, via a processor, a plurality of failure-protected stripes in a plurality of storage devices;

distributing the plurality of storage devices such that at most an allowed number of storage devices are within any particular node of a plurality of nodes;

associating a cluster of computing devices with a cluster key; and

registering a long-term key with a leader of the cluster when the computing device joins the cluster of computing devices.

24. The method of claim 23 , wherein the method comprises decrypting data, via the processor, as it leaves a storage device.

25. The method of claim 23 , wherein the processor encrypts the data according to a file key.

26. The method of claim 25 , wherein the file key is rotated when a file is copied.

27. The method of claim 25 , wherein all failure-protected stripes built by a plurality of buckets in the processor are associated with a filesystem key.

28. The method of claim 27 , wherein the file key is encrypted by the filesystem key.

29. The method of claim 27 , wherein the file key is re-encrypted when the filesystem key is rotated.

30. The method of claim 23 , wherein the method comprises:

negotiating a session key, prior to a transfer of the data, using an ephemeral key pair signed with the long-term key.

Continuity (5)
Continuation 17961981 · Oct 7, 2022
Continuation 17317086 · May 11, 2021
Continuation 16274541 · Feb 13, 2019
Provisional Application 62682198 · Jun 8, 2018
Related Publication 20250013768A1 · Jan 9, 2025
References Cited (85)
US 6487636B1 · Dolphin · 2002 [cited by examiner]
US 7200747B2 · Riedel · 2007 [cited by examiner]
US 7447839B2 · Uppala · 2008 [cited by examiner]
US 7681072B1 · Gibson · 2010 [cited by examiner]
US 7793146B1 · Gibson · 2010 [cited by examiner]
US 8601600B1 · Shankar · 2013 [cited by examiner]
US 8645749B2 · Reche · 2014 [cited by applicant]
US 8650435B2 · Vishnu · 2014 [cited by examiner]
US 8918478B2 · Ozzie · 2014 [cited by examiner]
US 9087012B1 · Hayes · 2015 [cited by examiner]
US 9178698B1 · Jarjur · 2015 [cited by examiner]
US 9448887B1 · Ben Dayan · 2016 [cited by examiner]
US 9645761B1 · Ben Dayan · 2017 [cited by examiner]
US 9807077B2 · Gounares · 2017 [cited by examiner]
US 10326744B1 · Nossik · 2019 [cited by examiner]
US 10397189B1 · Hashmi · 2019 [cited by examiner]
US 10453547B2 · Mehta · 2019 [cited by examiner]
US 11042661B2 · Ben Dayan · 2021 [cited by examiner]
US 11175986B1 · Best · 2021 [cited by examiner]
US 11269727B2 · Ben Dayan · 2022 [cited by examiner]
US 20080126813A1 · Kawakami · 2008 [cited by examiner]
US 20100199125A1 · Reche · 2010 [cited by examiner]
US 20110145593A1 · Auradkar · 2011 [cited by examiner]
US 20110225428A1 · Stufflebeam, Jr. · 2011 [cited by examiner]
US 20120221854A1 · Orsini · 2012 [cited by examiner]
US 20120221920A1 · Blaum · 2012 [cited by examiner]
US 20120221926A1 · Blaum · 2012 [cited by examiner]
US 20130205181A1 · Blaum · 2013 [cited by examiner]
US 20130212373A1 · Dodgson · 2013 [cited by examiner]
US 20140143543A1 · Aikas · 2014 [cited by examiner]
US 20140229737A1 · Roth · 2014 [cited by examiner]
US 20140279557A1 · Abou-Nasr · 2014 [cited by examiner]
US 20140281801A1 · Meir · 2014 [cited by examiner]
US 20150347765A1 · Hankins, Jr. · 2015 [cited by examiner]
US 20150355971A1 · Becker-Szendy · 2015 [cited by examiner]
US 20160246677A1 · Sangamkar · 2016 [cited by examiner]
US 20170052847A1 · Ben Dayan · 2017 [cited by examiner]
US 20170090776A1 · Kowles · 2017 [cited by examiner]
US 20170134477A1 · Ben Dayan · 2017 [cited by examiner]
US 20170220260A1 · Ben Dayan · 2017 [cited by examiner]
US 20170249472A1 · Levy · 2017 [cited by examiner]
US 20170272100A1 · Yanovsky · 2017 [cited by examiner]
US 20180083929A1 · Roth · 2018 [cited by examiner]
US 20190007208A1 · Surla · 2019 [cited by examiner]
US 20190042591A1 · Ben Dayan · 2019 [cited by examiner]
US 20190095296A1 · McMurchie · 2019 [cited by examiner]
US 20190121578A1 · Ben Dayan · 2019 [cited by examiner]
US 20190146672A1 · Ben Dayan · 2019 [cited by examiner]
US 20190146713A1 · Ben Dayan · 2019 [cited by examiner]
US 20190146718A1 · Ben Dayan · 2019 [cited by examiner]
US 20190146865A1 · Ben Dayan · 2019 [cited by examiner]
US 20190146879A1 · Ben Dayan · 2019 [cited by examiner]
US 20190146891A1 · Ben Dayan · 2019 [cited by examiner]
US 20190147066A1 · Ben Dayan · 2019 [cited by examiner]
US 20190147069A1 · Ben Dayan · 2019 [cited by examiner]
US 20190377638A1 · Ben Dayan · 2019 [cited by examiner]
US 20190377892A1 · Ben Dayan · 2019 [cited by examiner]
US 20190384497A1 · Ben Dayan · 2019 [cited by examiner]
US 20190385271A1 · Ben Dayan · 2019 [cited by examiner]
US 20200004426A1 · Ben Dayan · 2020 [cited by examiner]
US 20200004723A1 · Ben Dayan · 2020 [cited by examiner]
US 20200004725A1 · Ben Dayan · 2020 [cited by examiner]
US 20200026612A1 · Ben Dayan · 2020 [cited by examiner]
US 20200026687A1 · Ben Dayan · 2020 [cited by examiner]
US 20200034044A1 · Ben Dayan · 2020 [cited by examiner]
US 20200057566A1 · Ben Dayan · 2020 [cited by examiner]
US 20210294907A1 · Ben Dayan · 2021 [cited by examiner]
CN 104601579A · 2015 [cited by applicant]
CN 106815528A · 2017 [cited by applicant]
CN 107615730A · 2018 [cited by applicant]
CN 107924351A · 2018 [cited by applicant]
CN 107949842A · 2018 [cited by applicant]
JP 1997179768A · 1997 [cited by applicant]
JP 2008077366A · 2008 [cited by applicant]
JP 2014529238A · 2014 [cited by applicant]
JP 2016057811A · 2016 [cited by applicant]
WO 2013028235A2 · 2013 [cited by applicant]
WO 2017007945A1 · 2017 [cited by applicant]
WO 2019234501A2 · 2019 [cited by applicant]
Int'l Search Report and Written Opinion Appln No. PCT/IB2016/001177 mailed Dec. 2, 2016. [cited by applicant]
Int'l Search Report and Written Opinion Appln No. PCT/IB2019/000686 mailed Mar. 31, 2020. [cited by applicant]
Int'l Preliminary Report on Patentability Appln No. PCT/IB2019/000686 mailed Dec. 17, 2020. [cited by applicant]
Extended European Search Report Appln No. 19814618.5 dated Feb. 8, 2022. [cited by applicant]
Chinese Office Action Appln No. 2019800365270 dated Jan. 30, 2024. [cited by applicant]
Japanese Office Action AppIn No. 2021-517925 dated Oct. 28, 2022. [cited by applicant]