IP Library › Granted Patent US 12,432,050
Granted Patent B2
US 12,432,050 · App. 18/653,459 · Granted Sep 30, 2025

Managing data availability on encryption key status changes in replicated storage systems

Inventors: Bonan Liu (New York, NY); Ramesh Rathan Dharan (New York, NY); Michelle Morgan Socher (New York, NY); Shuen Wen Si (Mountain View, CA); Anwesha Das (New York, NY)
Assignee: Google LLC
H04L9/0825H04L9/0866H04L9/14H04L67/1095H04L67/561
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,050
App. No.
18/653,459
Granted
Sep 30, 2025
Kind
B2
Abstract

A method includes obtaining a key status for a first cryptographic key. The first cryptographic key is used to encrypt replicated data of a first replication instance. The method also includes determining, based on the key status, that the first cryptographic key is inaccessible which causes the first replication instance to be unavailable. In response to determining that the first cryptographic key is inaccessible, the method includes scheduling a second replication instance to be unavailable after a threshold amount of time has passed. The second replication instance includes replicated data encrypted by a second cryptographic key that is accessible. After the threshold amount of time has passed and when the first cryptographic key is still inaccessible, the method includes setting the second replication instance as unavailable.

Claims (38)

1. A computer-implemented method executed by data processing hardware of a cloud computing environment that causes the data processing hardware to perform operations comprising:

obtaining a first key status for a cryptographic key used to encrypt replicated data of a replication instance of a cloud data warehouse;

determining, based on the first key status, that the cryptographic key is inaccessible to the data processing hardware, the inaccessible cryptographic key causing the replication instance to be unavailable for updates by the data processing hardware;

based on determining that the cryptographic key is inaccessible to the data processing hardware, setting the replication instance as unavailable;

obtaining a second key status for the cryptographic key;

determining, based on the second key status, that the cryptographic key is now accessible to the data processing hardware; and

based on determining that the cryptographic key is now accessible to the data processing hardware, setting the replication instance as available to allow updates to the replication instance by the data processing hardware.

2. The computer-implemented method of claim 1 , wherein the cryptographic key is temporarily inaccessible due to a network outage.

3. The computer-implemented method of claim 1 , wherein the operations further comprise, based on determining that the cryptographic key is inaccessible to the data processing hardware, scheduling a second replication instance to be unavailable after a threshold amount of time has passed.

4. The computer-implemented method of claim 3 , wherein the second replication instance comprises replicated data encrypted by a second cryptographic key.

5. The computer-implemented method of claim 3 , wherein the operations further comprise:

determining that the cryptographic key is now accessible to the data processing hardware before the threshold amount of time has passed; and

based on determining that the cryptographic key is now accessible to the data processing hardware before the threshold amount of time has passed, canceling the schedule for second replication instance to be unavailable after the threshold amount of time has passed.

6. The computer-implemented method of claim 1 , wherein obtaining the second key status for the cryptographic key comprises obtaining the second key status before a threshold amount of time has passed.

7. The computer-implemented method of claim 1 , wherein the operations further comprise storing, in a data store, as replication metadata associated with the replication instance, an indication that the replication instance is inaccessible because the cryptographic key is inaccessible.

8. The computer-implemented method of claim 1 , wherein the cryptographic key is encrypted by a key encryption key (KEK).

9. The computer-implemented method of claim 8 , wherein the data processing hardware does not have access to the KEK.

10. The computer-implemented method of claim 1 , wherein the cryptographic key is stored at a key management service (KMS).

11. A system comprising:

data processing hardware of a cloud computing environment; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

obtaining a first key status for a cryptographic key used to encrypt replicated data of a replication instance of a cloud data warehouse;

determining, based on the first key status, that the cryptographic key is inaccessible to the data processing hardware, the inaccessible cryptographic key causing the replication instance to be unavailable for updates by the data processing hardware;

based on determining that the cryptographic key is inaccessible to the data processing hardware, setting the replication instance as unavailable;

obtaining a second key status for the cryptographic key;

determining, based on the second key status, that the cryptographic key is now accessible to the data processing hardware; and

based on determining that the cryptographic key is now accessible to the data processing hardware, setting the replication instance as available to allow updates to the replication instance by the data processing hardware.

12. The system of claim 11 , wherein the cryptographic key is temporarily inaccessible due to a network outage.

13. The system of claim 11 , wherein the operations further comprise, based on determining that the cryptographic key is inaccessible to the data processing hardware, scheduling a second replication instance to be unavailable after a threshold amount of time has passed.

14. The system of claim 13 , wherein the second replication instance comprises replicated data encrypted by a second cryptographic key.

15. The system of claim 13 , wherein the operations further comprise:

determining that the cryptographic key is now accessible to the data processing hardware before the threshold amount of time has passed; and

based on determining that the cryptographic key is now accessible to the data processing hardware before the threshold amount of time has passed, canceling the schedule for second replication instance to be unavailable after the threshold amount of time has passed.

16. The system of claim 11 , wherein obtaining the second key status for the cryptographic key comprises obtaining the second key status before a threshold amount of time has passed.

17. The system of claim 11 , wherein the operations further comprise storing, in a data store, as replication metadata associated with the replication instance, an indication that the replication instance is inaccessible because the cryptographic key is inaccessible.

18. The system of claim 11 , wherein the cryptographic key is encrypted by a key encryption key (KEK).

19. The system of claim 18 , wherein the data processing hardware does not have access to the KEK.

20. The system of claim 11 , wherein the cryptographic key is stored at a key management service (KMS).

Continuity (2)
Continuation 17452987 · Oct 29, 2021
Related Publication 20240291638A1 · Aug 29, 2024
References Cited (30)
US 6681017B1 · Matias et al. · 2004 [cited by applicant]
US 8166314B1 · Raizen et al. · 2012 [cited by applicant]
US 8498417B1 · Harwood et al. · 2013 [cited by applicant]
US 8892875B1 · Baldwin et al. · 2014 [cited by applicant]
US 8914362B1 · Zamir et al. · 2014 [cited by applicant]
US 10922132B1 · Shiramshetti et al. · 2021 [cited by applicant]
US 11537728B1 · Esbensen et al. · 2022 [cited by applicant]
US 12010218B2 · Liu et al. · 2024 [cited by applicant]
US 20020126850A1 · Allen et al. · 2002 [cited by applicant]
US 20100254537A1 · Buer et al. · 2010 [cited by applicant]
US 20120233455A1 · Kahler et al. · 2012 [cited by applicant]
US 20140201520A1 · Yacobi · 2014 [cited by applicant]
US 20140310525A1 · Kohlenberg et al. · 2014 [cited by applicant]
US 20150294118A1 · Parker et al. · 2015 [cited by applicant]
US 20160085996A1 · Eigner et al. · 2016 [cited by applicant]
US 20160191239A1 · Murray · 2016 [cited by applicant]
US 20160210200A1 · Kumarasamy et al. · 2016 [cited by applicant]
US 20160292249A1 · Vasanth et al. · 2016 [cited by applicant]
US 20170264432A1 · Horowitz et al. · 2017 [cited by applicant]
US 20180241561A1 · Albertson et al. · 2018 [cited by applicant]
US 20190173675A1 · Kaufman · 2019 [cited by examiner]
US 20190245918A1 · Xu · 2019 [cited by examiner]
US 20200053065A1 · Wisniewski · 2020 [cited by examiner]
EP 3782328A1 · 2021 [cited by applicant]
WO 2017218590A1 · 2017 [cited by applicant]
WO 2019204487A1 · 2019 [cited by applicant]
International Search Report and Written Opinion for the related Application No. PCT/US2022/ 078864, dated Mar. 1, 2023, 259 pages. [cited by applicant]
Prosecution History from U.S. Appl. No. 17/452,987, now issued U.S. Pat. No. 12,010,218, dated Sep. 14, 2023, through Feb. 6, 2024, 29 pp. [cited by applicant]
Response to Communication Pursuant to Rules 161(1) and 162 EPC dated Jun. 6, 2024, from counterpart European Application No. 22822244.4, filed Nov. 29, 2024, 59 pp. [cited by applicant]
First Examination Report from counterpart Indian Application No. 202447040426 dated Jul. 11, 2025, 11 pp. [cited by applicant]