IP Library › Granted Patent US 12,744,763
Granted Patent B2
US 12,744,763 · App. 18/173,697 · Granted Sep 22, 2026

Centrally managed remote storage encryption and decryption

Inventors: Francis Aitken (Nicasio, CA); Stephen Morris (San Francisco, CA); Ryan Justin Frias (Vacaville, CA); Scott Levine (San Anselmo, CA)
H04L63/0435H04L63/0272H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,763
App. No.
18/173,697
Granted
Sep 22, 2026
Kind
B2
Abstract

Techniques are disclosed for centrally managing remote storage encryption and decryption. In some embodiments, to access an encrypted volume on a storage device connected to a computing device, a virtual private network (VPN) client authenticates a user of the computing device to a VPN. After authenticating the user and establishing a VPN connection, the VPN client launches a key management system (KMS) client that authenticates the user and requests an encryption key from a KMS server based on the user, a volume identifier (ID) of the encrypted volume, and a storage device ID of the storage device. The KMS server verifies that the user is allowed to access the encrypted volume having the volume ID, and that the encrypted volume is stored on the storage device having the storage device ID. Upon verification, the KMS server transmits the encryption key to the KMS client for decrypting the encrypted volume.

Claims (35)

1 . A computer-implemented method for decrypting an encrypted volume, the method comprising:

identifying an encrypted volume stored on a storage device that is attached to a computing device, wherein the computing device is remote from a premises of an entity;

authenticating a user to a virtual private network that extends an on-premises network at the premises of the entity;

requesting, from a server via the virtual private network, an encryption key based on the user, an identifier (ID) associated with the encrypted volume, and an ID associated with the storage device; and

decrypting the encrypted volume based on the encryption key.

2 . The computer-implemented method of claim 1 ,

wherein the user is authenticated to the virtual private network via a VPN client running on the computing device, and further comprising further authenticating the user to a client application on the computing device prior to the client application requesting the encryption key from the server.

3 . The computer-implemented method of claim 1 , wherein the server stores one or more associations between each of one or more encryption keys and a corresponding user, a data set management group, a volume ID of an encrypted volume, and a storage device ID of a storage device.

4 . The computer-implemented method of claim 1 , wherein the encrypted volume stores a data set, and the user is assigned to a data set management group associated with the encrypted volume.

5 . The computer-implemented method of claim 1 , further comprising mounting the encrypted volume to create a mounted volume, wherein the mounted volume is decrypted.

6 . The computer-implemented method of claim 5 , further comprising, in response to one or more modifications to a data set stored on the mounted volume, synchronizing the data set with one or more data sets stored on one or more other volumes located on the premises of the entity.

7 . The computer-implemented method of claim 5 , further comprising unmounting the mounted volume in response to determining that at least one of the user is invalid or the user is not assigned to a data set management group associated with the mounted volume.

8 . The computer-implemented method of claim 5 , further comprising unmounting the mounted volume subsequent to termination of a virtual private network (VPN) connection with the on-premises network at the premises of the entity.

9 . The computer-implemented method of claim 1 , wherein the storage device comprises an external hard drive attached to a computing device.

10 . One or more non-transitory computer-readable storage media including instructions that, when executed by at least one processor, cause the at least one processor to perform steps comprising:

identifying an encrypted volume stored on a storage device that is attached to a computing device, wherein the computing device is remote from a premises of an entity;

authenticating a user to a virtual private network that extends an on-premises network at the premises of the entity;

requesting, from a server via the virtual private network, an encryption key based on the user, an identifier (ID) associated with the encrypted volume, and an ID associated with the storage device; and

decrypting the encrypted volume based on the encryption key.

11 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the step of authenticating the user to a client application on the computing device that requests the encryption key from the server.

12 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the server stores one or more associations between each of one or more encryption keys and a corresponding user, a data set management group, a volume ID of an encrypted volume, and a storage device ID of a storage device.

13 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the encrypted volume stores a data set, and the user is assigned to a data set management group associated with the encrypted volume.

14 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the step of mounting the encrypted volume to create a mounted volume, wherein the mounted volume is decrypted.

15 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the step of, in response to one or more modifications to a data set stored on the mounted volume, synchronizing the data set with one or more data sets stored on one or more other volumes.

16 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the step of unmounting the mounted volume in response to determining that at least one of the user is invalid or the user is not assigned to a data set management group associated with the mounted volume.

17 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the instructions, when executed by the at least one processor, further cause the at least one processor to perform the step of unmounting the mounted volume subsequent to termination of a virtual private network (VPN) connection between the computing device and the on-premises network.

18 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the storage device comprises an external hard drive attached to the computing device.

19 . A system, comprising:

one or more memories storing instructions; and

one or more processors that are coupled to the one or more memories and, when executing the instructions, are configured to:

identify an encrypted volume stored on a storage device that is attached to a computing device, wherein the computing device is remote from a premises of an entity,

authenticate a user to a virtual private network that extends an on-premises network at the premises of the entity,

request, from a server via the virtual private network, an encryption key based on the user, an identifier (ID) associated with the encrypted volume, and an ID associated with the storage device, and

decrypt the encrypted volume based on the encryption key.

20 . The system of claim 19 , wherein the one or more processors, when executing the instructions, are further configured to authenticate the user to a client application on the computing device that requests the encryption key from the server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2023
From: AITKEN, FRANCIS; MORRIS, STEPHEN; FRIAS, RYAN JUSTIN; LEVINE, SCOTT
To: LUCASFILM ENTERTAINMENT COMPANY LTD. LLC
Reel/Frame 065702/0631 →
Continuity (1)
Related Publication 20240291808A1 · Aug 29, 2024
References Cited (21)
US 10311240B1 · Nissler · 2019 [cited by examiner]
US 10581617B2 · Khosravi · 2020 [cited by examiner]
US 11127491B2 · Austin · 2021 [cited by examiner]
US 11256816B2 · Yankovskiy · 2022 [cited by examiner]
US 11438357B2 · Mistry · 2022 [cited by examiner]
US 11444754B1 · Shaked · 2022 [cited by examiner]
US 11582221B1 · Raj · 2023 [cited by examiner]
US 11646878B2 · Sofia · 2023 [cited by examiner]
US 11716391B2 · Azulay · 2023 [cited by examiner]
US 12120097B2 · Schmatz · 2024 [cited by examiner]
US 12255980B2 · Bitar · 2025 [cited by examiner]
US 20150373030A1 · Bank · 2015 [cited by examiner]
US 20210014048A1 · Lee · 2021 [cited by examiner]
US 20210103392A1 · Murray · 2021 [cited by examiner]
US 20220093275A1 · Sternberg · 2022 [cited by examiner]
US 20220382898A1 · Thomsen · 2022 [cited by examiner]
US 20220391107A1 · Mallick · 2022 [cited by examiner]
US 20230144072A1 · Shemer · 2023 [cited by examiner]
US 20230336343A1 · Lee · 2023 [cited by examiner]
US 20240171389A1 · Lee · 2024 [cited by examiner]
US 20240205003A1 · Bok · 2024 [cited by examiner]