Reliable large-scale data center protection

By performing pre-checks and health monitoring on data storage devices in the cloud storage system and activating static data encryption, the problems of high data unavailability and loss risk are solved, achieving efficient and reliable data protection.

CN114902224BActive Publication Date: 2026-03-31MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-05
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In cloud storage systems, the activation and deactivation of static data encryption carries a high risk of data unavailability and loss, especially in large-scale cloud storage systems where existing tools are time-consuming and unreliable, making it difficult to meet high availability requirements.

Method used

By pre-checking the status of data storage devices and activating static data encryption upon successful pre-check, combined with health checks to monitor device status, and using encryption orchestrators and encryption controllers to manage the data encryption process, the risk of failure and data loss is reduced.

Benefits of technology

It improves the reliability and high availability of static data encryption, reduces the need for storage device server restarts and data loss, and achieves efficient and reliable data protection in large-scale cloud storage systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114902224B_ABST
    Figure CN114902224B_ABST
Patent Text Reader

Abstract

Methods and systems for activating static data encryption in storage appliance servers in a cloud storage are disclosed. Specifically, an encryption orchestrator orchestrates an activation process through an encryption controller that controls policies and permissions to access data in a storage appliance server. To reduce the risk of data loss and time loss in activation, the encryption controller pre-checks for configuration anomalies in network connectivity, encryption keys, and security credentials of the storage appliance server before starting the activation. Furthermore, the encryption controller performs a health check of the storage appliance server to detect anomalies that require a restart of the storage appliance server. The health check reduces the risk of data loss when the storage appliance server becomes unresponsive to self-restart. User interface tools can be provided to visually identify and manage the encryption status and policies of the encryption controller, the storage appliance server, and data storage devices.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] As data breaches become more prevalent, the need for encryption of data at rest has increased. This is especially true for cloud storage data services as more users and businesses move their data from on-premises storage to the cloud.

[0002] Encryption at rest typically involves encrypting data stored on storage device servers, data storage devices, and / or data drives attached to storage device servers. Combined with encrypting dynamic data or data actively transmitted over a network (e.g., a virtual private network), encryption at rest enhances data security by protecting data while it resides in storage devices (whether locally or in the "cloud").

[0003] Tools for managing data-at-rest encryption provide activation and deactivation of encryption features by specifying the storage device (e.g., server, drive, or blade) attached to a storage device server. In some cases, such tools are executed on the server. Once activated, data on the data storage drive is encrypted, thus providing data-at-rest encryption. In some cases, the host operating system of the storage device server handles data encryption and decryption. In other cases, the hardware processor on the data storage drive (e.g., hard disk and storage device) handles encryption and decryption. Activating and deactivating encryption may require restarting or rebooting the storage device server and / or drive. If an error occurs during a restart or reboot of the storage device server and / or data storage drive, some or all of the data may become unrecoverable. Furthermore, the encryption activation operation on the storage device server and / or data storage drive can be time-consuming, especially if all existing data on the data storage drive needs to be encrypted. If an error is detected during the activation operation, the activation operation may need to be restarted.

[0004] These issues are compounded in cloud storage systems that may comprise tens of thousands of data storage drives attached to hundreds of servers. In fact, a cloud storage system could include over a million blade servers across a distributed geographic area. In some respects, all legacy data storage drives in the cloud storage system that do not support data-at-rest encryption may need to be converted to support it.

[0005] For use in cloud storage systems, tools for managing encryption of data at rest need improvement. One issue is that data may be unavailable during encryption activation and deactivation operations on one or more storage device servers and / or data storage drives. This is particularly problematic for cloud storage systems, as users typically expect and demand high availability. Therefore, minimizing the occurrence of storage device server restarts and the associated risk of data loss in cloud storage systems becomes crucial. Another issue is that data services may be unreliable during encryption activation and deactivation operations, especially as cloud storage systems grow larger. For example, an error in restarting a storage device server during application software updates or patches could lead to data loss. Furthermore, the scalability of management policies and the coordination of encryption activation and deactivation operations become problematic across thousands of data storage drives.

[0006] One way to address these issues is to manually activate and deactivate encryption on storage devices. However, this is extremely time-consuming and virtually impossible in large cloud storage networks. Therefore, there is a need to improve the reliability of automatic activation of encryption for data at rest on data storage drive groups in cloud storage systems.

[0007] It is with regard to these and other general considerations that the various aspects disclosed herein have been made. Moreover, while relatively specific problems may be discussed, it should be understood that the examples should not be limited to solving the specific problems identified in the context of this disclosure or elsewhere. Summary of the Invention

[0008] According to this disclosure, the above and other problems can be resolved by pre-checking the data storage device, activating encryption of data at rest in the data storage device when the pre-check passes, and monitoring the health status and configuration of the data storage device (e.g., health check) after encryption.

[0009] Providing reliable data-at-rest encryption in a cloud environment can be addressed through centralized orchestration of the task of encrypting data on storage device servers and data storage devices. Orchestration can reduce failures when activating data-at-rest encryption on storage device servers and data storage devices by performing pre-checks. Orchestration can also reduce failures during active operation of storage device servers and data storage devices based on data-at-rest encryption by performing health checks on storage device servers and data storage devices. Specifically, orchestration may include the following steps: pre-checking the status of the storage device server to be encrypted; activating data encryption on the storage device server if the pre-check passes; and monitoring the integrity of the storage device server and its configuration data after activating data-at-rest encryption on the storage device server. The data used by the pre-checks and health checks of the storage device may include, but is not limited to, network configuration data, encryption and decryption keys, assigned security credentials, and the status of the hardware-based encryption processor of the storage device (if equipped).

[0010] A graphical user interface (GUI) provides the ability to display and modify the configuration of storage devices and servers in the cloud. The GUI can provide controls to adjust various parameters for activating and deactivating data-at-rest encryption between storage devices or data drives.

[0011] This summary is provided to describe in a simplified form the selection of concepts further described below in the detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter. Additional aspects, features, and / or advantages of the examples will be set forth in part in the description which follows, and will be apparent in part from the description, or may be learned by practice of this disclosure. Attached Figure Description

[0012] Non-restrictive and non-exhaustive examples are described with reference to the following figures.

[0013] Figure 1 An overview of an example system for the cryptographic orchestrator system used in this disclosure is illustrated.

[0014] Figure 2 An exemplary diagram of the cryptographic controller disclosed herein is shown.

[0015] Figure 3 An example of a method for statically encrypting data according to an example system of this disclosure is illustrated.

[0016] Figures 4A to 4C An exemplary timing diagram for activating static data encryption is illustrated in the example system according to this disclosure.

[0017] Figure 5The data structure of this disclosure is illustrated, and this disclosure can be practiced using this data structure.

[0018] Figures 6A to 6B An example of a method for activating static data encryption according to an example system of the present disclosure is illustrated, and the present disclosure can be practiced using this method.

[0019] Figure 7 An example user interface of an example system according to this disclosure is illustrated. This disclosure can be practiced using this user interface, which provides the structure, settings and status of the server and storage device and acts on the storage device for data encryption at rest.

[0020] Figure 8 This is a block diagram illustrating an example physical component of the computing device of this disclosure, which can be used to implement various aspects of this disclosure.

[0021] Figure 9A and 9B This is a simplified block diagram of the mobile computing device disclosed herein, various aspects of which can be practiced using this mobile computing device.

[0022] Figure 10 This is a simplified block diagram of the distributed computing system disclosed herein, and various aspects of this disclosure can be implemented using this distributed computing system.

[0023] Figure 11 The illustration shows a tablet computing device for performing one or more aspects of the present disclosure. Detailed Implementation

[0024] Various aspects of this disclosure are described more fully below with reference to the accompanying drawings, which form a part of it and illustrate specific example aspects. However, different aspects of this disclosure may be implemented in many different forms and should not be construed as limited to the aspects set forth herein. Rather, these aspects are provided so that this disclosure will be thorough and complete, and will fully convey the scope of these aspects to those skilled in the art. The aspects may be practiced as methods, systems, and apparatuses. Thus, the aspects may take the form of hardware implementations, entirely software implementations, or implementations combining hardware and software aspects. Therefore, the following description should not be considered limiting.

[0025] This disclosure relates to systems and methods for providing reliable data center protection at scale using data-at-rest encryption in the cloud. "Defense-at-depth" is a cybersecurity approach that provides multi-layered and collective data protection. Protecting data while it is stored on data storage devices has become a crucial part of defense-at-depth. Providing data-at-rest encryption is effective in the event of malicious removal or mishandling of these disks. While data-at-rest encryption is widely used in data servers, it has become critical to provide data-at-rest encryption on servers with thousands of virtual disks and storage devices in cloud storage systems due to customer expectations of high levels of security, availability, and performance. One aspect of providing this defense-at-depth by cloud storage systems is providing infrastructure-based data encryption, such as ensuring that data stored on physical disks is encrypted at rest. To reliably operate infrastructure-layer encryption at the scale of large cloud providers, cloud storage systems need to efficiently and reliably manage encryption at rest for each data storage device within the data storage infrastructure.

[0026] With the widespread adoption of cloud storage systems, ensuring data is protected at rest has become crucial. This data protection extends beyond the millions of server blades in data centers to include customer data within virtual machines. However, encrypting all data is a time-consuming process, especially when existing cloud storage devices do not yet support data-at-rest encryption. One challenge is the reduced reliability of data services when data recovery events occur following data loss. Furthermore, potential data loss can result from failures during startup, operation, and shutdown of storage devices. In some respects, checking the possible states of storage devices and data storage drives to identify anomalies (such as encryption / decryption key mismatches and network connectivity inconsistencies) can prevent potential data recovery events. Pre-check modes or agents can perform checks before activating data encryption to identify conditions that could lead to data recovery events. In some respects, pre-check modes can be initiated automatically or programmatically without requiring the commencement of encryption operations. Pre-check modes can test the prerequisites for successfully activating data-at-rest encryption on storage devices and data storage drives.

[0027] In addition, health check modes or agents can periodically check network and server configurations, data encryption / decryption keys, and credentials during data encryption activities at rest. A high risk of data loss may be associated with restarting the storage device server of the data storage drive. Health checks may detect anomalies before applying security and other software patches and updates that could lead to a restart / reboot of the storage device server.

[0028] Figure 1An overview of an example system 100 of this disclosure is illustrated. System 100 may include one or more client computing devices 104 (e.g., client computing devices 104A and 104B) that can execute applications (e.g., web search service applications, natural language speech recognition applications, file browsers, etc.). One or more client computing devices 104 may be used by users 102 (e.g., users 102A and 102B). User 102 may be a client of a cloud storage service. The application is any type that can accommodate recorded user actions. Client devices 104A and 104B are connected to network 108 via respective links 106A and 106B. Cloud storage system 110 provides a set of data storage devices as a cloud to client computing devices 104 via network 108. In some aspects, the cloud storage system is located in one or more data centers. Cloud storage system 110 may be connected to the network via link 106C. Cloud storage system 110 may include data at rest encryption, wherein data stored in corresponding storage devices in the cloud is encrypted. The cloud storage system 110 may include thousands of data storage devices 126 (e.g., data storage devices 126A to 126H) connected in groups to corresponding storage device servers 124 (e.g., storage device servers 124A to 124D).

[0029] like Figure 1 As illustrated in the example, cloud storage system 110 includes at least one server version of an encryption orchestrator 114. The encryption orchestrator 114 orchestrates the encrypted management of data in data storage devices 126, storage device servers 124, and encryption controllers 116 within cloud storage system 110. The encryption orchestrator 114 is connected to one or more encryption controllers 116 (e.g., encryption controllers 116A and 116B). The one or more encryption controllers 116 include policy managers 118 (e.g., policy managers 118A and 118B), key managers 120 (e.g., key managers 120A and 120B), and permission managers (e.g., permission managers 122A and 122B).

[0030] A server version of the encryption orchestrator 114 can also be implemented in a distributed environment across network 108. Furthermore, it should be understood that a client or server version of the encryption orchestrator 114 may be able to receive commands from users (e.g., users 102A or 102B) to configure and manage data-at-rest encryption in the cloud storage system 110. Although a server version of the encryption orchestrator 114 is shown and described, this should not be construed as limiting. Conversely, a client version of the encryption orchestrator 114 can be similarly implemented on client computing devices 104A, 104B to remotely manage the cloud storage system 110.

[0031] In at least some aspects, one or more client computing devices 104 (e.g., 104A and 104B) may be personal or handheld computers operated by one or more users 102 (e.g., user 102A and another user 102B). For example, one or more client computing devices 104 may include one or more of the following: mobile phones, smartphones, tablet computers, phablets, smartwatches, wearable computers, personal computers, desktop computers, laptop computers, gaming devices / computers (e.g., mobile phones, smartphones, tablets, tablet phones, smartwatches, wearable computers, personal computers, desktop computers, laptop computers, gaming devices / computers). (e.g., television). This list is merely illustrative and should not be considered restrictive. Any suitable client computing device used to execute the classifier application 114 can be used.

[0032] In at least some aspects, network 108 is a computer network, such as an enterprise intranet, an enterprise extranet, and / or the Internet. In this respect, network 108 may include a local area network (LAN), a wide area network (WAN), the Internet, and wireless and wired transmission media. In other aspects, server computing device 112 and other server computing devices 110A and 110B may communicate with some components of the system via corresponding links 106A to 106E to a local network (e.g., an enterprise intranet), while server computing device 112 may communicate with other components of the system via a wide area network (e.g., the Internet). Furthermore, the aspects and functionalities described herein can operate on a distributed system (e.g., a cloud computing system), where application functionalities, memory, data storage devices and retrieval, and various processing functions can operate remotely to each other via a distributed computing network (such as the Internet or an intranet).

[0033] As described above, the encryption orchestrator 114 can be implemented in the cloud storage system 110 to orchestrate the encryption and decryption of data at rest in the data storage devices 126 within the cloud storage system 110. In a basic configuration, the encryption orchestrator 114 is connected to one or more encryption controllers 116 (e.g., encryption controllers 116A and 116B). For example, the encryption orchestrator 114 can be connected to hundreds of encryption controllers 116. Each of the encryption controllers 116 can be connected to one or more storage device servers 124. For example, encryption controller 116A can be connected to storage device servers 124A and 124B. In some aspects, encryption controller 116A can connect to thousands of storage device servers 124. For example, in some other aspects, encryption controller 116A can be connected to hundreds of server racks, where each rack can include more than sixty storage servers 124 in blade form. Each of the storage device servers 124 can be connected to one or more data storage devices 126 (e.g., data storage devices 126A to 126H). For example, storage device server 124A can connect to data storage devices 126A and 126B. In some aspects, each of the storage device servers 124 can connect to hundreds or thousands of data storage devices 126. In some aspects, encryption orchestrator 114 can enable the determination of which storage device servers activate and deactivate encryption, and set various policies, including but not limited to the data encryption type for all policy managers (e.g., policy managers 118A and 118B).

[0034] In some aspects, storage device server 124 can encrypt and decrypt data in data storage device 126 based on the host operating system of its respective storage device server 124. Different host operating systems can provide encryption capabilities specific to their respective host operating systems. In other aspects, storage device server 124 can encrypt and decrypt data in data storage device 126 based on hardware-based data encryption capabilities provided by data storage device 126. Such hardware-based data encryption capabilities can utilize a data processor within data storage device 126. Data storage device 126 may include data drive devices. In other aspects, data storage device 126 may be implemented as a virtual data disk drive, wherein multiple virtual data disk drives may exist within the data storage device. Virtual data storage devices spanning multiple data storage devices (e.g., data storage devices 126A and 126B) may also exist.

[0035] In some aspects, the encryption controller 116A may include a policy manager 118A, a key manager 120A, and a permission manager 122A, collectively controlling the encryption of data at rest in the corresponding data storage devices 126A to 126D connected to storage device servers 124A to 124B. The key manager 120A manages security keys used for encrypting and decrypting data stored in the data storage devices 126A to 126D. In some aspects, the key manager 120A also manages security credentials used for authenticating and accessing the data storage devices 126A to 126D via storage device server 124A. Similarly, the key manager 120B manages keys used for encrypting and decrypting data in data storage devices 126E to 126H. In some aspects, the key manager 120B also manages security credentials used for authenticating and accessing the data storage devices 126E to 126H via storage device server 124B. The policy manager 118A manages policies for handling the encryption of data at rest in the data storage devices 126A to 126D. Policies may include, but are not limited to, activating and deactivating data encryption at rest by specifying a data storage device (e.g., data storage device 126A). In some aspects, cloud storage system 110 may use policies to address the problem of reliably managing data at rest in a scalable and robust manner. Policy manager 118A receives, for example, requests for policy-based commands (such as activation commands for encrypted data storage devices) from encryption orchestrator 114. Based on the results of executing the policy-based commands, policy manager 118A provides updates and responses to encryption orchestrator 114. Permission manager 122A manages permission settings for accessing data storage devices 126A to 126D through storage device servers 124A to 124B. Permission settings may include, but are not limited to, access credentials for accessing storage device servers 124 and data storage devices 126. In some aspects, permission settings may be specific to the specific host operating system of storage device servers 124 and data storage devices 126.

[0036] In some aspects, the encryption orchestrator 114 can provide cloud storage system administrators with a graphical user interface tool to view, activate, and initiate other operations on the corresponding encryption controllers 116 (e.g., encryption controllers 116A and 116B), storage device servers 124, and data storage devices 126. For example, the tool polls the operational status of the encryption controllers 116, the policies and keys set in the corresponding encryption controllers 116, network characteristic values, the health check status of the storage device servers 124, and the encryption and other statuses of the corresponding data storage devices 126. In response to polling requests from the tool at the encryption orchestrator 114, the corresponding encryption controllers 116 can provide operational status. In some other aspects, the encryption controllers 116 can periodically push operational status to the encryption orchestrator 114 to automatically update the corresponding operational status in the tool.

[0037] It should be understood that, relative to Figure 1 The various methods, devices, applications, features, etc., described are not intended to limit System 100 to being performed by the specific applications and features described. Therefore, additional topology configurations may be used to practice the methods and systems disclosed herein and / or the features and applications described may be excluded without departing from the methods and systems disclosed herein.

[0038] Figure 2 Exemplary diagrams of encryption controllers 116A and 116B of this disclosure are illustrated. In at least some aspects, the data encryption system 200 includes encryption controller 116A. In some aspects, encryption controller 116A includes policy manager 118A. Policy manager 118A includes at least a request receiver 204, a storage device pre-checker 206, a storage device encryption activator 208, a storage device health monitor 210, and a status updater 212. Policy manager 118A includes a set of policies for managing data-at-rest encryption between data storage devices in cloud storage system 110. For example, the policy set includes the type of data-at-rest encryption in storage device server 124, regardless of whether key management is centralized at key manager 118 or distributed to the respective storage server 124.

[0039] Request receiver 204 receives a request to activate data at rest encryption in data storage devices (126A to 126H). For example, request receiver 204 receives the request from encryption orchestrator 114 based on user input via a graphical user interface by the operator of cloud storage system 110. For example, the request may include, as its data structure, a command for activating data at rest encryption and one or more identifiers of the target data storage device for activating data at rest encryption.

[0040] In response to receiving a request to activate data encryption, the storage device pre-checker 206 pre-checks the status of the data storage device (e.g., data storage devices 126A to 126H specified in the request). In some aspects, the pre-check includes requesting configuration data and operational status of the specific data storage devices 126A to 126H. The type of status data used for the pre-check may include, but is not limited to, the network addresses of the storage device server 124 (e.g., storage device server 124A) and the corresponding encryption controller 116 (e.g., encryption controller 116A), the network connectivity between the storage device server 124 and the corresponding encryption controller 116, configuration parameters of the data storage device or disk drive, path names, history of hardware and software problems at the data storage device, integrity of encryption and decryption keys managed by the key manager 120, security credentials for the specified data storage device, data transfer speed and latency over the network when accessing the specified data storage device, and the integrity of access permission settings. In some aspects, the type of status data used for the pre-check relates to prerequisites for successful activation. The storage device pre-checker 206 can obtain status data by requesting and receiving data from the corresponding encryption controller 116 and storage device server 124. Pre-checking the data storage device before activating encryption at rest reduces the likelihood of encryption activation failure in subsequent steps. In some respects, pre-checking is effective in preventing data loss, as failed encryption activation can lead to irrecoverable data loss.

[0041] Storage device encryption activator 208 activates static data encryption in a data storage device specified by a request. For example, storage device encryption activator 208 may communicate with encryption controller 116 and request activation of data encryption for data in one or more specific data storage devices 126A to 126H. After storage device encryption is activated, the data in the assigned data storage device is encrypted.

[0042] After the static data is encrypted in the designated storage device server and after the data storage device becomes active, the storage device health monitor 210 monitors the status of the designated storage device server and the data storage device. In some aspects, the monitoring of the storage device status may include a one-time verification of parameters associated with the designated storage device server and the data storage device. Such parameters may include, but are not limited to, the network addresses of the storage device server 124 (e.g., storage device server 124A) and the corresponding encryption controller 116 (e.g., encryption controller 116A), the network connectivity between the storage device server 124 and the corresponding encryption controller 116, the configuration parameters of the data storage device or disk drive, the path name, the history of hardware and software problems at the data storage device, the integrity of the encryption and decryption keys managed by the key manager 120, the security credentials of the designated data storage device, the data transfer speed and latency over the network when accessing the designated data storage device, and the integrity of the access permission settings. In some aspects, the parameters used for the health check relate to the prerequisites for the successful restart operation of the storage device server with active static data encryption when a restart or reboot of the storage device server or data storage device occurs. Parameters can be obtained from devices associated with the specified data storage device, storage servers to which the specified data storage device is attached, key managers (e.g., key managers 120A to 120B), and permission managers (e.g., permission managers 122A to 122B). Specifically, checking the integrity of the encryption and decryption keys managed by key manager 120 is important because corruption of these keys can likely cause restarts of storage device server 124 and data storage device 126 to fail. Restarting or restarting storage device server 124 can occur in various instances, including applying software patch updates to storage device server 124. When restarting or restarting storage device server 124 fails, encrypted data in storage device server 124 may become unrecoverable. In some other aspects, storage device health monitor 210 can periodically check parameters or be triggered by events such as data access or idle timeouts in accessing data storage devices. Storage device health monitor 210 can issue alerts and notifications to encryption orchestrator 114 via a graphical user interface tool.

[0043] The state updater 212 updates the state of a specified data storage device through means such as, but not limited to, graphical user interface tools and message transmissions to the encryption orchestrator 114. In some aspects, the state updater 212 may update the state on the graphical user interface tool of the encryption orchestrator 114. For example, the graphical user interface tool may interactively provide the hierarchical structure of the storage device server 124 and the data storage device 126, as well as state information about the respective data storage devices. In some aspects, the encryption orchestrator 114 receives the latest state of the corresponding encryption controller 116 through polling. In other aspects, the encryption controller 116 pushes the corresponding state information to the encryption orchestrator.

[0044] As should be understood, relative to Figure 2 The various methods, devices, applications, and features described are not intended to limit the examples of information retrieval system 200. For example, in various aspects, the cryptographic orchestrator may also include at least a request receiver 204, a storage device pre-checker 206, a storage device cryptographic activator 208, a storage device health monitor 210, and a status updater 212. Therefore, additional topology configurations that can be used to practice the methods and systems described herein can be excluded without departing from the methods and systems disclosed herein.

[0045] Figure 3 An example of a method for statically encrypting data according to an example system of this disclosure is illustrated. The general sequence of operations in method 300 is as follows: Figure 3 As shown. Typically, method 300 begins with start operation 302 and ends with end operation 314. Method 300 may include more or fewer stages, or may be combined with... Figure 3 The different arrangement sequences of the stages are shown. Method 300 can be executed as a computer-executable instruction set, which is executed by a computer system and encoded or stored on a computer-readable medium. Further, method 300 can be executed by gates or circuits associated with a processor, ASIC, FPGA, SOC, or other hardware device. In the following, method 300 should be referred to in conjunction with... Figures 1 to 2 Explain using the systems, components, devices, modules, software, data structures, data characteristic representations, signaling diagrams, methods, etc., described in sections 4 to 11.

[0046] Receive operation 304 receives a request to activate data-at-rest encryption in a storage device server. This request may specify activating data-at-rest encryption in one or more data storage devices connected to the corresponding storage device server. In some aspects, receive operation 302 receives the request as a result of user interaction with an encryption orchestrator tool within a graphical user interface. The user of this tool can select a storage device server and issue a command to activate data-at-rest encryption on the storage device server. Upon successful activation of data-at-rest encryption, data written to the storage device server is encrypted.

[0047] Operation 306 performs a pre-check on the specified storage device server. The types of status data used for performing the pre-check operation may include, but are not limited to, network addresses, network communication performance data, connectivity between the storage device server and the key manager 120 in the encryption controller 116, and keys for data encryption and decryption in specific data storage devices 126A to 126H. The storage device pre-checker 206 can obtain status data by requesting and receiving data from the corresponding encryption controller 116 and storage device server 124. Performing a pre-check on the specified data storage device before activating encryption reduces the likelihood that activation will fail in subsequent steps. In some aspects, performing a pre-check before activating data encryption at the storage device server is effective in reducing activation processing time and preventing data loss.

[0048] Comparison operation 307 compares the pre-check result to determine if it indicates a pass (e.g., success or OK). If the status is negative (i.e., pre-check failed), the operation proceeds to update operation 312. Update operation 312 updates the status of the storage device server to the pre-check failure state. In some aspects, the status updater 212 may update the status on the cryptographic orchestrator 112 to warn of the need to repair the storage device server 124 that failed the pre-check. In some other aspects, the storage device server 124 and / or data storage devices 126A to 126H with pre-check problems may be marked for repair, and the pre-check may be performed at a later time after the repair is complete and is not marked for repair (not shown). If the status is positive (i.e., pre-check successful), the operation proceeds to activation operation 308.

[0049] Activation operation 308 activates at-rest data encryption in the specified storage device server. In some aspects, activation may include activating data encryption capabilities provided by the host operating system of the storage device server to which the data storage device or drive is attached. In other aspects, activation may include activating data encryption capabilities provided by hardware-based data encryption in the specified data storage device. The detailed protocol for activating data encryption on a specific storage device server may depend on the host operating system of the storage device server and the type of the specified data storage device. Activation operation 308 may look for methods specific to the host operating system and the specified data storage device when activating data encryption. In some aspects, activation operation 308 may include resetting and restarting the specified storage device server and data storage device. In other aspects, data may be lost if the specified data storage device fails to restart itself during activation operation 308. Encryption orchestrator 114 may remove data from the specified storage device server or data storage device before performing activation operation 308 to enable data recovery in the event of a failure of the specified storage device server or data storage device.

[0050] The check operation 310 can check the status (health check) of the specified storage device server and / or data storage device after the specified storage device server is activated. In some aspects, the status check may include one-time verification of parameters associated with the specified storage device server and data storage device. Such parameters may include, but are not limited to, the network address of the data storage device or disk drive, path name, history of hardware and software problems at the data storage device, integrity of encryption and decryption keys, security credentials for the specified data storage device (e.g., for locking and unlocking the data storage device), connectivity between the encryption controller 116 (especially the key manager 120) and the storage device server 124, data transfer speed and latency on the network when accessing the specified data storage device, and the integrity of access permission settings. These parameters can be obtained from the devices associated with the specified storage device server, the data storage devices attached to the specified storage device server, the key managers (e.g., key managers 120A to 120B), and the permission managers (e.g., permission managers 122A to 122B). In some other aspects, the storage device health monitor 210 may check the parameters periodically or be triggered by events such as data access or idle timeouts in accessing the specified storage device server and data storage device. The storage device health monitor 210 can trigger alarms and notifications about the status of the encryption orchestrator 114 through a graphical user interface tool.

[0051] Update operation 312 updates the status of the specified storage device server and data storage device based on the processing result of the request to activate data encryption at rest in the specified storage device server. For example, update operation 312 can update the status by indicating that data encryption in the specified storage device server has been successfully activated. This status may include the results of health checks on the specified storage device server that has been actively accessed and used for writing and reading data. In some aspects, the status can be provided by an encryption orchestrator tool, which may feature a graphical user interface.

[0052] Comparison operation 313 compares whether there are more storage device servers to encrypt. When there are more storage device servers to encrypt (i.e., yes), the step returns to receive operation 304. When there are no more storage device servers to encrypt (i.e., no), the step proceeds to end 314.

[0053] It should be understood that operations 302 to 314 are described for the purpose of illustrating the method and system and are not intended to limit the disclosure to a particular sequence of steps. For example, the steps may be performed in a different order, additional steps may be performed, and the disclosed steps may be excluded without departing from the disclosure.

[0054] Figures 4A to 4C An exemplary timeline for activating static data encryption using an example system according to this disclosure is illustrated. Figure 4A The timing diagram 400A illustrates the timing of communication and processing operations between components used to activate encryption in the cloud storage system 110 in the data storage device. The encryption controller 116A includes a policy manager 118A and a key manager 120A.

[0055] In encryption operation 402, encryption orchestrator 114 transmits a command to policy manager 118A in encryption controller 116A to implement a policy or workflow to activate encryption in a specific data storage device (e.g., data storage device 126A). Policy manager 118A then sends command 404 to storage device server 124A to remove data from data storage device 126A. Removing data to another data storage device allows data recovery in the event of encryption activation failure and data becoming unrecoverable. Storage device server 124A sends command 406 to data storage device 126A to remove data. Data storage device 126A can move data from data storage device 126A to another data storage device (not shown) so that data is not lost in the event that data storage device 126A fails to activate encryption and loses all data stored in data storage device 126A. In some aspects, data storage device 126A can copy data to another data storage device, thereby allowing clients to continue accessing data while data storage device 126A undergoes encryption activation without interruption. Data storage device 126A then transmits a "Withdraw OK" (success) status 408 to storage device server 124A. Storage device server 124A then sends a status 410 indicating that the withdrawal command was successfully completed to policy manager 118A.

[0056] Next, policy manager 118A sends a pre-check command 422A to storage device server 124A. Key manager 120A can look up the key of data storage device 126A and send command 426A with the key to storage device server 124A. Storage device server 124A sends command 424A to data storage device 126A to pre-check data storage device 126A. Data storage device 126A can perform the pre-check by reading and verifying parameters, including but not limited to the network address, encryption and decryption keys, and security credentials of data storage device 126A. Data storage device 126A then sends a status (pre-check OK) 426A to storage device server 124A. Storage device server 124A then sends command 428A to key manager 120 to check the integrity of the encryption and decryption keys of storage device server 124A and data storage device 126A. Key manager checks the integrity of the keys and sends command 430A to send the OK status to storage device server 124A. In some aspects, storage device server 124A receives encryption and decryption keys from key manager 120A to perform integrity checks. Additionally or alternatively, storage device server 124A performs a pre-check by reading status parameters from data storage device 126A and determining whether the status parameters are normal. Storage device server 124A can then send a pre-check OK status 432A to policy manager 118A.

[0057] Next, policy manager 118A sends command 460A to storage device server 124A to activate data at rest encryption in data storage device 126A. Storage device server 124A sends command 462A to data storage device 126A via the host operating system to activate data encryption in data storage device 126A. After successful activation, data storage device 126A sends a status "Encryption OK" 464A to storage device server 124A. In some embodiments, data storage device 126A may undergo a power cycle, where it shuts down and then restarts itself. Data storage device 126A can determine the successful encryption activation status after restarting. In other embodiments, data storage device 126A completes encryption activation without restarting itself. Data storage device 126A sends the status "Encryption OK" 464A to storage device server 124A. Storage device server 124A sends the successful encryption activation status (466A) to policy manager 118A. Policy Manager 118A then sends command 470 to Storage Device Server 124A to recover data based on data withdrawn before activation. Storage Device Server 124A sends command 472 to Data Storage Device 126A to recover data. In some aspects, Data Storage Device 126A recovers data by copying the data withdrawn due to Data Withdrawal command 406. Upon completion of data recovery, Data Storage Device 126A sends status 474A to Storage Device Server 124A. Storage Device Server 124A then sends status 476, indicating successful data recovery, to Policy Manager 118A. Policy Manager 118A sends an Encryption Storage Device OK command 478 to Encryption Orchestrator 114.

[0058] After successful encryption activation, policy manager 118A can send command 480A to storage device server 124A to check drive health (e.g., a health check). In some aspects, after data storage device 126A has restored withdrawn data, storage device server 124A can check the status data of data storage device 126A. In some other aspects, storage device server 124A sends command 482A to data storage device 126A to check the health status of data storage device 126A. Data storage device 126A can send command 484A to storage device server 124A to check whether data storage device 126A has experienced abnormal states during data input and output processing. Additionally or alternatively, storage device server 124A sends a key check command 486A to key manager 120A to check the integrity of the encryption and decryption keys used for data at rest encryption at storage server 124A and data storage device 126A. Key manager 120A performs a key integrity check and sends a key check OK status 488A as a response to storage server 124A. In some embodiments, storage server 124A may receive the key from key manager 120A to perform a key integrity check at storage device server 124A. Storage device server 124A then sends a health check status 490A to policy manager 118A.

[0059] As should be understood, operations 402 to 490A are described for the purpose of illustrating the method and system and are not intended to limit the disclosure to a particular sequence of operations. For example, operations may be performed in different orders, additional operations may be performed, and the disclosed operations may be excluded without departing from the disclosure.

[0060] Figure 4B Timing diagram 400B illustrates the timing of communication and processing operations between components of a cloud storage system 110 used to activate data-at-rest encryption in a data storage device. Specifically, timing diagram 400B depicts encryption activation when an identified problem exists during a pre-check.

[0061] and Figure 4A Similarly, in operation 402, the encryption orchestrator 114 transmits commands to the policy manager 118A to execute policies or workflows to activate data-at-rest encryption in a specific data storage device (e.g., data storage device 126B). In some aspects, the policy manager 118A may send commands to the storage device server 124A ( Figure 4B(Not shown in the image) to remove data from data storage device 126B. Storage device server 124A sends command 406 to data storage device 126B to remove data. Data storage device 126B can then move data from data storage device 126B to another data storage device (…). Figure 4B (not shown in the image) ensures that data will not be lost if the data storage device 126B fails to activate encryption and all data stored in the data storage device 126B is lost.

[0062] Then, policy manager 118A sends a pre-check command 422B to storage device server 124A by specifying data storage device 126B as the target device to be pre-checked. Additionally or alternatively, storage device server 124A may identify and determine the target device based on the receipt of pre-check command 422B. Storage device server 124A sends command 424B to data storage device 126B to pre-check data storage device 126B. Data storage device 126B can perform the pre-check operation by reading and verifying parameters, including but not limited to the network address, encryption key, decryption key, and security credentials of data storage device 126B. Here, data storage device 126B detects that the pre-check failed due to a problem found while using data storage device 126B. Examples of potential pre-check failures include, but are not limited to, connectivity errors between storage device server 124A and key manager 120A in encryption controller 116A; integrity errors of encryption and decryption keys managed by key manager 120A or locally managed by storage device server 124A; connectivity errors between storage device server 124A and data storage device 126B; network address errors between encryption controller 116A and storage device server 124A; and integrity errors of data storage device 126B. Data storage device 126B then sends a status (pre-check failure) 426B to storage device server 124A. Additionally or alternatively, storage device server 124A performs the pre-check by reading status parameters from data storage device 126B and determining whether the status parameters are normal. In this example, the pre-check of data storage device 126B fails. Storage device server 124A then sends a pre-check failure status 432B to policy manager 118A.

[0063] In some respects, policy manager 118A can send the error completion status of an encrypted storage device command to the encryption orchestrator to reject a request to activate encryption due to an error in data storage device 126B. (This operation is not in...) Figure 4B(As shown in the diagram.) Alternatively or concurrently, policy manager 118A sends a pre-check command 422A to storage device server 124A by designating data storage device 126A as a candidate because data storage device 126B has failed. Storage device server 124A sends command 424A to data storage device 126A to pre-check data storage device 126A. Data storage device 126A can perform the pre-check by reading and verifying parameters, including but not limited to data storage device 126A's network address, encryption and decryption keys, and security credentials. Data storage device 126A then sends a status (pre-check OK) 426A to storage device server 124A. Storage device server 124A then sends command 428A to key manager 120 to check the integrity of the encryption and decryption keys of storage device server 124A and data storage device 126A. Key manager checks the integrity of the keys and sends command 430A to send the OK status to storage device server 124A. In some aspects, storage device server 124A may receive encryption and decryption keys from key manager 120A to perform integrity checks. Additionally or alternatively, storage device server 124A may perform a pre-check by reading status parameters from data storage device 126A and determining whether the status parameters are normal. Storage device server 124A may then send a pre-check OK status 432A to policy manager 118A.

[0064] Policy Manager 118A can send command 460A to Storage Device Server 124A to activate data-at-rest encryption in Data Storage Device 126A. Storage Device Server 124A can then send command 462A to Data Storage Device 126A to activate data-at-rest encryption in Data Storage Device 126A. After successful activation, Data Storage Device 126A can send a status "Encryption OK" 464A to Storage Device Server 124A. In some embodiments, Data Storage Device 126A undergoes a power cycle, where it can shut down and then restart itself. Data Storage Device 126A can determine the successful encryption activation status after restarting. In other embodiments, Data Storage Device 126A can complete encryption activation without restarting itself. Data Storage Device 126A then sends the status "Encryption OK" 464A to Storage Device Server 124A. Storage Device Server 124A sends a successful encryption activation status 466A to Policy Manager 118A. Upon receiving a status 466A indicating the completion of static data encryption in data storage device 126A, policy manager 118A sends a completion status 478 for encryption activation operation to encryption orchestrator 114.

[0065] In some respects, after successfully activating data at rest encryption, the policy manager 118A can then send commands to the storage device server 124A. Figure 4B (Not shown in the image) to recover data based on data withdrawn before activation. Storage device server 124A sends a command to data storage device 126A (…). Figure 4B (Not shown in the image) to recover the data.

[0066] In various aspects, after successful encryption activation in storage device server 124A, policy manager 118A sends command 480A to storage device server 124A to check drive health (health check). In some aspects, storage device server 124A then reads health data from data storage device 126A, since data storage device 126A is online and actively available to input and output data to clients. In other aspects, storage device server 124A sends command 482A to data storage device 126A to check the health status of data storage device 126A. Data storage device 126A may send command 484A to storage device server 124A to check whether data storage device 126A has experienced an abnormal state while processing data input and output. Additionally or alternatively, storage device server 124A sends a check key command 486A to key manager 120A to check the integrity of the encryption and decryption keys used for at-rest data encryption at storage server 124A and data storage device 126A. Key manager 120A performs a key integrity check and sends a key OK status 488A as a response to storage server 124A. In some aspects, storage server 124A may receive a key from key manager 120A to perform a key integrity check at storage device server 124A. Storage device server 124A then sends a health check status 490A to policy manager 118A. In some aspects, policy manager 118A periodically transmits commands 480A to storage device server 124A to perform health checks on storage device server 124A and data storage device 126A while the data storage device is active and online, thereby processing data input and output. For example, this period may be scheduled by policy manager 118A. Additionally or alternatively, this period may be determined by storage device server 124A and / or data storage device 126A based on parameters such as processing load and time since the last error or anomaly was detected. Although not shown, when status information pertains to key management, storage device server 124A and / or data storage device 126A can send status information to key manager 120A. In some aspects, for example, encryption orchestrator 114 can request storage encryption status 491A from encryption controller 116A (specifically policy manager 118A). Policy manager 118A can notify encryption orchestrator 114 of the status 492A of storage device 426A based on a health check operation, indicating that no anomalies were found in the health check on storage device server 124A. If so, encryption orchestrator 114 displays the normal status via a graphical user interface. Additionally or alternatively, encryption orchestrator 114 provides status to the user via message passing.

[0067] As should be understood, Figure 4BOperations 402 to 492A are described for the purpose of illustrating the method and system and are not intended to limit the disclosure to a particular sequence of operations. For example, operations may be performed in different orders, additional operations may be performed, and the disclosed operations may be excluded without departing from the disclosure.

[0068] Figure 4C Timing diagram 400C illustrates the timing of communication and processing operations between components of a cloud storage system 110 for cryptographic activation in a data storage device. Specifically, timing diagram 400C depicts a data storage device that encounters problems during cryptographic activation despite having passed the pre-check process.

[0069] In operation 402, the encryption orchestrator 114 transmits a command to the policy manager 118A to execute a policy or workflow to activate data-at-rest encryption in a specific data storage device (e.g., data storage device 126B). The policy manager 118A then sends a pre-check command 422B to the storage device server 124A. The storage device server 124A sends command 424B to the data storage device 126B to pre-check it. The data storage device 126B can perform the pre-check by reading and verifying parameters, including but not limited to its network address, encryption and decryption keys, and security credentials. Here, the data storage device 126B detects that the pre-check has passed. The data storage device 126B then sends a status (pre-check OK) 426C to the storage device server 124A. The storage device server 124A then sends command 428A to the key manager 120 to check the integrity of the encryption and decryption keys of the storage device server 124A and the data storage device 126A. The key manager checks the integrity of the key and sends command 430A to send an OK status to storage device server 124A. In some aspects, storage device server 124A may receive encryption and decryption keys from key manager 120A to perform an integrity check. Additionally or alternatively, storage device server 124A may perform a pre-check by reading status parameters from data storage device 126B and determining whether the status parameters are normal. In this example, the pre-check of data storage device 126B is successful. Storage device server 124A then sends a successful pre-check status 432C to policy manager 118A.

[0070] Policy manager 118A can then send command 460C to storage device server 124A to activate data at rest encryption in data storage device 126B. Storage device server 124A can then issue command 462B to data storage device 126B to activate data at rest encryption in data storage device 126B. In some aspects, data storage device 126B detects an error during activation. Data storage device 126B sends a failed activation status 464C to storage device server 124A. In some other aspects, data storage device 126B may fail to restart itself during activation and become unable to communicate with storage device server 124A. For example, storage device server 124A can detect an unresponsive data storage device 126B based on a timeout and determine that activation in data storage device 126B has failed after the timeout period has elapsed. Storage device server 124A can then send status 466C regarding the failed encryption activation in data storage device 126B to policy manager 118A. In some aspects, status 466C may include detailed information about the error status. This detailed information may include, but is not limited to, restart errors of storage device server 124A, restart errors of data storage device 126B (including connectivity timeouts), integration errors of encryption and decryption keys (managed locally in storage device server 124A or remotely in key manager 120A of encryption controller 116A), connectivity errors between encryption controller 116A (including key manager 120A) and storage device server 124A, hardware errors in data storage device 126B, and network configuration errors.

[0071] In some respects, the policy manager 118A notifies the storage device server 124A of its status. The graphical user interface tool in the encryption orchestrator 114 can display the status of the storage device server 124A managed by the encryption controller 116A.

[0072] In some aspects, the policy manager 118A may include a policy to assign and pre-check data storage device 126A as a backup device when the initially specified data storage device fails a pre-check. In other aspects, the graphical user interface may also enable administrators to specify alternative storage device servers or data storage devices for users. The current example includes a policy to use data storage device 126A as a backup when data storage device 126B fails to activate. The policy manager 118A then sends a pre-check command 422A to the storage device server 124A by designating data storage device 126A as a backup for the failed data storage device 126B. The storage device server 124A sends command 424A to data storage device 126A to pre-check data storage device 126A. Data storage device 126A can perform the pre-check by reading and verifying parameters, including but not limited to the network address, encryption key and decryption key, and security credentials of data storage device 126A. Data storage device 126A then sends a status (pre-check OK) 426A to the storage device server 124A. Storage device server 124A then sends command 428A to key manager 120 to check the integrity of the encryption and decryption keys of storage device server 124A and data storage device 126A. Key manager checks the integrity of the keys and sends command 430A to send an OK status to storage device server 124A. In some aspects, storage device server 124A may receive encryption and decryption keys from key manager 120A to perform integrity checks. Additionally or alternatively, storage device server 124A may perform a pre-check by reading status parameters from data storage device 126A and determining whether the status parameters are normal. Storage device server 124A may then send a pre-check OK status 432A to policy manager 118A.

[0073] Policy Manager 118A can then send command 460A to Storage Device Server 124A to activate data-at-rest encryption in Data Storage Device 126A. Storage Device Server 124A can then issue command 462A to Data Storage Device 126A to activate data-at-rest encryption in Data Storage Device 126A. After successful activation, Data Storage Device 126A sends a status "Encryption OK" 464A to Storage Device Server 124A. In some aspects, Data Storage Device 126A can undergo a power cycle, where Data Storage Device 126A can shut down its power and then restart itself. Data Storage Device 126A can determine the successful encryption activation status after restarting Data Storage Device 126A. In some other aspects, Data Storage Device 126A completes encryption activation without restarting itself. Data Storage Device 126A then sends the status "Encryption OK" 464A to Storage Device Server 124A. Storage Device Server 124A sends a successful encryption activation status 466A to Policy Manager 118A. Upon receiving a status 466A regarding the completion of static data encryption in data storage device 126A, policy manager 118A sends a completion status 478 of the encryption request to encryption orchestrator 114.

[0074] After successfully activating data at rest encryption, policy manager 118A can send command 480A to storage device server 124A to check drive health (health check). In some aspects, storage device server 124A then reads health data from data storage device 126A, since data storage device 126A is online and actively available to input and output data to clients. In other aspects, storage device server 124A sends command 482A to data storage device 126A to check the health status of data storage device 126A. Additionally or alternatively, storage device server 124A sends a check key command 486A to key manager 120A to check the integrity of the encryption and decryption keys used for data at rest encryption at storage server 124A and data storage device 126A. Key manager 120A performs the key integrity check and sends a check key OK status 488A as a response to storage server 124A. In some aspects, storage server 124A may receive keys from key manager 120A to perform key integrity checks at storage device server 124A. Data storage device 126A may send a status 484A to storage device server 124A indicating whether data storage device 126A has experienced any abnormalities while processing data input and output. Storage device server 124A then sends a health check status 490A to policy manager 118A. Although not shown, storage device server 124A and / or data storage device 126A may send status information to key manager 120A when the status information pertains to key management. In some aspects, policy manager 118A may periodically (481) transmit commands 480A to storage device server 124A to perform health checks on storage device server 124A and data storage device 126A while the data storage devices are active and online, thereby processing data input and output. For example, this period may be scheduled by policy manager 118A. Alternatively or concurrently, the period may be determined by the storage device server 124A and / or the data storage device 126A based on parameters such as processing load and the time since the last error or anomaly was detected.

[0075] Policy manager 118A notifies the encryption orchestrator 114 of the status 498A of storage device 426A, indicating that no anomalies were found through a health check of storage device 426A. Encryption orchestrator 114 displays the normal status via a graphical user interface. Alternatively or additionally, encryption orchestrator 114 may provide the status to the user via message sending and receiving. Although Figure 4CAs not shown, data storage device 126A can detect anomalies during a health check. In some aspects, data storage device 126A sends anomaly information from health data 488A to storage device server 124A. Storage device server 124A then sends the anomaly information to policy manager 118A. Policy manager 118A notifies encryption orchestrator 114 of status 498A. Encryption orchestrator 114 can provide information about the problems found during the health check in a graphical user interface tool. Additionally or alternatively, encryption orchestrator 114 can transmit status to a user via message sending and receiving.

[0076] As should be understood, Figure 4C Operations 402 to 492A are described for the purpose of illustrating the method and system and are not intended to limit the disclosure to a particular sequence of operations. For example, operations may be performed in different orders, additional operations may be performed, and the disclosed operations may be excluded without departing from the disclosure.

[0077] As should be understood, relative to Figures 4A to 4C The various methods, devices, applications, features, etc., described herein are not examples intended to limit the processing in cloud storage system 110. Therefore, additional topology configurations that can be used to practice the methods and systems described herein without departing from the methods and systems disclosed herein can be excluded.

[0078] Figure 5 The data structure according to the present invention is illustrated. About Figure 5 Information entries for data storage devices in the cloud storage system 110 include, for example, encryption controller ID 501, server ID 502, storage device ID 504, credentials 506, key 508, encryption policy 510, and status 512. Different applications can provide different types of operations as shown in the example.

[0079] Encryption controller ID 501 indicates the encryption controller (e.g. Figure 1 Identifiers 116A to 116B in the diagram. Encryption orchestrator 114 orchestrates multiple encryption controllers 116 in the cloud storage system 110. Figure 5 In the data, the encryption controller ID is indicated by "ABC". Server ID 502 indicates the storage device server in cloud storage system 110 (e.g., Figure 1 The storage device ID 504 is the identifier for storage device servers 124A to 124D. Storage device ID 504 indicates the data storage device (e.g., ...). Figure 1The identifier of data storage devices 126A to 126H is provided, which are connected to the corresponding storage device server. A data structure associates the data storage devices with the storage device servers. Credentials 506 list security credentials that can authenticate the data storage devices. For example, these credentials can be used to lock and unlock data storage device 126. Key 508 indicates a key used to encrypt and / or decrypt data stored in data storage device 126. In some aspects, the key can be locally managed in the corresponding storage device server 124 and / or data storage device 126. The value “LOCAL” in key 508 indicates that the key for a specific storage data server 124 is locally managed by storage data server 124. Encryption policy 510 indicates the type of policy used for at-rest data encryption in the corresponding data storage device. For example, the data storage device may feature data encryption based on the data encryption characteristics of the storage device server's host operating system (e.g., “Host OS-Type-A”). In other examples, the data storage device may feature hardware-based data encryption functionality (e.g., “DISK-HARDWARE”) via a digital signal processor within the data storage device. Status 512 indicates the status of the corresponding data storage device. For example, the value "ENCRYPTED" indicates that the data storage device has activated data encryption at rest. The value "UNENCRYPTED" indicates that the data storage device is storing data without encryption. The value "ACTIVATING…" indicates that the data storage device is in the process of activating data encryption at rest. The value "ERROR" indicates that an error occurred while the storage device was storing data.

[0080] In some respects, regarding data-at-rest encryption in cloud storage system 110, cloud storage system 110 can use data structures to manage defense-in-depth. Encryption orchestrator 114 can use data from data structure 500 to provide information about cloud storage system 110 through a graphical user interface.

[0081] As should be understood, relative to Figure 5 The types and structures of the data, data fields, etc., described herein are not intended to limit the examples of Data Structure 500. Therefore, it can be excluded that data and data fields with additional types and structures can be used to practice the methods and systems and / or components described herein without departing from the methods and systems disclosed herein.

[0082] Figures 6A to 6B An example of an encrypted activation method in a data storage device according to an example system of the present disclosure is illustrated, which can be used to practice the present disclosure.

[0083] The general order of operations in method 600A is as follows: Figure 6AAs shown in the diagram. Typically, method 600A begins with start operation 602 and ends with end operation 616. Method 600A may include more or fewer stages, or may be combined with... Figure 6A The different arrangement sequences are shown. Method 600A can be executed as a set of computer-executable instructions that are executed by a computer system and encoded or stored on a computer-readable medium. Furthermore, method 600A can be executed by gates or circuits associated with a processor, ASIC, FPGA, SOC, or other hardware device. In the following, method 600A should be referred to in conjunction with... Figures 1 to 5 It is explained using the systems, components, devices, modules, software, data structures, data characteristic representations, signaling diagrams, methods, etc., described in sections 7 to 11.

[0084] Operation 604 receives a request from encryption controller 116 to encrypt a storage device server. In some aspects, this request is for encryption activation in a specific storage device server within cloud storage system 110. This request can cause the activation of data-at-rest encryption in one or more data storage devices connected to the specified storage device server. In some other aspects, the request can specify a data storage device connected to the specified storage device server. The specified data storage device can be... Figure 1 One or more data storage devices 126A to 126H are included. In some aspects, the data storage device may be a disk drive. In some other aspects, the data storage device may be a virtual data storage device that is part of a physical data storage device or spans multiple physical data storage devices.

[0085] The withdrawal operation 606 can be performed by the encryption controller 116 to withdraw data from a data storage device in a designated storage device server. In at least some aspects, the withdrawal operation 606 can cause the encryption orchestrator 114 to instruct the storage device server connected to the designated data storage device to move existing data from the designated data storage device to another data storage device. Such data withdrawal may be important to prevent data loss when the designated storage device server or data storage device crashes during activation and the data becomes unrecoverable.

[0086] Operation 608 can be performed by the encryption controller 116 as a pre-check of a specified data storage device. In some aspects, the pre-check may include requesting configuration data and operational status of specific data storage devices 126A to 126H. The types of status data used for the pre-check may include, but are not limited to, connectivity between storage device servers 124A to 124D and key managers 120A to 120B in encryption controllers 116A to 116B, the integrity of encryption and decryption keys managed by key managers 120A to 120B or locally managed by storage device servers 124A to 124D, connectivity between storage device servers 124A to 124D and data storage devices 126A to 126H, network addresses of encryption controllers 116A to 116B and storage device servers 124A to 124D, and the integrity of data storage devices 126A to 126H. The storage device pre-checker 206 can obtain status data by requesting and receiving data from the respective encryption controllers 116 and storage device servers 124. Pre-checking the data storage device before activating encryption reduces the likelihood of encryption failure during subsequent operations. In some respects, pre-checking is effective in preventing data loss, as failed encryption activation can lead to irrecoverable data loss.

[0087] Comparison operation 609 compares whether the pre-check operation was successful (i.e., passed, yes). If the pre-check operation is unsuccessful (i.e., failed, no), the operation moves to execution operation 608. In some other aspects, encryption controller 116 may transmit the error status of the encryption request to encryption orchestrator 114. If the pre-check operation is successful (i.e., passed, yes), the operation proceeds to activation operation 610.

[0088] Activation operation 610 can activate encryption of data at rest in a specified storage device server. In some aspects, activating a specified storage device server may include encrypting some or all existing data stored in the data storage device. A key manager (e.g., 120A to 120B) may send keys to the specified storage device server (e.g., 124A to 124B) for encrypting and decrypting data in the storage device server. In some other aspects, the activation operation may require the specified storage device server to restart itself. During the restart process, a failure of the specified data storage device may occur. In this case, the encryption controller 116 may designate the specified storage device server or another data storage device in another storage device server as an alternative and activate the alternative data storage device.

[0089] Recovery operation 612 can recover data from a specific storage device server. In some respects, recovery operation 612 occurs after confirming that the specified storage device server is active in data encryption at rest and that the specified storage device server is in a normal state. Recovery operation 612 can recover data that was withdrawn before encryption was activated to restore user access.

[0090] Monitoring operation 614 can monitor the health status of a specified storage device server after static encryption in the specified storage device server becomes active. In some aspects, monitoring the health status may include a one-time verification of parameters associated with the specified storage device server and the data storage device. Such parameters may include, but are not limited to, the network address of the data storage device or disk drive, path name, history of hardware and software problems at the data storage device, encryption and decryption keys, security credentials for the specified data storage device (e.g., for locking and unlocking the data storage device), integrity of access permission settings, connectivity between storage device servers 124A to 124D and key managers 120A to 120B in encryption controllers 116A to 116B, integrity of encryption and decryption keys managed by key managers 120A to 120B or locally managed by storage device servers 124A to 124D, connectivity between storage device servers 124A to 124D and data storage devices 126A to 126H, network addresses of encryption controllers 116A to 116B and storage device servers 124A to 124D, and integrity of data storage device 126. Some parameters can be obtained from the data storage device associated with the specified storage device server, the specified storage device server, the key manager (e.g., key managers 120A to 120B), and the permission manager (e.g., permission managers 122A to 122B). In some other aspects, monitoring operation 614 may include the encryption controller 116 periodically requesting health checks, or being triggered, for example, by various events, data access, or idle timeouts during access to the data storage device. In some aspects, monitoring operation 614 may cause the results of monitoring operations based on the encryption controller 116 to generate and transmit alarms and notifications to the encryption orchestrator 114. The encryption orchestrator 114 may provide status information through a graphical user interface and other interactive tools and logs.

[0091] Comparison operation 616 compares whether the health check is successful (e.g., passed, yes). If the health check is unsuccessful (e.g., yes), the operation proceeds to monitoring operation 614 to continue periodic health checks. If the health check is unsuccessful (e.g., no), the operation can proceed to withdrawal operation 606.

[0092] A series of operations 602 to 616 enables the encryption orchestrator 114 to enable the encryption controller 116 to activate the storage device server, which stores unencrypted data, by removing existing data from the storage device server, pre-checking the storage device server before encryption activation, activating the storage device server and data storage device for data at rest encryption, restoring the data to make the data storage device available for access again, and then monitoring the health of the activated storage device server and data storage device to reliably encrypt data at rest. Typically, pre-checking and periodic health checks of the storage device server may take less time than activating the storage device server for data at rest encryption and then encountering failures during or after activation when restarting the storage device server. It should be understood that operations 602 to 616 are described for illustrative purposes of the method and system and are not intended to limit this disclosure to a particular sequence of operations; for example, operations may be performed in a different order, additional operations may be performed, and the disclosed operations may be excluded without departing from this disclosure. A series of operations 604 to 616 are performed by... Figure 6B Reference (A)618 indicates.

[0093] The general sequence of stages in Method 600B is as follows: Figure 6B As shown in the diagram. Typically, method 600B begins with start operation 630 and ends with end operation 642. Method 600B may include more or fewer stages, or may be combined with... Figure 6B The different arrangement sequences are shown. Method 600B can be executed as a set of computer-executable instructions that are executed by a computer system and encoded or stored on a computer-readable medium. Further, method 600B can be executed by gates or circuits associated with a processor, ASIC, FPGA, SOC, or other hardware device. In the following, method 600B should be referred to in conjunction with... Figures 1 to 6A It is explained using the systems, components, devices, modules, software, data structures, data characteristic representations, signaling diagrams, methods, etc., described in sections 7 to 11.

[0094] Method 600B illustrates steps for batch-based, automated, and reliable cryptographic activation on a set of storage device servers and a set of data storage devices specified by a list of storage device servers and storage data devices. In some aspects, method 600B includes a set of operations 604 to 614 for cryptographic activation in the storage device servers and data storage devices, such as... Figure 6A As indicated by (A) in the diagram. The receiving operation 632 is performed by the encryption controller 116 receiving data from a storage device server (e.g., storage device servers 124A to 124D) and a data storage device (e.g., Figure 1A list of one or more data storage devices (126A to 126H) is used for encryption activation. For example, this list may include one or more storage device server IDs and data storage device IDs. Comparison operation 634 compares whether there are any more data storage devices on the list to activate encryption. If there is a data storage device to be activated (636), operation set (A) is performed against the data storage device. In some aspects, operation set (A) includes... Figure 6A Operations 604 to 616 are performed. After executing operation set (A), the operation flow returns to comparison operation 634 to determine whether the list still includes any storage device servers to be activated. When no more storage device servers (and data storage devices) are to be activated (640), the operation flow proceeds to end 642. In some aspects, method 600B automatically activates data at rest encryption in multiple storage device servers and data storage devices in an iterative manner. In some aspects, method 600B can automatically allocate and activate alternative storage device servers and / or alternative data storage devices when the initially assigned storage device server (or data storage device) for activation fails a pre-activation health check, during activation, or after activation. In cloud storage system environments, where tens of thousands of data storage devices and hundreds of storage device servers are grouped and managed by encryption controller 116 and then centrally managed by encryption orchestrator 114, it is crucial to automatically and reliably activate data at rest encryption in the corresponding storage device servers and data storage devices.

[0095] Figure 6BThe illustrated set of operations enables cloud storage system 110 to reliably automate encrypted activation across sets of storage device servers and data storage devices. In some aspects, cloud storage system 110 may include sets of thousands of storage device servers and data storage devices (e.g., data drives) storing unencrypted data. Cloud storage system 110 may need to migrate all storage device servers and data storage devices to provide data-at-rest encryption for defense-in-depth network security. Since activating each storage device server in a set of storage device servers to encrypt data at rest can be time-consuming and prone to failure when restarting storage device servers, the batch operation for activating sets of storage device servers and data storage devices needs to be reliable and efficient. This operation reduces the risk of encountering storage device server and data storage device failures during activation by withdrawing existing data, pre-checking the corresponding storage device servers before activating them, and performing periodic health checks on the activated storage device servers. Additionally or alternatively, the operation may include automated steps to select target storage device servers and data storage devices and switch them from the initial target and failed storage device servers and data storage devices to other storage device servers and data storage devices when errors occur while processing activation requests. Through automated processes, the activation of storage devices, servers, and data storage devices in a cloud storage system can be performed reliably and efficiently.

[0096] It should be understood that operations 630 to 642 are described for the purpose of illustrating the method and system and are not intended to limit the disclosure to a particular sequence of steps. For example, the steps may be performed in a different order, additional steps may be performed, and the disclosed steps may be excluded without departing from the disclosure.

[0097] Figure 7 An example of a user interface according to the present invention is illustrated. In some aspects, the user interface is a graphical user interface that interactively displays the structure of servers and devices under the selection encryption controller 116 of the cloud storage system 110.

[0098] In some respects, Figure 7The encryption orchestrator tool window provides a graphical user interface 700 that displays the hierarchical structure of storage device servers and corresponding data storage devices under the encryption controller 116. As an example, area 702 includes a rendering of the relationship between storage device servers and data storage devices. For example, area 702 shows two storage device servers, rack 0 / server 1 (710) and rack 0 / server 2 (712), among multiple storage device servers managed by the encryption controller with ID "0055" in the cloud storage system 110. Information and status about the respective server are indicated in the corresponding box. For example, rack 0 / server 1 has a HostOS-based data encryption policy and the data drive is locked. The health check status of the storage device server is shown as an error, for example, in the case of a key integrity problem between key manager 120 and storage device server 124, categorized as "key error". Two data storage devices (storage device 1 (740) and storage device 2 (742)) are connected to rack 0 / server 1 (710). Four data storage devices (storage device 3 (744), storage device 4 (746), storage device 5 (748), and storage device 6 (750)) are connected to rack 0 / server 2 (712). Rack 0 / server 2 (712) has a data encryption policy based on the host OS, and the data drives are locked. The health check status of the storage device servers is shown as OK. The content of area 702 can be scrolled to display more servers and data storage devices under the encryption controller. For example, area 702 is vertical by moving the scroll button 706 vertically. Although not shown, the content of area 702 can be scrolled horizontally using the horizontal scroll button.

[0099] The content of area 702 of the graphical user interface 700 can be updated by the user selecting the refresh button 704. When the refresh button is interactively selected, the cryptographic orchestrator 114 can transmit a command, such as a request for storage status command 491A, to the policy manager 118A of the cryptographic controller 116A to receive status information about one or more of the storage device server 124 and data storage devices 126 controlled by the cryptographic controller 116A. In response, the policy manager 118A sends status information (e.g., 492A) to the cryptographic orchestrator 114 to update the information in area 702. In some aspects, area 702 can provide a visual representation of action, where one or more of the storage device server 124 and data storage devices 126 are iteratively activated by updating status information.

[0100] In some aspects, each indication of the storage device server and data storage device indicates the status of the corresponding storage device server and data storage device. For example, storage device 1 (740) (i.e., one of the data storage devices attached to rack 0 / server 1 (storage device server)) currently shows an error status from a health check. For example, such an error indication can be provided as received by cryptographic orchestrator 114 when the status notification includes an error in the data storage device based on a health check. Figure 4B The result of status notification 492A. Storage device 2 (742) encrypts the data at rest, as indicated by “ENCRYPTED”.

[0101] It should be understood that, Figure 7 The structure of the cloud storage system 110 rendered in region 702 is described for the purpose of illustrating the graphical user interface 700 of the method and system, and is not intended to limit the disclosure to a particular sequence of steps, such as steps may be performed in a different order, additional steps may be performed, and the disclosed steps may be excluded without departing from the disclosure.

[0102] As an example of the operating environment of the processing equipment, refer to Figures 8 to 11 The exemplary operating environment described herein. In other instances, components of the system disclosed herein can be distributed across multiple devices and are executable by multiple devices. For example, input can be typed on a client device and information can be processed or accessed from other devices on the network, such as server devices, network devices, other client devices, etc.

[0103] Figures 8 to 11 The related descriptions provide a discussion of the various operational environments in which the various aspects of this disclosure can be practiced. However, relative to... Figures 8 to 11 The devices and systems illustrated and discussed are for illustrative purposes and not a limitation of the vast array of computing device configurations that can be used to practice the various aspects of this disclosure described herein.

[0104] Figure 8This is a block diagram illustrating the physical components (e.g., hardware) of a computing device 800 in which various aspects of this disclosure can be implemented. The computing device components described below can be adapted to the aforementioned computing device, including client computing devices 104A to 104B and encryption orchestrators 114, encryption controllers 116A to 116B, and storage device servers 124A to 124D. In a basic configuration, computing device 800 may include at least one processing unit 802 and system memory 804. Depending on the configuration and type of the computing device, system memory 804 may include, but is not limited to, volatile storage devices (e.g., random access memory), non-volatile storage devices (e.g., read-only memory), flash memory, or any combination of such memory. System memory 804 may include an operating system 805 and one or more program modules 806 adapted to perform various aspects of the disclosure herein, such as a request receiver 204, a storage device pre-checker 206, an encryption activator 208, a storage device health monitor 210, and a status updater 212. For example, operating system 805 may be adapted to control the operation of computing device 800. Furthermore, embodiments of this disclosure may be practiced in conjunction with graphics libraries, other operating systems, or any other applications, and are not limited to any particular application or system. This basic configuration is... Figure 8 The components are illustrated within the dashed line 808. The computing device 800 may have additional features or functionalities. For example, the computing device 800 may also include additional data storage devices (removable and / or non-removable), such as, for example, a hard disk, optical disk, or magnetic tape. Such additional storage devices... Figure 8 The diagram shows removable storage device 809 and non-removable storage device 810.

[0105] As stated above, multiple program modules and data files can be stored in system memory 804. When executed on processing unit 802, program module 806 (e.g., application 820) can perform processes including, but not limited to, the aspects described herein. Other program modules that can be used in this disclosure may include email and contact applications, word processing applications, spreadsheet applications, database applications, PowerPoint presentation applications, drawing or computer-aided applications, etc.

[0106] Furthermore, embodiments of this disclosure can be practiced in electrical circuits including discrete electronic components, in packaged or integrated electronic chips containing logic gates, in circuits utilizing microprocessors, or on a single chip containing electronic components or a microprocessor. For example, embodiments of this disclosure can be practiced via a system-on-a-chip (SOC), wherein... Figure 8Each or many of the components illustrated can be integrated onto a single integrated circuit. Such a SoC device may include one or more processing units, graphics units, communication units, system virtualization units, and various application functionalities, all integrated (or “programmed”) onto a chip substrate as a single integrated circuit. When operating via the SoC, the functionalities described herein with respect to the client switching protocol can be operated via dedicated logic integrated with other components of the computing device 800 on the single integrated circuit (chip). Embodiments of this disclosure can also be practiced using other techniques capable of performing logical operations (e.g., AND, OR, and NOT), including but not limited to mechanical, optical, fluid, and quantum technologies. Furthermore, embodiments of this disclosure can be practiced within a general-purpose computer or in any other circuit or system.

[0107] The computing device 800 may also have one or more input devices 812, such as a keyboard, mouse, pen, voice or speech input device, touch or swipe input device, etc. Multiple output devices 814 may also be included, such as a monitor, speaker, printer, etc. The above devices are examples, and other devices may be used. The computing device 800 may include one or more communication connections 816 that allow communication with other computing devices 850. Examples of suitable communication connections 816 include, but are not limited to, radio frequency (RF) transmitters, receivers, and / or transceiver circuitry; universal serial buses (USB), parallel and / or serial ports.

[0108] As used herein, the term computer-readable medium can include computer storage device media and computer storage media. Computer storage device media and computer storage media can include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, or program modules). System memory 804, removable storage device 809, and non-removable storage device 810 are examples of computer storage device media (e.g., memory storage devices). Computer storage device media can include RAM, ROM, electrically erasable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical storage devices, magnetic cassettes, magnetic tape, disk storage devices or other magnetic storage devices, or any other article of manufacture that can be used to store information and can be accessed by computing device 800. Any such computer storage device media can be part of computing device 800. Computer storage device media does not include carrier waves or other propagated or modulated data signals.

[0109] Communication media can be implemented by computer-readable instructions, data structures, program modules, or other data in modulated data signals (such as carrier waves or other transport mechanisms), and include any information delivery medium. The term "modulated data signal" can describe a signal whose one or more characteristics are set or altered in a manner that encodes information in the signal. By way of example, and not limitation, communication media can include wired media (such as wired networks or direct wired connections) and wireless media (such as acoustic, radio frequency (RF), infrared, and other wireless media).

[0110] Figure 9A and 9B The illustration shows a mobile computing device 900 from which embodiments of this disclosure can be practiced, such as a mobile phone, smartphone, wearable computer (e.g., a smartwatch), tablet computer, laptop computer, etc. In at least some aspects, the client can be a mobile computing device. (See also...) Figure 9A One aspect of a mobile computing device 900 for implementing these aspects is illustrated. In a basic configuration, the mobile computing device 900 is a handheld computer with input and output elements. The mobile computing device 900 typically includes a display 905 and one or more input buttons 910 that allow users to type information into the mobile computing device 900. The display 905 of the mobile computing device 900 can also be used as an input device (e.g., a touchscreen display). If included, optional side input elements 915 allow for further user input. The side input elements 915 can be rotary switches, buttons, or any other type of manual input element. In alternative aspects, the mobile computing device 900 can include more or fewer input elements. For example, in some embodiments, the display 905 may not be a touchscreen. In yet another alternative embodiment, the mobile computing device 900 is a portable telephone system (such as a cellular phone). The mobile computing device 900 may also include an optional keypad 935. The optional keypad 935 can be a physical keypad or a “soft” keypad generated on a touchscreen display. In various embodiments, the output element includes a display 905 for displaying a graphical user interface (GUI), a visual indicator 920 (e.g., a light-emitting diode), and / or an audio transducer 925 (e.g., a speaker). In at least some aspects, the mobile computing device 900 includes a vibration transducer for providing tactile feedback to a user. In yet another aspect, the mobile computing device 900 includes input and / or output ports for sending signals to or receiving signals from external devices, such as audio inputs (e.g., a microphone jack), audio outputs (e.g., a headphone jack), and video outputs (e.g., an HDMI port).

[0111] Figure 9BThis is a block diagram illustrating the architecture of one aspect of a mobile computing device. Specifically, the mobile computing device 900 may include a system (e.g., architecture) 902 to implement some aspects. In one embodiment, the system 902 is implemented as a "smartphone" capable of running one or more applications (e.g., browser, email, calendar, contact manager, messaging client, game, and media client / player). In at least some aspects, the system 902 is integrated as a computing device, such as integrating a personal digital assistant (PDA) and a wireless phone.

[0112] One or more applications 966 may be loaded into memory 962 and run on or associated with operating system 964. Examples of applications include telephone dialer programs, email programs, personal information management (PIM) programs, word processing programs, spreadsheet programs, internet browser programs, messaging programs, etc. System 902 also includes a non-volatile storage device area 968 within memory 962. The non-volatile storage device area 967 may be used to store persistent information that should not be lost if system 902 is powered off. Applications 966 may use and store information in the non-volatile storage device area 967, such as emails or other messages used by email applications. A synchronization application (not shown) also resides on system 902 and is programmed to interact with a corresponding synchronization application residing on the host computer to keep the information stored in the non-volatile storage device area 967 synchronized with the corresponding information stored on the host computer. It should be understood that other applications can be loaded into memory 962 and run on the mobile computing device 900 described herein (e.g., search engine, extractor module, relevance ranking module, answer scoring module, etc.).

[0113] System 902 has a power supply 950, which can be implemented as one or more batteries. The power supply 950 may also include an external power source, such as an AC adapter or power docking bracket for replenishing or recharging the batteries.

[0114] System 902 may also include a radio interface layer 952, which performs the functions of transmitting and receiving radio frequency communications. Radio interface layer 952 facilitates wireless connectivity between system 902 and the "external world" via a communications operator or service provider. Transmissions to and from radio interface layer 952 are performed under the control of operating system 964. In other words, communications received by radio interface layer 952 can be distributed to application program 966 via operating system 964, and vice versa.

[0115] A visual indicator 920 can be used to provide visual notifications, and / or an audio interface 954 can be used to generate audible notifications via an audio transducer 925. In the illustrated configuration, the visual indicator 920 is a light-emitting diode (LED), and the audio transducer 925 is a speaker. These devices can be directly coupled to a power supply 950 such that, when activated, they remain on for a duration specified by the notification mechanism, even if the processor 960 and other components may be turned off to conserve battery power. The LED can be programmed to remain on indefinitely until the user takes an action to indicate the device's power-on status. The audio interface 954 is used to provide audible signals to and receive audible signals from the user. For example, in addition to being coupled to the audio transducer 925, the audio interface 954 can also be coupled to a microphone to receive audible input, such as facilitating telephone conversations. According to embodiments of this disclosure, the microphone can also act as an audio sensor to facilitate control of the notification, as described below. System 902 may also include a video interface 956, which enables the operation of the vehicle camera 930 to record still images, video streams, etc.

[0116] The mobile computing device 900 implementing system 902 may have additional features or functionalities. For example, the mobile computing device 900 may also include additional data storage devices (removable and / or non-removable), such as disks, optical discs, or magnetic tapes. Such additional storage devices... Figure 9B The diagram shows area 967 of the non-volatile storage device.

[0117] Data / information generated or captured by mobile computing device 900 and stored via system 902 can be locally stored on mobile computing device 900, as described above, or the data can be stored on any number of storage media that can be accessed by the device via radio interface layer 952 or via a wired connection between mobile computing device 900 and a separate computing device associated with mobile computing device 900 (e.g., a server computer in a distributed computing network such as the Internet). It should be understood that such data / information can be accessed via mobile computing device 900, via radio interface layer 952, or via a distributed computing network. Similarly, according to well-known data / information transmission and storage device components, including email and collaborative data / information sharing systems, such data / information can be easily transferred between computing devices for storage and use.

[0118] Figure 10The illustration depicts one aspect of a system architecture for processing data received from a remote source at a computing system, such as a general-purpose computing computer 1004, a tablet computing device 1006, or a mobile computing device 1008, as described above. Content displayed at server device 1002 can be stored in different communication channels or other storage device types. For example, various documents can be stored using a directory service 1022, a web portal 1024, an email service 1026, an instant messaging repository 1028, or a social networking site 1030. An encryption executor tool 1021 can be used by a client communicating with server device 1002, and / or a classification component 1020 can be used by server device 1002. Server device 1002 can provide data between client computing devices (such as personal computers 1004, tablet computing devices 1006, and / or mobile computing devices 1008 (e.g., smartphones)) via network 1015. By way of example, the above-described computer system can be implemented in a personal computer 1004, a tablet computing device 1006, and / or a mobile computing device 1008 (e.g., a smartphone). In addition to receiving graphics data that can be preprocessed at the graphics originating system or post-processed at the receiving computing system, any embodiment of these computing devices can obtain content from a data repository having data-at-rest encryption 2106. In some aspects, server 1002, a data repository having data-at-rest encryption 2016, a directory service, web portal 1024, email service 1026, instant messaging repository 1028, and social networking service 1030 can constitute a cloud storage system.

[0119] Figure 11 An exemplary tablet computing device 1100 is illustrated, capable of performing one or more aspects of the present invention. Furthermore, the aspects and functionalities described herein can operate on a distributed system (e.g., a cloud-based computing system), where application functionalities, memory, data storage devices and retrieval, and various processing functions can remotely operate on each other via a distributed computing network (such as the Internet or an intranet). Various types of user interfaces and information can be displayed via an in-vehicle computing device display or via a remote display unit associated with one or more computing devices. For example, various types of user interfaces and information can be displayed and interacted with on a wall where various types of user interfaces and information are projected. Interaction with numerous computing systems to which embodiments of the invention can be practiced includes keystroke typing, touchscreen typing, voice or other audio typing, gesture typing, wherein the associated computing device is equipped with detection (e.g., camera) functionality for capturing and interpreting user gestures to control the functionality of the computing device, etc.

[0120] The descriptions and illustrations of one or more aspects provided in this application are not intended to limit or constrain the scope of the claimed disclosure in any way. The aspects, examples, and details provided in this application are considered sufficient to convey ownership and enable others to make and use the best mode of the claimed disclosure. The claimed disclosure should not be construed as limited to any aspect, example, or detail provided in this application. Various features (structural and methodological) are intended to be selectively included or omitted, whether in combination or separately, to produce embodiments with a particular set of features. Given the descriptions and illustrations provided in this application, those skilled in the art will anticipate variations, modifications, and alternatives falling within the spirit of the broader aspects of the general inventive concept practiced in this application, without departing from the broader scope of the claimed disclosure.

[0121] One aspect of this document may include a computer-implemented method for activating encryption in a data storage device. The method includes: receiving a request to activate encryption on a storage device server, wherein the storage device server includes a data storage device; performing a pre-check on the storage device server; encrypting data stored in the storage device server when the pre-check is successful; monitoring the operational status of the storage device server while the data stored in the data storage device is encrypted; and periodically providing the operational status of the storage device server.

[0122] In another aspect, the pre-check includes verifying the server configuration of the storage device server, which includes encryption and decryption keys for the storage device server.

[0123] On the other hand, the operational status of the storage device server includes one or more of the following: the network address of the data storage device, the connectivity status between the storage device server and the key server, the security credentials of the data storage device, and the access permissions of the data storage device.

[0124] In another aspect, the method further includes sending a status failure notification when the pre-check fails and rejecting the request for encryption to activate the storage device server.

[0125] On the other hand, encrypting data stored on a storage device server also includes encryption by the host operating system of the storage device server, wherein the data storage device is attached to the storage device server.

[0126] On the other hand, the encryption of data stored in the data storage device is performed by a data encryption processor embedded in the data storage device.

[0127] In another aspect, the method further includes: identifying a candidate data storage device when an error occurs during the execution of a pre-check on the data storage device; performing a pre-check on the candidate data storage device; encrypting the data stored in the candidate data storage device when the pre-check on the candidate data storage device is successful; monitoring the operational status of the candidate data storage device when the data stored in the candidate data storage device has been encrypted; and periodically providing the operational status of the candidate data storage device.

[0128] In another aspect, the method further includes: withdrawing data from the data storage device to an alternative data storage device; encrypting the withdrawn data on the alternative data storage device; and restoring the encrypted withdrawn data back to the data storage device.

[0129] In another aspect, the method further includes: receiving a list of multiple storage device servers in a cloud storage system; and iteratively activating encryption across the multiple storage device servers.

[0130] In another aspect, providing the operational status of the storage device server includes generating a visual representation of multiple storage device servers and data storage devices in the cloud storage system, the visual representation of the multiple storage device servers and data storage devices including: a storage device server; and one or more data storage devices attached to the storage device server, wherein the one or more data storage devices include data storage devices; updating the visual representation of the operational status of the data storage devices; and generating a visual representation of an iterative action set, the iterative action including static encryption of data in at least one of the one or more data storage devices.

[0131] In another scenario, this method is executed by the cryptographic controller.

[0132] In another approach, the method is performed by a cryptographic orchestrator.

[0133] Another aspect of this document may include a cloud storage system comprising a storage device server having at least one data storage device, an encryption orchestrator, and an encryption controller. The encryption orchestrator includes a processor and a memory storing computer-executable instructions that, when executed, cause the processor to provide a graphical representation of the storage device server to at least one data storage device and interactively receive commands to activate encryption of data in the data storage device. The encryption controller includes a processor and a memory storing computer-executable instructions that, when executed, cause the processor to: receive a request to activate encryption of the data storage device; perform a pre-check of the data storage device; encrypt data stored in the data storage device when the pre-check is successful; monitor the operational status of the data storage device when the data stored in the data storage device has been encrypted; and periodically provide the operational status of the data storage device to the encryption orchestrator.

[0134] In another aspect, the encryption controller also includes: a key manager, which stores encryption keys for statically encrypting data on at least one storage device server; and a policy manager, which provides a set of policies for encryption activation on at least one storage device server.

[0135] In another aspect, the cryptographic controller also includes computer-executable instructions that, when executed, cause the processor to remove data from the data storage device if the pre-check fails.

[0136] In another aspect, the encryption controller also includes computer-executable instructions that, when executed, cause the processor to receive a list of multiple data storage devices and iteratively activate encryption in the multiple data storage devices.

[0137] In another aspect, the cryptographic orchestrator also includes computer-executable instructions that, when executed, cause the processor to generate visual representations of multiple devices in the cloud storage system, update visual representations of the operational states of data storage devices, and generate visual representations of a set of interactive actions, the iterative actions including statically encrypting data in at least one of one or more data storage devices. The visual representations of the multiple devices include a storage device server and one or more data storage devices attached to the storage device server. The one or more data storage devices include data storage devices.

[0138] Another aspect of this document may include a computer storage medium storing computer-executable instructions for encrypting the activation of a plurality of data storage devices, which, when executed by a processor, cause the processor to: receive a first request to activate the encryption of static data in a first server, wherein the first server includes a plurality of data storage devices; perform a first pre-check on the first server; encrypt data stored in the first server when the first pre-check is successful; monitor the operational status of the plurality of data storage devices connected to the first server when the data stored in the first server has been encrypted; and periodically provide the operational status of the first server and the plurality of data storage devices connected to the first server.

[0139] In another aspect, the computer storage medium also includes computer-executable instructions that, when executed by a processor, cause the processor to: receive a second request to activate static data encryption in a second server, wherein the second server includes a plurality of data storage devices; perform a second pre-calibration on the second server, wherein the second pre-calibration verifies at least one decryption key in the second server used for data decryption; and, if the second pre-calibration fails, send an error message.

[0140] In another aspect, the computer storage medium also includes computer-executable instructions that, when executed by a processor, cause the processor to identify alternative data storage devices when a second pre-check of the second server results in an error.

Claims

1. A computer-implemented method for activating encryption in a storage device server, the computer-implemented method comprising: receiving a request to activate the encryption of the storage device server, wherein the storage device server comprises a data storage device; processing pre-checks of the storage device server, including testing pre-requisites for successful activation of static data encryption on the storage device server; encrypting data stored in the storage device server when the pre-checks of the storage device server are successful; monitoring an operational status of the storage device server when the data stored in the data storage device has been encrypted; and periodically providing the operational status of the storage device server.

2. The computer-implemented method of claim 1, wherein the pre-checks further comprise reading and verifying a server configuration of the storage device server, the server configuration comprising encryption and decryption keys for the storage device server.

3. The computer-implemented method of claim 1, wherein the operational status of the storage device server comprises one or more of: a network address of the storage device server, a status of connectivity between the storage device server and a key server, security credentials of the storage device server, and access permissions of the storage device server.

4. The computer-implemented method of claim 1, further comprising: sending a status failure notification when the pre-checks fail, and denying the request to activate the encryption of the storage device server.

5. The computer-implemented method of claim 1, wherein encrypting the data stored in the storage device server further comprises: encrypting the data based on a host operating system of the storage device server, wherein the data storage device is attached to the storage device server.

6. The computer-implemented method of claim 1, wherein encrypting the data stored in the storage device server is performed by a data encryption processor embedded in the data storage device.

7. The computer-implemented method of claim 1, further comprising: identifying an alternative data storage device when the pre-checks of the storage device server fail; processing alternative pre-checks of the alternative data storage device; encrypting the data stored in the alternative data storage device when the alternative pre-checks of the alternative data storage device are successful; monitoring an operation of the alternative data storage device when the data stored in the alternative data storage device has been encrypted; and periodically providing the status of the alternative data storage device.

8. The computer-implemented method of claim 7, further comprising: removing the data from the data storage device; restoring the data to the data storage device after the encryption of the data stored in the alternative data storage device based on the alternative pre-checks.

9. The computer-implemented method of claim 1, further comprising: receiving a list of a plurality of the storage device servers in a cloud storage system; and ​ ​ iteratively activating the encryption in the plurality of the storage appliance servers.

10. The computer-implemented method of claim 9, wherein providing the operational status of the storage appliance servers further comprises: generating a visual representation of the plurality of the data storage devices in the plurality of the storage appliance servers and the cloud storage system; updating the visual representation of the operational status of the data storage devices; and generating the visual representation of an iterative action comprising statically encrypting the data in at least one of the plurality of the storage appliance servers.

11. The computer-implemented method of claim 1, wherein the computer- implemented method is performed by an encryption controller.

12. The computer-implemented method of claim 1, wherein the computer- implemented method is performed by an encryption orchestrator.

13. A cloud storage system having static data encryption, the cloud storage system comprising: a storage appliance server having at least one data storage device; an encryption orchestrator comprising: a first processor; and a first memory storing a first set of computer-executable instructions that, when executed, cause the first processor to: provide a graphical representation of the storage appliance server to the at least one data storage device; and transmit a command to activate data encryption in the storage appliance server; and an encryption controller comprising: a second processor; and a second memory storing a second set of computer-executable instructions that, when executed, cause the second processor to: receive a request to activate the data encryption in the storage appliance server; perform a pre-check of the storage appliance server comprising testing preconditions for successful activation of static data encryption on the storage appliance server; when the pre-check of the storage appliance server is successful, perform the data encryption in the storage appliance server; when the data encryption in the storage appliance server is successful, periodically monitor an operational status of the storage appliance server; and periodically provide the operational status of the storage appliance server to the encryption orchestrator.

14. The cloud storage system of claim 13, wherein the encryption controller further comprises: a key manager, wherein the key manager comprises encryption keys for the static data encryption on the storage appliance server; and a policy manager, wherein the policy manager provides a set of policies for the data encryption in the storage appliance server.

15. The cloud storage system of claim 13, wherein the encryption controller further comprises a second set of computer-executable instructions that, when executed, cause the second processor to: when the pre-check is successful, clear data in a storage appliance server.

16. The cloud storage system of claim 15, wherein, the encryption controller further comprises the second set of computer- executable instructions that, when executed, cause the second processor to: receiving a list of a plurality of the storage appliance servers; and iteratively activating encryption in the plurality of storage appliance servers.

17. The cloud storage system of claim 15, wherein the encryption orchestrator further comprises a first set of computer-executable instructions that, when executed by the first processor, cause the first processor to: generate a first visual representation, wherein the first visual representation further comprises: the storage appliance server; and the at least one data storage device; provide a second visual representation, wherein the second visual representation comprises the operational status of the at least one data storage device; and generate a third visual representation, wherein the third visual representation comprises a set of iterative activations of the static data encryption in the storage appliance server.

18. A computer storage medium storing computer-executable instructions for activation of static data encryption in a server, which when executed by a processor cause the processor to: receive a first request to activate the static data encryption in a first server, wherein the first server comprises a first set of data storage devices; perform a first pre-check of the first server, comprising testing pre-requisites for successful activation of static data encryption on the storage appliance server; when the first pre-check is successful, encrypt the data stored in the first server; when the data stored in the first server has been encrypted, monitor an operational status of the first server and the first set of data storage devices connected to the first server; and periodically provide the operational status of the first server and the first set of data storage devices.

19. The computer storage medium of claim 18, further comprising the computer- executable instructions, which when executed by the processor, cause the processor to: receive a second request to activate the static data encryption in a second server, wherein the second server comprises a second set of data storage devices; perform a second pre-check of the second server and the second set of data storage devices, wherein the second pre-check comprises verifying at least one decryption key for data decryption in the second server; and when the second pre-check is unsuccessful, send an error message.

20. The computer storage medium of claim 19, further comprising the computer- executable instructions, which when executed by the processor, cause the processor to: when the second pre-check of the second server is in error, identify a third server with a third set of data storage devices.

Citation Information

Patent Citations

  • Mobile operation and maintenance management platform safe operation and big data application system under cloud environment

    CN109284839A

  • Intercepting calls for encryption handling in persistent access multi-key systems

    US20190081990A1