Managing access to tape cartridges at tape archiving service providers

By using key encryption and decryption mechanisms in the tape cartridge, it solves the problem of users' difficulty in accessing quickly and data security, and realizes the secure encrypted storage and transmission of data in the tape archive service, supporting the secure migration and upgrade of the tape cartridge.

CN120344963APending Publication Date: 2025-07-18INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380084052.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-09
Filing Date
2023-11-21
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In existing tape archiving services, it is difficult for users to quickly access archived tape cartridges, and data security is difficult to guarantee, especially when data is not stored encrypted, tape archiving service providers may abuse sensitive data.

Method used

By storing the key encryption key in the nonvolatile memory of the tape cartridge, using the user's public key signature and product-specific private key decryption, ensuring that only the legitimate tape driver can access the user's encryption key, realizing encrypted transmission and storage of data.

Benefits of technology

It realizes the secure encrypted storage and transmission of tape cartridge data, ensuring that only legitimate users can access the data, prevent unauthorized access, and supports the secure reproduction of data during the migration and upgrade of tape cartridges.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120344963A_ABST
    Figure CN120344963A_ABST
Patent Text Reader

Abstract

A computer program product, system, and method are provided for managing access to a tape cartridge at a tape archiving service provider. It is determined whether a non-volatile memory of the tape cartridge stores a key encryption key, the key encryption key including an encrypted user encryption key associated with a user. In response to determining that the non-volatile memory of the tape cartridge stores the key encryption key, the key encryption key is decrypted to generate a user encryption key. The user encryption key resulting from the decryption is provided to a tape-driven encryption engine to encrypt the plaintext data read from the tape medium in the tape cartridge using the user encryption key to return to the read request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a computer program product, system, and method for managing access to tape cartridges at a tape archival service provider. Background Art

[0002] Some companies offer tape archival services to allow users to offload the archival storage of backup tape cartridges to a tape archival service provider. The tape archival service provides a secure and climate-controlled environment for storing the archived tape cartridges, minimizing physical degradation over time. Typically, when a user needs to retrieve data from a tape cartridge, the tape archival service transports the tape cartridge from the storage facility to the user.

[0003] One drawback of tape archival services is that it is cumbersome for users to access tape cartridges that have been sent to archival when needed, because users typically have to wait for the tape cartridges to be physically returned to them. Additionally, if data is stored in plain text on the tape cartridges, someone at the service provider's facility may access the tape cartridges to misuse sensitive data. If the service provider is not provided access to the encryption keys to access the encrypted data stored in the tape drives, the service provider may be unable to transfer the user data from older tape cartridges to the latest tape cartridge generation, which can typically store much more data than the previous generation of tape cartridges.

[0004] There is a need in the art for improved techniques to provide tape archival services to users having a collection of tape cartridges. Summary of the Invention

[0005] A first embodiment provides a computer program product, system, and method for managing access to tape cartridges at a tape archival service provider. Determine whether a non-volatile memory of the tape cartridge stores a key encryption key that includes an encrypted user encryption key associated with a user. In response to determining that the non-volatile memory of the tape cartridge stores the key encryption key, decrypt the key encryption key to produce the user encryption key. Provide the decrypted user encryption key to an encryption engine of the tape drive to encrypt plain text data read from the tape medium in the tape cartridge using the user encryption key for return to a read request.

[0006] The first embodiment provides security and encryption protocols to prevent unauthorized users from reading the plaintext data on the tape cartridge by enabling the tape drive at the tape archival service to access the user encryption key in the key encryption key maintained in the tape cartridge. This allows the tape drive to securely access the user encryption key through a series of encryptions, and then use the user encryption key to encrypt the data read from the tape cartridge for providing to the read request, and decrypt the encrypted write data provided to the tape drive for writing to the tape cartridge. In this way, the tape drive ensures that the plaintext data on the tape cartridge remains secure and is protected by encrypting any external transmission of the data with the encryption key provided by the user who stores the data in the tape cartridge.

[0007] Optionally, the first embodiment may include signing the key encryption key in the non-volatile memory of the tape cartridge with the user private key associated with the user. The non-volatile memory of the tape cartridge includes the user public key. The operations of storing the key encryption key and the user public key in the non-volatile memory of the tape cartridge include using the user public key to authenticate the signed key encryption key to generate the key encryption key. Decrypting the key encryption key is performed in response to authenticating the signed key encryption key.

[0008] With the optional embodiment added above, the signing of the key encryption key and the use of the user public key for authentication ensure to the tape drive that the key encryption key is provided by the real user. After authenticating the user who writes the key encryption key to the tape cartridge, the key encryption key can be decrypted to generate the user encryption key while the user is authenticated.

[0009] Optionally, the first embodiment may further include that the key encryption key includes the user encryption key encrypted with the product-specific public key associated with the tape drive. The key encryption key is decrypted with the product-specific private key maintained in the tape drive to generate the user encryption key for encrypting the plaintext data read from the tape medium.

[0010] With the optional embodiment added above, the user can securely store the key encryption key in the tape cartridge, which includes the user encryption key encrypted with the product-specific public key, and only the tape drive can decrypt it using the product-specific secret key maintained by the tape drive. In this way, the user ensures that only the legitimate tape drive will be able to decrypt the key encryption key to obtain the user encryption key, because only the authorized tape drive will have the product-specific secret key.

[0011] Optionally, the first embodiment may further include receiving a read request for the plaintext data in the tape medium. In response to the read request, the encryption engine may use the user encryption key to encrypt the requested plaintext data from the tape medium to return the encrypted requested plaintext data to the read request.

[0012] Using the optional embodiments appended above, although the tape cartridge stores plaintext data, the tape drive only returns encrypted data (encrypted with the user encryption data) in response to a read request, to ensure that only the user who wrote the data to the cartridge can read and access the encrypted read data, because the plaintext data on the tape cartridge can only be decrypted with the user encryption key securely maintained by the user.

[0013] Optionally, the first embodiment may also provide that the tape drive includes a source tape drive, the tape cartridge includes a source tape cartridge, and the tape medium includes a source tape medium. Further, the read request includes an operation of transferring encrypted plaintext data from the source tape medium to a destination tape medium in a destination tape cartridge coupled to a destination tape drive. In this case, the key encryption key is transferred from the source tape drive to the destination tape drive for storage in the destination tape drive. The destination tape drive decrypts the transferred key encryption key to generate a user encryption key for decrypting the plaintext data transferred from the source tape drive to generate plaintext data to be written to the destination tape medium.

[0014] Using the embodiments appended above, the encrypted read mode is used to transfer encrypted plaintext data from one or more source tape drives to a destination tape drive, where the destination tape drive must decrypt to store the plaintext data on the tape. This can be performed when upgrading a tape cartridge to a higher capacity destination tape cartridge. Further, the key is copied from the source tape cartridge to the destination tape cartridge, so the destination tape cartridge has the same encrypted read mode setting as the source tape cartridge. This allows the destination tape cartridge to be handled in the same manner as the source cartridge. Still further, this migration method enables secure reproduction of the contents of the tape medium 208 by migrating to a new destination drive after encrypting the data.

[0015] The second embodiment provides a computer program product, system, and method for managing access to a tape cartridge at a tape archival service provider. Plaintext data is received from a user computer associated with a user for writing to the tape medium of the tape cartridge. A product-specific public key associated with the tape drive is sent to the user computer. Then a key encryption key is received from the user computer, the key encryption key including a user encryption key associated with the user encrypted with the product-specific public key. The product-specific public key and the product-specific private key are maintained in the tape drive and are a pair of keys in a cryptographic system. The key encryption key is decrypted with the product-specific private key to generate a user encryption key. The plaintext data read from the tape medium is encrypted using the user encryption key for return in response to a read request.

[0016] Using the second embodiment above, the user computer can provide a key encryption key encrypted with the tape drive product-specific public key for the tape drive to use with the tape cartridge now. Encrypting the user encryption key with the product-specific public key assures the user that only a legitimate tape drive including the product-specific private key can access the user encryption key to encrypt the plaintext data read from the tape drive.

[0017] Optionally, the second embodiment can also perform storing the key encryption key in the non-volatile memory of the tape cartridge. When it is detected that the tape cartridge is reinserted into the tape drive after being ejected from the tape drive, the key encryption key is accessed from the non-volatile memory of the reinserted tape cartridge. The accessed key encryption key is decrypted with the product-specific private key to generate the user encryption key for encrypting the plaintext data read from the tape medium.

[0018] Using the above optional embodiment, a new key encryption key stored in the non-volatile memory of the tape cartridge can now be accessed when received from the user and when the tape cartridge is reinserted into the tape drive, such that the tape drive accesses the new key encryption key stored in the tape cartridge to decrypt to generate the user encryption key for encrypting data for read-back and decrypting data for writing in plaintext.

[0019] Optionally, the second embodiment can also include that the received key encryption key includes a first key encryption key and the user encryption key includes a first user encryption key. Determine whether decryption successfully generates the first user encryption key. In response to determining that decryption successfully generates the user encryption key, store the first key encryption key in the non-volatile memory of the tape cartridge. Storing the first key encryption key overwrites a second key encryption key stored in the non-volatile memory of the tape cartridge, the second key encryption key including a second user encryption key associated with the user and encrypted with the product-specific public key. The second key encryption key was stored in the non-volatile memory of the tape cartridge before the first key encryption key was received from the user.

[0020] Using the above optional embodiment, the first key encryption key provided by the user is used to update and overwrite the previous key encryption key stored in the tape cartridge for read operations and write operations in the future when the tape cartridge is reinserted into the tape drive. This allows the user to update the user encryption key maintained in the tape cartridge for future read operations and write operations on the storage cartridge. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 An embodiment of a tape archival environment is illustrated.

[0022] Figure 2 An embodiment of a tape drive and a tape cartridge is illustrated.

[0023] Figure 3 An embodiment of a user computer is illustrated, which is used to perform operations related to tape drives and tape cartridges at a tape archival service provider.

[0024] Figure 4 An embodiment of operations performed when a tape cartridge is loaded in a tape drive to access a user encryption key is illustrated.

[0025] Figure 5 An embodiment of operations performed by a tape archival service provider to process a user request to read data from a user tape cartridge sent to the tape archival service provider is illustrated.

[0026] Figure 6 An embodiment of operations performed by a tape archival service provider to process a user request to write data to a user tape cartridge sent to the tape archival service provider is illustrated.

[0027] Figure 7 An embodiment of the arrangement of source and destination tape drives in a tape library for migrating data from one or more source tapes to a destination tape in a destination tape drive is illustrated.

[0028] Figure 8 An embodiment of operations for copying data from a source tape cartridge in a source tape drive to a destination tape cartridge in a destination tape drive is illustrated.

[0029] Figure 9 An embodiment of operations performed by a user computer and a tape archival service provider to update a user encryption key for a tape cartridge at the tape archival service provider is illustrated.

[0030] Figure 10 Illustrated is where Figure 1 and Figure 2 can be implemented DETAILED DESCRIPTION

[0031] The described embodiments provide improvements to computer technology for accessing plaintext data on tape cartridges maintained by a tape archival service. The described embodiments provide security and encryption protocols to prevent unauthorized users from reading the plaintext data on a tape cartridge by enabling a tape drive at the tape archival service to access a user encryption key in a key encryption key maintained in the tape cartridge. This allows the tape drive to securely access the user encryption key through a series of encryption and signature operations, and then use the user encryption key to encrypt data read from the tape cartridge for a read request, and decrypt the encrypted write data provided to the tape drive for writing to the tape cartridge. In this way, the tape drive ensures that the plaintext data on the tape cartridge remains secure and is protected by encrypting any external transfer of data with the encryption key provided by the user who stored the data in the tape cartridge.

[0032] In addition, by enabling the tape drive to unwrap the user encryption key from the source tape cartridge, the source tape drive can migrate the plaintext data encrypted with the user encryption key obtained from the source tape cartridge on the source tape cartridge to the destination tape cartridge, and copy the key encryption key from the source tape drive for storage in the destination tape cartridge. In this way, the destination tape cartridge can unwrap the same user encryption key from the key encryption key copied to the destination tape cartridge to decrypt the encrypted transfer data for storage in plaintext in the destination tape cartridge. In this way, the tape drive at the tape archival service provider does not have to obtain the key from a key manager, but can obtain the key from the tape cartridge with the data to be accessed or transferred.

[0033] Figure 1 An embodiment of a tape archival environment is illustrated, which shows a tape archival service provider 100 facility having one or more tape libraries 102 and tape cartridges 202 provided by or on behalf of users of the tape archival service provided by the service provider i ( Figure 2 ) of storage tapes 104. The service provider server 106 includes a server request manager 108 to receive requests from a user computer 300 on a network 110 i to access data in a tape cartridge 202 that the user has sent to the tape archival service provider 100 for archival i .

[0034] The tape library 102 includes a magazine 112 for the tape cartridges 202 i , an accessor 114 having a robotic picker assembly and a barcode reader, the robotic picker assembly for grasping a tape cartridge in the magazine 112 and moving it to another magazine or storage slot or tape drive 2001, 2002... 200 none of the tape drives, and the barcode reader is used to read the barcode on the tape cartridge 202 i ; and a library controller 116 that receives requests for data in the tape cartridge and controls the accessor 114 to load the tape cartridge 202 i and direct user read requests and write requests from the user computer 300 to the tape drives 2001, 2002... 200 n . The library controller 116 has information about the different tape drives 2001, 2002... 200 n , the cartridges 112 and the tape cartridges 202 at the storage tape 104 i . The service provider server 106 and the tape library 102 can communicate through the local network 118 of the tape archive service provider 100

[0035] Figure 2 illustrates an embodiment of the tape drive 200 i that includes a controller 204 that receives read requests and write requests and controls the head system 206 to read data from and write data to the mounted tape storage medium 208 in the tape cartridge 202 loaded into the tape drive 200 i i . The controller 204 can buffer data for read requests and write requests in the cache 210 such that the read data in the tape medium 208 is buffered in the cache 210 before being transferred to the service provider server 106 for return to the user computer 300 i and such that the write data from the user computer 300 i is buffered before being written to the tape storage medium 208. The tape drive 200 i also includes an encryption engine 212 into which the user encryption key DK 302 is loaded from the user computer 300 i for encrypting the plaintext data read from the tape medium 208 for return to the read request and decrypting the received encrypted write data to write the plaintext data to the tape medium 208

[0036] The cache 210 can buffer various keys used during the encryption process, including: a product-specific secret key (PS-SK) 214 (e.g., a private key), and a product-specific public key (PS-PK) 216, which are keys associated with the tape drive 200 i and are a pair of keys in a cryptosystem such as a public key infrastructure; from the user computer 300 i ​The received user public key 304, which is part of a key pair from a cryptographic system that includes a user secret key 306 (e.g., a private key) stored in the non-volatile memory 308 of the user computer 300 i ; the user encryption key DK 302 provided from the user computer 300 i ; the key encryption key (KEK) 218, which includes the user encryption key (DK) 302 encrypted at the user computer 300 i with the product-specific public key 216; and the signed KEK - (S-KEK) 310, which includes the KEK 218 signed at the user computer 300 i with the user private key 304 and stored in the non-volatile memory 220 of the cartridge 202 i , from where the S-KEK is loaded into the cache 210 of the tape drive 200 i . The user encryption key DK 302 can include an asymmetric key or a user encryption public key in the cryptographic system to encrypt data, where the user computer 300 i will maintain the user encryption private key in the pair to decrypt the data encrypted by the user encryption public key. The non-volatile memory 220 of the cartridge 202 i also stores the US-PK 304 for verifying the signature of the S-KEK 310 signed with the US-SK 306 at the user computer 300 i .

[0037] The tape drive 200 i includes a non-volatile memory 222 to persistently store the PS-SK 214 and the PS-PK 216, which are then loaded into the cache 210 for use during operation. The tape drive controller 204 includes a request manager 224 to manage read requests and write requests from the user, and an encryption mode manager 226 to determine whether to set the encrypted read (ER) mode 228 to indicate that the data read from the tape medium 208 is encrypted before returning the data to the read request, and to write the data to the tape medium 208 after the written data is decrypted.

[0038] Figure 3 The user computer 300 i can include service provider client code 311 (such as a toolkit provided by a tape archival service provider to enable the user computer 300 i to interact with the service provider server 106), and can include a read / write interface 312 to the user cartridge 202 maintained by the tape archival service provider 100 iSend read requests and write requests; the cartridge transfer manager 314 prepares the cartridge 202 for transfer to the tape archive service provider 100 (such as by writing the S-KEK 310 and US-PK 304 to the cartridge 202 i by writing to the non-volatile memory 220); and the encryption read mode updater 316 updates the user encryption key DK302 for the cartridge residing at the tape archive service provider 100 i . The cartridge transfer manager 314 can create the S-KEK 310 by first encrypting the user encryption key 302 with the PS-PK 216 to generate the KEK218 (i.e., KEK = {DK} U ), and then signing the KEK 218 with the US-SK 306 (i.e., S-KEK = [KEK] PS-PK ). US-SK .

[0039] In an additional embodiment, the user may use a native tape drive tool or backup program at the user computer 300 i for the user computer 300 i to write to the cartridge 202 i by writing the US-PK 304 and S-KEK 310 to the cartridge 202 i . In an additional embodiment, the user may pass requests to read data or write data to the service provider server 106 via a website provided by the tape archive service provider.

[0040] In an alternative embodiment, the (one or more) tape drives may be directly connected to the service provider server or the user computer. In an additional embodiment, the user computer may be directly connected to the local network 118 and communicate directly with the tape library 102, the tape drive directly connected to the local network 118, and / or the service provider server.

[0041] The controller 204 and the encryption engine 212 may consist of code executed by a processor or may be implemented in hardware / firmware (such as a separate field programmable gate array (FPGA)).

[0042] The cartridge 202 i may include a cartridge such as one that follows the Linear Tape-Open (LTO) format. In an alternative embodiment, the portable cartridge may include other types of portable storage media, such as disk drives, static memories, flash memories, solid state storage devices (SSDs), etc.

[0043] Non-volatile memory 222, 220, and 308 may include various types of storage devices, including magnetic hard disk drives, solid-state storage devices (SSDs) composed of solid-state electronic devices,

[0044] Tape Drive 200 i The cache 210 in may include volatile memory (such as EEPROM (electrically erasable programmable read-only memory), flash memory, flash disk, random access memory (RAM) drive, storage class memory (SCM), etc.), phase change memory (PCM), resistive random access memory (RRAM), spin transfer torque memory (STM-RAM), conductive bridge RAM (CBRAM), magnetic hard disk drive, optical disk, magnetic tape, etc.

[0045] The local network 118 may include one or more local area networks (LANs), storage area networks (SANs), etc. The network 110 may include a LAN, a SAN, a wide area network (WAN), the Internet, a peer-to-peer network, a wireless network, etc.

[0046] Through the equipment 102, 106, 108, 200 i and 300 i The program components 108, 116, 204, 224, 226, 212, 310, 312, 314, 316 of the present invention include program code that is loaded into a memory and executed by a processor. Alternatively, some or all of the component functions may be implemented in a hardware device (such as in an application specific integrated circuit (ASIC), a field programmable gate array (FPGA)), or performed by a separate dedicated processor. In one embodiment, the encryption engine 212 may be implemented in the tape drive 200 i is implemented as an FPGA card to manage cryptographic operations.

[0047] Figure 4 The diagram shows that when the tape cartridge 202 i is inserted into the tape drive 200 i 400 is loaded into the tape drive 200. i Tape cassette 202 i Thereafter, the encryption mode manager 226 queries (at block 402) the detected tape cartridge 202 i , to determine whether the cartridge stores the S-KEK 310 and the US-PK 304 in the non-volatile memory 220. If so, the S-KEK 310 and the US-PK 304 are loaded into the cache 210 for use in authenticating (at block 404) the signature of the S-KEK 310 that was created on the user computer 300.i It is signed using US-SK 306 at i . US-PK 304 is used to verify the signature because KEK 218 will be included together with the signed S-KEK 310 to determine whether the hash of KEK 218 matches the S-KEK 306 decrypted using US-PK 304. If the signature of S-KEK 310 cannot be authenticated (at block 404), an error is returned (at block 406). If the signature of S-KEK 310 can be authenticated (at block 404), KEK 218 is returned (at block 408) as authenticated from the user. Then, KEK 218 is decrypted (at block 410) using PS-SK 214 to obtain the user encryption key DK 302. All the keys 214, 310, 218, 304 used are retained in the cache 210 during operation. DK 302 is loaded (at block 412) into the encryption engine 212 to encrypt the plaintext data read from the tape medium 208 and decrypt the encrypted plaintext data to write the plaintext data to the tape medium 208. After obtaining the user encryption key DK 302 for the encryption engine 212, all the keys 214, 216, 310, 218, 304, 302 are erased (at block 414) from the cache 210, and the ER mode 228 is set to encrypt-read.

[0048] Using Figure 4 the operation of, if the tape cartridge 202 i includes S-KEK 310 and US-PK 304, the controller 204 can automatically extract the user encryption key DK 302 for the encrypt-read mode while the tape cartridge is loaded in the tape drive 200 i at i .

[0049] Figure 5 Illustrated is an embodiment of the operation performed by the read / write interface 312 module, the server request manager 108 at i of the user computer 300, and the request manager 224 at i of the tape drive 200 to process a read request from the user computer 300 i at i for data stored in a specified tape cartridge 202 i at i . The read / write interface 312 at i of the user computer 300 sends (at block 500) a read request to the service provider server 106 to read data from a specified tape cartridge 202 at the tape archival facility i at i . After receiving (at block 502) the read request, the service provider server 106 sends to the specified tape cartridge 202 i including the specified tape cartridge 202 i at i . i at i . iThe tape library 102 sends (at block 504) a command to process the read request, including, if necessary, assigning the specified tape cartridge 202 to the tape library 102. i Loading in tape drive 200 i and if the tape cartridge 202 i If not loaded yet, execute Figure 4 The tape drive request manager 224 reads the requested plaintext data from the tape storage medium 208 and sends the read data to the encryption engine 212 to encrypt the read requested plaintext data on the tape medium 208 using (at block 508) the user encryption key DK 302 for return to the requesting user computer 300. i After receiving the encrypted plaintext data, the read / write interface 312 may use the user encryption key DK 302 to decrypt the encrypted data to provide the plaintext data to the user.

[0050] Figure 6 The diagram shows the user computer 300 i The read / write interface 312 module to the service provider, the server request manager 108 and the tape drive 200 at i The request manager 224 at the server executes to process requests from the user computer 300 i 302, the write request has a data file to be written to the specified tape cartridge 202 encrypted with the user encryption key DK 302. i The read / write interface sends (at block 600) a write request to the tape archive service provider 100, the write request having plaintext data to be written to the specified tape cartridge encrypted with the user encryption key (DK) 302. After receiving (at block 602) the write request having the encrypted data, the server request manager 108 sends a write request to the specified tape cartridge 202. i The tape library 102 sends (at block 604) a command to process the write request, including, if necessary, retrieving the specified tape cartridge 202. i Loading in tape drive 200 i and if the tape cartridge 202 i If not loaded yet, execute Figure 4 The tape drive encryption engine 212 uses (at block 606 ) the user encryption key DK 302 to decrypt the encrypted write data to write (at block 608 ) the decrypted plaintext write data to the tape media 208 .

[0051] use Figure 5 and Figure 6 In the embodiment of the present invention, the data is stored in plain text in the tape cartridge 202 at the tape archiving facility. However, if there is any attempt to read the data, the tape drive 200i configured to return only the requested data encrypted using the user encryption key 302 provided by the user and archived in the tape cartridge 202 i This ensures the secure transfer of data from the tape medium 208. In addition, to ensure that plaintext data is written to the tape medium 208, the tape drive 200 i decrypts the encrypted write data to write the data as plaintext to the tape cartridge 202 i . By storing the data as plaintext, the user can change the user encryption key 302 without having to decrypt and re-encrypt all the data on the tape medium 208.

[0052] Figure 7 and Figure 8 are encryption modes for an example of a request to read data for migrating a portion of the data from one or more source tape cartridges 202 S to a destination tape cartridge 202 D . Figure 7 illustrates an arrangement in the tape library 102 that has a source tape drive 200 S and a destination tape drive 200 D , which may be located in the same tape library 102 or different tape libraries 102. Figure 2 Other keys and components of are also illustrated in the tape drives 200 S , 200 D .

[0053] Figure 8 illustrates an example of an operation to copy all the data in the tape medium of one or more source tape cartridges 202 S to a destination tape cartridge 202 D . After initiating (at block 800) the operation to migrate / copy data from the source tape cartridge 202 S to the destination tape cartridge 202 D , the source tape drive 200 S performs (at block 802) Figure 4 the operation in the encryption engine 212 to establish the user encryption key DK 302. The destination tape drive 200 D loads (at block 804) the destination cartridge 202 D . The source tape drive 200 S copies (at block 806) the S-KEK 310 and US-PK 304 in the non-volatile memory 220 of the source tape cartridge 202 S to the destination tape drive 200 D for storage in the destination tape cartridge 202 D , as illustrated in Figure 7 .​

[0054] Destination tape drive 200 D Use US-PK 304 (at block 808) to authenticate the signed S-KEK 310, and use PS-SK 214 to decrypt KEK 218 to generate the user encryption key DK 302 and load DK 302 into the encryption engine 212 in the destination tape drive 200 D as described with respect to Figure 4 The source tape drive 200 S The encryption engine 212 encrypts (at block 810) the plaintext data from the source tape cartridge using DK 302 and sends it to the destination tape drive 200 D The destination tape drive 200 D The encryption engine 212 decrypts the encrypted plaintext data from the source tape drive 200 S using DK 302 and writes it to the destination tape cartridge 202 D .

[0055] Figure 7 and Figure 8 The embodiments of use an encrypted read mode to transfer encrypted plaintext data from one or more source tape drives to a destination tape drive, where the destination tape drive must decrypt to store the plaintext data on the tape medium 208. This can be performed when upgrading the tape cartridge 202 S to a higher capacity destination tape cartridge 202 D In addition, the keys 304, 310 are copied from the source tape cartridge 202 S to the destination tape cartridge 202 D so that the destination tape cartridge 202 D has the same encrypted read mode settings as the source tape cartridge 202 S This allows the destination tape cartridge 202 to be processed in the same manner as the source cartridge 202 S . Further, this migration method enables a secure reproduction of the contents of the tape medium 208 by migrating to a new destination drive after encrypting the data D .

[0056] Figure 9 Illustrates an embodiment of the operation of the encrypted read mode updater 316 in the user computer 300 i and the encryption mode manager 226 in the tape drive 200 i which provides a new user encryption key DK 302 N for use by the tape drive 200 i and updates the tape cartridge 202 with a new S-KEK 310 N ​i The S-KEK 310 in N To program a new user encryption key 302, the encryption read mode updater 316 at the user computer 300 i sends (at block 900) a write of plaintext data to the service provider 300 to be written to the specified tape cartridge 202. i After receiving (at block 902) the write request for plaintext data, the service provider server 106 sends (at block 904) a command to the tape library 102 that instructs the specified tape cartridge 202 i to process the write of plaintext data, including loading the specified tape cartridge in the tape drive if necessary and performing Figure 4 the operations of i In response to receiving the write request for plaintext data to update the encryption read mode, the tape drive 200 i sends (at block 906) the PS-PK 216 to the user computer 300 N for providing the new user encryption key 302.

[0057] At the user computer 300 i After receiving the PS-PK 216, the encryption read mode updater 316 encrypts (at block 908) the new DK 302 N which may include a DK newly generated to replace the existing DK in the tape cartridge 202 i and encrypts the new DK 302 N to create the new KEK 218 N The new KEK 218 is signed (at block 910) with the US-SK 306 N or the hash of the new KEK 218 N to produce the new signed S-KEK 310 N The new S-KEK 310 N and the US-PK 304 are transmitted (at block 912) to the service provider server 106 for the specified tape cartridge 202 at the tape archival service provider i to update the S-KEK 310 in the non-volatile memory 220 of the tape cartridge 202. i

[0058] Alternatively, the user can initiate a re-keying via the web interface at the service provider server 106 by transmitting the new S-KEK 310 N and the US-PK 304 and instructing the tape cartridge to update with the new S-KEK 310. N

[0059] Service provider server 106 forwards the received new S-KEK 218 N and US-PK 304 (at block 914) to the tape library 102 having a tape drive 200 i with a specified cartridge 202 to be reprogrammed i The tape drive encryption mode manager 226 determines (at block 916) whether the US-PK 304 authenticates the signed S-KEK 310 N . If not, an error is returned (at block 918). If authenticated, the encryption mode manager 226 determines (at block 920) whether the US-PK304 is currently stored in the non-volatile memory (NVM) 220 i of the cartridge 202. If so, and if (at block 922) the US-PK 304 i in the cartridge 202 matches the received US-PK, the encryption mode manager 226 uses (at block 924) the received US-PK 304 to authenticate the new S-KEK 310 N to generate a new KEK 218 N . If there is no match (at block 922), an error is returned (at block 918). The new KEK 218 is decrypted (at block 926) with the PS-SK 214 N to generate a new user encryption key DK 302 N . If (at block 928) the decryption is successful (such as the decryption does not produce a NULL key), the received S-KEK 310 N and US-PK 304 are stored in the non-volatile memory 220 of the cartridge 202 i for subsequent use when the cartridge 202 i is ejected and loaded into the tape drive. The user encryption key DK 302 N can be loaded into the encryption engine 212 for use in encryption operations when the cartridge 202 i is loaded into the tape drive 200 i . If (at block 928) the decryption is not successful (i.e., results in a NULL key), the S-KEK310 and US-PK 304 in the non-volatile memory 220 of the cartridge 202 are deleted (at block 932). i

[0060] In an embodiment using Figure 9 , the user can specify a new user encryption key in the signed S-KEK 310 N to be sent to the service provider server 106 for updating in the tape drive 200 iThe user encryption key used in and update the tape cartridge 202 i The S-KEK 310 in to store the new S-KEK 310 N For use in the same tape drive or different tape drives. This allows the user to update the user encryption key and S-KEK 310 maintained in the tape cartridge 202 i Therein N For future read and write operations on the storage cartridge.

[0061] The present invention can be a system, method, and / or computer program product. The computer program product can include one or more computer-readable storage media having computer-readable program instructions thereon for causing a processor to perform aspects of the present invention.

[0062] Various aspects of the present disclosure are described by narrative text, flowcharts, block diagrams of computer systems, and / or block diagrams of machine logic included in computer program product (CPP) embodiments. For any flowchart, depending on the technology involved, operations may be performed in a different order than shown in a given flowchart. For example, again depending on the technology involved, two operations shown in consecutive flowchart blocks may be performed in reverse order, as a single integrated step, concurrently, or in a manner that at least partially overlaps in time.

[0063] A computer program product embodiment (“CPP embodiment” or “CPP”) is a term used in this disclosure to describe a set of one or more storage media (also referred to as “media”) that are collectively included in a set of one or more storage devices. The set of one or more storage media collectively includes machine-readable code corresponding to instructions and / or data for performing the computer operations specified in the CPP claims. A “storage device” is any tangible device that can retain and store instructions for use by a computer processor. Without limitation, computer-readable storage media can be electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, mechanical storage media, or any suitable combination of the foregoing. Some known types of storage devices that include these media include: floppy disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory sticks, floppy disks, mechanically encoded devices (such as punched cards or pits / bumps formed on the major surfaces of a disc), or any suitable combination of the foregoing. As used in this disclosure, computer-readable storage media are not construed to store in the form of a transient signal per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide, optical pulses transmitted through an optical fiber cable, electrical signals communicated through a wired communication, and / or other transmission media. As will be understood by those skilled in the art, data typically moves at some specific points in time during the normal operation of a storage device, such as during access, defragmentation, or garbage collection, but this does not make the storage device transient because the data is not transient when stored.

[0064] Computing environment 1000 includes an example of an environment for executing at least some of the code in computer code 1001 related to performing the methods of the invention, such as Figure 2 the server request manager 108 in. The service provider server 106 can be implemented in computer 1001 and communicate over the WAN 1002.

[0065] In addition to block 1001, the computing environment 1000 also includes, for example, a computer 1001, a wide area network (WAN) 1002, an end-user device (EUD) 1003, a remote server 1004, a public cloud 1005, and a private cloud 1006. In this embodiment, the computer 1001 includes a processor set 1010 (including processing circuitry 1020 and a cache 1021), a communication fabric 1011, volatile memory 1012, persistent storage 1013 (including an operating system 1022 and block 1001, as described above), a peripheral set 1014 (including a user interface (UI) device set 1023, a storage device 1024, and an Internet of Things (IoT) sensor set 1025), and a network module 1015. The remote server 1004 includes a remote database 1030. The public cloud 1005 includes a gateway 1040, a cloud orchestration module 1041, a set of host physical machines 1042, a set of virtual machines 1043, and a set of containers 1044.

[0066] The computer 1001 can take the form of a desktop computer, a laptop computer, a tablet computer, a smartphone, a smartwatch, or other wearable computer, a mainframe computer, a quantum computer, or any form of computer or mobile device now known or to be developed in the future that is capable of running a program, accessing a network, or querying a database such as the remote database 1030. As is well understood in the computer art and depending on the technology, the performance of a computer-implemented method can be distributed among multiple computers and / or multiple locations. On the other hand, in this introduction to the computing environment 1000, the detailed discussion focuses on a single computer (specifically, the computer 1001) to keep the introduction as simple as possible. The computer 1001 can be located in the cloud, although it is not shown in the cloud in Figure 10 this figure. On the other hand, unless explicitly indicated, the computer 1001 is not required to be in the cloud.

[0067] The processor set 1010 includes one or more computer processors of any type now known or to be developed in the future. The processing circuitry 1020 can be distributed across multiple packages, for example, multiple coordinated integrated circuit chips. The processing circuitry 1020 can implement multiple processor threads and / or multiple processor cores. The cache 1021 is a memory located within the (one or more) processor chip packages and is typically used for data or code that should be readily accessible to the threads or cores running on the processor set 1010. Cache memory is typically organized into multiple levels based on relative proximity to the processing circuitry. Alternatively, some or all of the cache for the processor set can be located "off-chip". In some computing environments, the processor set 1010 can be designed to work with qubits and perform quantum computing.

[0068] Computer-readable program instructions are typically loaded onto computer 1001 so that a processor set 1010 of computer 1001 performs a series of operational steps to implement a computer-implemented method, such that the instructions thus executed will instantiate the method specified in the flowchart and / or narrative description of the computer-implemented method included in this document (collectively referred to as the "inventive method"). These computer-readable program instructions are stored in various types of computer-readable storage media, such as cache 1021 and other storage media discussed below. The program instructions and associated data are accessed by processor set 1010 to control and direct the execution of the inventive method. In computing environment 1000, at least some of the instructions for performing the inventive method may be stored in persistent storage device 1013.

[0069] Communication structure 1011 is a signal conduction path that allows the various components of computer 1001 to communicate with each other. Typically, such a structure is made up of switches and conductive paths, such as switches and conductive paths that make up a bus, a bridge, a physical input / output port, etc. Other types of signal communication paths can be used, such as fiber optic communication paths and / or wireless communication paths.

[0070] Volatile memory 1012 is any type of volatile memory known now or to be developed in the future. Examples include dynamic type random access memory (RAM) or static type RAM. Typically, volatile memory 1012 is characterized by random access, but this is not required unless explicitly indicated. In computer 1001, volatile memory 1012 is located in a single package and inside computer 1001, but alternatively or additionally, volatile memory can be distributed across multiple packages and / or located external to computer 1001.

[0071] Persistent storage device 1013 is any form of non-volatile storage for a computer known now or to be developed in the future. The non-volatility of such a storage device means that the stored data is retained whether or not power is supplied to computer 1001 and / or directly to persistent storage 1013. Persistent storage device 1013 can be read-only memory (ROM), but typically at least a portion of the persistent storage device allows data to be written, deleted, and rewritten. Some familiar forms of persistent storage devices include disk and solid state storage devices. Operating system 1022 can take many forms, such as various known proprietary operating systems or open-source portable operating system interface-type operating systems that utilize a kernel. The code included in block 1001 typically includes at least some of the computer code related to performing the inventive method (such as Figure 1 server request manager 108).

[0072] The peripheral device set 1014 includes a collection of the peripheral devices of the computer 1001. The data communication connections between the peripheral devices and the other components of the computer 1001 can be implemented in various ways, such as a Bluetooth connection, a Near Field Communication (NFC) connection, a connection made by a cable (such as a Universal Serial Bus (USB) type cable), a plug-in connection (e.g., a Secure Digital (SD) card), a connection via a local communication network, and even a connection via a wide area network (such as the Internet). In various embodiments, the UI device set 1023 may include components such as a display screen, a speaker, a microphone, wearable devices (such as goggles and smartwatches), a keyboard, a mouse, a printer, a touchpad, a game controller, and a haptic device. The storage 1024 is an external storage device, such as an external hard drive, or a plug-in storage device, such as an SD card. The storage device 1024 can be persistent and / or volatile. In some embodiments, the storage device 1024 may take the form of a quantum computing storage device for storing data in the form of qubits. In embodiments where the computer 1001 needs to have a large amount of memory (e.g., where the computer 1001 locally stores and manages a large database), such storage may be provided by a peripheral storage device designed to store a very large amount of data (such as a Storage Area Network (SAN) shared by multiple geographically distributed computers). The IoT sensor set 1025 consists of sensors that can be used in Internet of Things applications. For example, one sensor can be a thermometer and another sensor can be a motion detector.

[0073] The network module 1015 is a collection of computer software, hardware, and firmware that allows the computer 1001 to communicate with other computers via the WAN 1002. The network module 1015 may include hardware (such as a modem or a Wi-Fi signal transceiver), software for packetizing and / or depacketizing data for communication network transmission, and / or web browser software for transferring data over the Internet. In some embodiments, the network control function and the network forwarding function of the network module 1015 are executed on the same physical hardware device. In other embodiments (e.g., embodiments utilizing Software Defined Network (SDN)), the control function and the forwarding function of the network module 1015 are executed on physically separate devices, such that the control function manages multiple different network hardware devices. The computer-readable program instructions for performing the method of the invention can generally be downloaded to the computer 1001 from an external computer or an external storage device via a network adapter card or a network interface included in the network module 1015.

[0074] WAN 1002 is any wide area network (e.g., the Internet) that is capable of transmitting computer data over non-local distances via any technology, now known or hereafter developed, for transmitting computer data. In some embodiments, WAN 1002 may be replaced and / or supplemented by a local area network (LAN) that is designed to transmit data between devices located in a local area, such as a Wi-Fi network. A WAN and / or a LAN typically includes computer hardware such as copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and edge servers.

[0075] User computer 300 i is any computer system used and controlled by an end user (e.g., an enterprise customer operating computer 1001) and may take any form discussed above with respect to computer 1001, but with service provider client code 311. User computer 300 i typically sends read requests and write requests to service provider server 106, as well as other related commands to computer 1001 that implements service provider server 106. For example, in the hypothetical case where computer 1001 is designed to return read data from a tape cartridge to user computer 300 i then the read data is typically transmitted from network module 1015 of computer 1001 to user computer 300 via WAN 1002 i . In this manner, user computer 300 i can receive the requested data from archived tape cartridge 202 i . In some embodiments, user computer 300 i can be a client device, such as a thin client, a fat client, a mainframe computer, a desktop computer, etc.

[0076] Remote server 1004 is any computer system that provides at least some data and / or functionality to computer 1001. Remote server 1004 may be controlled and used by the same entity that operates computer 1001. Remote server 1004 represents the (one or more) machines that collect and store helpful and useful data for use by other computers (e.g., computer 1001). For example, in the hypothetical case where computer 1001 is designed and programmed to provide recommendations based on historical data, then the historical data may be provided to computer 1001 from remote database 1030 of remote server 1004.

[0077] A public cloud 1005 is any computer system that can be used by multiple entities and that provides on-demand availability of computer system resources and / or other computing capabilities, particularly data storage (cloud storage) and computing performance, without direct active management by the user. Cloud computing typically exploits the sharing of resources to achieve economies of consistency and scale. The direct and active management of the computing resources of the public cloud 1005 is performed by the computer hardware and / or software of the cloud orchestration module 1041. The computing resources provided by the public cloud 1005 are typically implemented by virtual computing environments running on individual computers that make up the set of host physical machines 1042, which are all the physical computers in and / or available for the public cloud 1005. The virtual computing environment (VCE) typically takes the form of virtual machines from the set of virtual machines 1043 and / or containers from the set of containers 1044. It should be understood that these VCEs can be stored as images and can be transferred as images among and between individual physical machine hosts or after the VCEs are instantiated. The cloud orchestration module 1041 manages the transfer and storage of the images, deploys new instantiations of the VCEs, and manages the active instantiations of the VCE deployments. The gateway 1040 is a collection of computer software, hardware, and firmware that allows the public cloud 1005 to communicate over the WAN 1002.

[0078] Some further explanation of the virtualized computing environment (VCE) will now be provided. A VCE can be stored as an "image". New active instances of a VCE that can be instantiated from the image. Two familiar types of VCEs are virtual machines and containers. A container is a VCE that uses operating system-level virtualization. This refers to an operating system feature in which the kernel allows the existence of multiple isolated user space instances (called containers). From the perspective of the programs running within them, these isolated user space instances typically behave like real computers. A computer program running on a normal operating system can utilize all the resources of that computer, such as connected devices, files and folders, network shares, CPU performance, and quantifiable hardware capabilities. However, a program running within a container can only use the contents of that container and the devices allocated to that container, a feature known as containerization.

[0079] The private cloud 1006 is similar to the public cloud 1005, except that the computing resources are only available for use by a single enterprise. Although the private cloud 1006 is depicted as communicating with the WAN 1002, in other embodiments, the private cloud can be completely disconnected from the Internet and only accessible through a local / private network. A hybrid cloud is a combination of multiple different types of clouds (e.g., private cloud, community cloud, or public cloud types), typically implemented by different providers separately. Each of the multiple clouds remains a separate and discrete entity, but the larger hybrid cloud architecture is combined together through standardized or proprietary technologies that enable orchestration, management, and / or data / application portability between the multiple constituent clouds. In this embodiment, both the public cloud 1005 and the private cloud 1006 are part of the larger hybrid cloud.

[0080] The terms "one embodiment", "embodiment", "multiple embodiments", "the embodiment", "the multiple embodiments", "one or more embodiments", "some embodiments", and "an embodiment" mean "one or more (but not all) embodiments of the present (one or more) inventions", unless otherwise explicitly stated.

[0081] The terms "comprising", "including", "having", and their variants mean "including but not limited to", unless otherwise explicitly stated.

[0082] An enumerated list of items does not imply that any or all of the items in the list are mutually exclusive, unless otherwise explicitly stated.

[0083] The terms "a", "an", and "the" mean "one or more", unless otherwise explicitly stated.

[0084] Devices that communicate with each other do not need to communicate with each other continuously, unless otherwise explicitly stated. Additionally, devices that communicate with each other can communicate directly or indirectly through one or more media.

[0085] A description of an embodiment with multiple components that communicate with each other does not imply that all such components are required. Instead, various optional components are described to illustrate the wide variety of possible embodiments of the present invention.

[0086] When a single device or article is described herein, it will be clear that the single device / article can be replaced by more than one device / article (whether or not they cooperate). Similarly, where more than one device or article is described herein (whether or not they cooperate), it will be clear that more than one device / article can be replaced by a single device / article, or a different number of devices / articles than the number shown can be substituted. The functions and / or features of a device can alternatively be embodied by one or more other devices that are not explicitly described as having such functions / features. Thus, other embodiments of the present invention do not need to include the device itself.

[0087] The foregoing description of the various embodiments of the present invention has been presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the invention to the precise forms disclosed. Many modifications and variations are possible in light of the above teachings. The scope of the invention is not intended to be limited by this detailed description, but rather by the appended claims. The foregoing specification, examples and data provide a complete description of the manufacture and use of the invention. Since many embodiments of the invention can be made without departing from the scope of the invention, the invention resides in the appended claims.

Claims

1. A computer program product for a tape drive in which a tape cartridge is coupled, the tape cartridge including a non-volatile memory and a tape medium, the computer program product including a computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code being executable to perform operations, the operations including: Determining whether the non-volatile memory of the tape cartridge stores a key encryption key, the key encryption key including an encrypted user encryption key associated with a user; And In response to determining that the non-volatile memory of the tape cartridge stores the key encryption key, performing: Decrypting the key encryption key to produce the user encryption key; And Providing the decrypted user encryption key to an encryption engine of the tape drive to encrypt plaintext data read from the tape medium in the tape cartridge for return in response to a read request.

2. The computer program product according to claim 1, wherein the key encryption key in the non-volatile memory of the tape cartridge is signed with a user private key associated with the user, wherein the non-volatile memory of the tape cartridge includes a user public key, and wherein the operations in response to the non-volatile memory of the tape cartridge storing the key encryption key and the user public key include: Authenticating the signed key encryption key using the user public key to produce the key encryption key, wherein decrypting the key encryption key is performed in response to authenticating the signed key encryption key.

3. The computer program product according to claim 1, wherein the key encryption key includes the user encryption key encrypted with a product-specific public key associated with the tape drive, and wherein the key encryption key is decrypted using a product-specific private key maintained in the tape drive to produce the user encryption key for encrypting the plaintext data read from the tape medium.

4. The computer program product according to claim 1, wherein the operations further include: Receiving a read request for the plaintext data in the tape medium; And In response to the read request, encrypting the requested plaintext data from the tape medium using the user encryption key by the encryption engine for return of the encrypted requested plaintext data in response to the read request.

5. The computer program product according to claim 1, wherein the operations further include: Receiving a write request including encrypted write plaintext data encrypted with the user encryption key for writing to the tape medium; In response to the write request, decrypting the encrypted write plaintext data using the user encryption key by the encryption engine to produce the write plaintext data; And Writing the write plaintext data to the tape medium.

6. The computer program product according to claim 1, wherein the operations further include: In response to decrypting the key encryption key, a valid encryption key is generated, and an encrypt-read mode is indicated for the tape cartridge. When the encrypt-read mode is set, the encryption engine uses the user encryption key to encrypt the plaintext read from the tape medium in the tape cartridge for return in response to a read request.

7. The computer program product according to claim 1, wherein the read request is from the user, and a user computer associated with the user uses the user encryption key to decrypt the encrypted plaintext data returned in response to the read request.

8. The computer program product according to claim 1, wherein the tape drive includes a source tape drive, the tape cartridge includes a source tape cartridge, and the tape medium includes a source tape medium, and wherein the read request includes an operation of transferring encrypted plaintext data from the source tape medium to a destination tape medium in a destination tape cartridge coupled to a destination tape drive, and wherein the operation further includes: transferring the key encryption key from the source tape drive to the destination tape drive for storage in the destination tape drive, wherein the destination tape drive decrypts the transferred key encryption key to generate the user encryption key for decrypting the plaintext data transferred from the source tape drive to generate the plaintext data to be written to the destination tape medium.

9. A computer program product implemented in a tape drive in which a tape cartridge is coupled, the tape cartridge including a tape medium, the computer program product including a computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code being executable to perform operations, the operations including: receiving plaintext data to be written to the tape medium from a user computer associated with a user; sending a product-specific public key associated with the tape drive to the user computer; receiving a key encryption key from the user computer, the key encryption key including the user encryption key associated with the user encrypted with the product-specific public key, wherein the product-specific public key and product-specific private key maintained in the tape drive are a pair of keys in a cryptographic system; decrypting the key encryption key with the product-specific private key to generate the user encryption key; and using the user encryption key to encrypt the plaintext data read from the tape medium for return in response to a read request.

10. The computer program product according to claim 9, wherein the operations further include: storing the key encryption key in a non-volatile memory of the tape cartridge; detecting that the tape cartridge is reinserted into the tape drive after being ejected from the tape drive; accessing the key encryption key from the non-volatile memory of the reinserted tape cartridge; and decrypting the accessed key encryption key with the product-specific private key to generate the user encryption key for encrypting the plaintext data read from the tape medium.

11. The computer program product according to claim 9, wherein the received key encryption key includes a first key encryption key, and wherein the user encryption key includes a first user encryption key, and wherein the operations further include: Determining whether decryption successfully produces the first user encryption key; And In response to determining that decryption successfully produces the user encryption key, storing the first key encryption key in the non-volatile memory of the tape cartridge, wherein storing the first key encryption key overwrites a second key encryption key stored in the non-volatile memory of the tape cartridge, the second key encryption key including a second user encryption key associated with the user and encrypted with the product-specific public key, wherein the second key encryption key was stored in the non-volatile memory of the tape cartridge before the first key encryption key was received from the user.

12. The computer program product according to claim 11, wherein the operations further include: In response to determining that decryption does not successfully produce the first user encryption key, deleting the second key encryption key stored in the non-volatile memory of the tape cartridge.

13. The computer program product according to claim 9, wherein the operations further include: Receiving a product-specific key from the user as part of receiving the key encryption key from the user; And Determining whether the product-specific public key received from the user matches the product-specific key stored in the non-volatile memory of the tape cartridge, wherein decrypting the key encryption key and using the user encryption key decrypted from the key encryption key are performed in response to determining that the product-specific public key received from the user matches the product-specific key stored in the non-volatile memory of the tape cartridge.

14. A system including a tape drive with a tape cartridge coupled thereto, the system including: Non-volatile memory; Tape medium; A computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code being executed to perform operations, the operations including: Determining whether the non-volatile memory of the tape cartridge stores a key encryption key, the key encryption key including an encrypted user encryption key associated with a user; and In response to determining that the non-volatile memory of the tape cartridge stores the key encryption key, performing: Decrypting the key encryption key to produce the user encryption key; and providing the decrypted user encryption key to an encryption engine of the tape drive to encrypt plaintext data read from the tape medium in the tape cartridge for return in response to a read request.

15. The system according to claim 14, wherein the key encryption key in the non-volatile memory of the tape cartridge is signed with a user private key associated with the user, wherein the non-volatile memory of the tape cartridge includes a user public key, and wherein the operation of storing the key encryption key and the user public key in the non-volatile memory of the tape cartridge includes: Authenticating the signed key encryption key using the user public key to generate the key encryption key, wherein decrypting the key encryption key is performed in response to authenticating the signed key encryption key.

16. The system according to claim 14, wherein the operation further includes: Receiving a read request for the plaintext data in the tape medium; And In response to the read request, encrypting, by the encryption engine, the requested plaintext data from the tape medium using the user encryption key to return the encrypted requested plaintext data to the read request.

17. The system according to claim 14, wherein the tape drive includes a source tape drive, the tape cartridge includes a source tape cartridge, and the tape medium includes a source tape medium, and wherein the read request includes an operation of transferring encrypted plaintext data from the source tape medium to a destination tape medium in a destination tape cartridge coupled to a destination tape drive, and wherein the operation further includes: Transferring the key encryption key from the source tape drive to the destination tape drive for storage in the destination tape drive, wherein the destination tape drive decrypts the transferred key encryption key to generate the user encryption key for decrypting the plaintext data transferred from the source tape drive to generate the plaintext data to be written to the destination tape medium.

18. A system including a tape drive having a tape cartridge coupled thereto, the system including: Tape medium; Receiving plaintext data to be written to the tape medium from a user computer associated with a user; And A computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code being executed to perform operations including: Sending a product-specific public key associated with the tape drive to the user computer; Receiving a key encryption key from the user computer, the key encryption key including a user encryption key associated with the user encrypted with the product-specific public key, wherein the product-specific public key and product-specific private key maintained in the tape drive are a pair of keys in a cryptosystem; Decrypting the key encryption key using the product-specific private key to generate the user encryption key; and Using the user encryption key to encrypt the plaintext data read from the tape medium for return to a read request.

19. The system according to claim 18, wherein the operation further includes: Storing the key encryption key in the non-volatile memory of the tape cartridge; Detecting that the tape cartridge is reinserted into the tape drive after being ejected from the tape drive; Access the key encryption key from the non-volatile memory of the re-inserted cartridge; And Decrypt the accessed key encryption key with the product-specific private key to generate the user encryption key for encrypting the plaintext data read from the tape medium.

20. The system according to claim 18, wherein the received key encryption key includes a first key encryption key, and wherein the user encryption key includes a first user encryption key, and wherein the operation further includes: Determine whether decryption successfully generates the first user encryption key; And In response to determining that decryption successfully generates the user encryption key, store the first key encryption key in the non-volatile memory of the cartridge, wherein storing the first key encryption key overwrites a second key encryption key stored in the non-volatile memory of the cartridge, the second key encryption key including a second user encryption key associated with the user and encrypted with the product-specific public key, wherein the second key encryption key was stored in the non-volatile memory of the cartridge before the first key encryption key was received from the user.

21. The system according to claim 18, wherein the operation further includes: In response to determining that decryption does not successfully generate the first user encryption key, delete the second key encryption key stored in the non-volatile memory of the cartridge.

22. A method implemented in a tape drive in which a cartridge is coupled, the method including: Determine whether the non-volatile memory of the cartridge stores a key encryption key, the key encryption key including an encrypted user encryption key associated with a user; And In response to determining that the non-volatile memory of the cartridge stores the key encryption key, perform: Decrypt the key encryption key to generate the user encryption key; And Provide the decrypted user encryption key to the encryption engine of the tape drive to encrypt the plaintext data read from the tape medium in the cartridge with the user encryption key for return to a read request.

23. The method according to claim 22, wherein the key encryption key in the non-volatile memory of the cartridge is signed with a user private key associated with the user, and wherein the non-volatile memory of the cartridge includes a user public key, the method including: In response to the non-volatile memory of the cartridge storing the key encryption key and the user public key, authenticate the signed key encryption key with the user public key to generate the key encryption key, wherein decrypting the key encryption key is performed in response to authenticating the signed key encryption key.

24. The method according to claim 22, further including: Receive a read request for the plaintext data in the tape medium; And In response to the read request, encrypt the requested plaintext data from the tape medium with the user encryption key by the encryption engine for return of the encrypted requested plaintext data to the read request.

25. The method according to claim 22, wherein the tape drive includes a source tape drive, the tape cartridge includes a source tape cartridge, the tape medium includes a source tape medium, and wherein the read request includes an operation of transferring encrypted plaintext data from the source tape medium to a destination tape medium in a destination tape cartridge coupled to a destination tape drive, the method further comprising: transferring the key encryption key from the source tape drive to the destination tape drive for storage in the destination tape drive, wherein the destination tape drive decrypts the transferred key encryption key to generate the user encryption key for decrypting the plaintext data transferred from the source tape drive to generate the plaintext data to be written to the destination tape medium.

26. A computer program product implemented in a user computer for a user to store data in a tape medium in a tape cartridge, the computer program product comprising a computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code being executable to perform operations, the operations comprising: writing plaintext data associated with the user to a tape medium in a tape cartridge; and writing a key encryption key including an encrypted user encryption key associated with the user to non-volatile memory of the tape cartridge, wherein storing the key encryption key in the non-volatile memory of the tape cartridge causes a tape drive into which the tape cartridge is inserted to decrypt the key encryption key to generate the user encryption key for use by an encryption engine of the tape drive to encrypt plaintext data read from the tape medium in the tape cartridge for return in response to a read request.

27. The computer program product according to claim 26, wherein the operations further comprise: signing the key encryption key with a user secret key associated with the user; and writing a user public key, wherein the user secret key and the user public key are a pair of keys in a cryptosystem, and wherein storing the key encryption key in the non-volatile memory of the tape cartridge causes the tape drive to use the user public key to verify the signature of the signed key encryption key.

28. The computer program product according to claim 26, wherein the operations further comprise: encrypting the user encryption key with a product-specific public key associated with the tape drive to form the key encryption key to form the key encryption key, wherein storing the key encryption key in the non-volatile memory of the tape cartridge causes the tape drive to decrypt the key encryption key with a product-specific private key maintained in the tape drive to generate, wherein the product-specific public key and the product-specific private key are a pair of keys in a cryptosystem.

29. The computer program product according to claim 26, wherein the operations further comprise: Send a read request for the plaintext data in the tape medium to the tape drive, wherein the read request causes the encryption engine of the tape drive to use the user encryption key to encrypt the requested plaintext data from the tape medium to return the encrypted requested plaintext data to the user computer.

30. The computer program product according to claim 26, wherein the operation further comprises: Send a write request including encrypted write plaintext data encrypted with the user encryption key to write to the tape medium, wherein the write request causes the encryption engine of the tape drive to decrypt the encrypted write plaintext data using the user encryption key to generate the write plaintext data to be written to the tape medium.

31. The computer program product according to claim 26, wherein storing the key encryption key in the non-volatile memory of the tape cartridge causes the tape drive to indicate an encrypt-read mode for the tape cartridge and use the user encryption key to encrypt the plaintext read from the tape medium in the tape cartridge for a read request.

32. A computer program product implemented in a user computer for a user to store data in a tape medium in a tape cartridge, the computer program product comprising a computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code being executable to perform operations, the operations comprising: Send plaintext data to write to the tape medium in the tape cartridge loaded in the tape drive; Receive a product-specific public key associated with the tape drive from the tape drive; Generate a key encryption key by encrypting a user encryption key associated with the user with the product-specific public key, wherein the product-specific public key and product-specific private key maintained in the tape drive are a pair of keys in a cryptosystem; And Transmit the key encryption key to the tape drive so that the tape drive decrypts the key encryption key with the product-specific private key to generate the user encryption key for encrypting the plaintext data read from the tape medium for return in response to a read request.

33. The computer program product according to claim 32, wherein the operation further comprises: Sign the key encryption key with a user private key associated with the user, wherein the signed key encryption key is transmitted to the tape drive together with the user public key, wherein the user public key and the user private key are a pair of keys, and transmitting the user public key causes the tape drive to use the user public key to remove the signature to obtain the key encryption key.

34. The computer program product according to claim 32, wherein transmitting the key encryption key to the tape drive causes the tape drive to store the key encryption key in the non-volatile memory of the tape cartridge, and later retrieve the key encryption key from the non-volatile memory of the tape cartridge when the tape cartridge is reinserted into the tape drive for encrypting data read from the tape medium.

35. The computer program product according to claim 7, wherein transmitting the key encryption key to the tape drive causes the tape drive to store the key encryption key in the non-volatile memory of the tape cartridge, and the key encryption key overwrites a pre-existing key encryption key stored in the non-volatile memory of the tape cartridge.

36. A system in data communication with a tape cartridge having a non-volatile memory and a tape medium and a tape drive, the system comprising: a processor; and a computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code being executable by the processor to perform operations, the operations including: writing plaintext data associated with the user to the tape medium in the tape cartridge; and writing a key encryption key including an encrypted user encryption key associated with the user to the non-volatile memory of the tape cartridge, wherein storing the key encryption key in the non-volatile memory of the tape cartridge causes the tape drive into which the tape cartridge is inserted to decrypt the key encryption key to generate the user encryption key for use by an encryption engine of the tape drive to encrypt plaintext data read from the tape medium in the tape cartridge for return in response to a read request.

37. The system according to claim 36, wherein the operations further include: signing the key encryption key with a user secret key associated with the user; and writing a user public key, wherein the user secret key and the user public key are a pair of keys in a cryptosystem, and storing the key encryption key in the non-volatile memory of the tape cartridge causes the tape drive to use the user public key to verify the signature of the signed key encryption key.

38. The system according to claim 36, wherein the operations further include: encrypting the user encryption key with a product-specific public key associated with the tape drive to form the key encryption key, wherein storing the key encryption key in the non-volatile memory of the tape cartridge causes the tape drive to decrypt the key encryption key with a product-specific private key maintained in the tape drive to generate, wherein the product-specific public key and the product-specific private key are a pair of keys in a cryptosystem.

39. The system according to claim 36, wherein the operations further include: Send a read request for the plaintext data in the tape medium to the tape drive, where the read request causes the encryption engine of the tape drive to use the user encryption key to encrypt the requested plaintext data from the tape medium to return the encrypted requested plaintext to the user computer.

40. The system according to claim 36, wherein the operation further comprises: Sending a write request including encrypted write plaintext data encrypted with the user encryption key for writing to the tape medium, where the write request causes the encryption engine of the tape drive to decrypt the encrypted write plaintext data using the user encryption key to generate the write plaintext data to be written to the tape medium.

41. The system according to claim 36, wherein storing the key encryption key in the non-volatile memory of the tape cartridge causes the tape drive to indicate an encrypt-read mode for the tape cartridge and use the user encryption key to encrypt the plaintext read from the tape medium in the tape cartridge for a read request.

42. A system in data communication with a tape cartridge having a non-volatile memory and a tape medium and a tape drive, the system comprising: A processor; And A computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code being executable by the processor to perform operations, the operations comprising: Sending plaintext data for writing to the tape medium in the tape cartridge loaded in the tape drive; Receiving a product-specific public key associated with the tape drive from the tape drive; Generating a key encryption key by encrypting a user encryption key associated with the user with the product-specific public key, where the product-specific public key and product-specific private key maintained in the tape drive are a pair of keys in a cryptographic system; and Transmitting the key encryption key to the tape drive so that the tape drive decrypts the key encryption key with the product-specific private key to generate the user encryption key for encrypting the plaintext data read from the tape medium for return in response to a read request.

43. The system according to claim 42, wherein the operation further comprises: Signing the key encryption key with a user private key associated with the user, where the signed key encryption key is transmitted to the tape drive together with the user public key, where the user public key and the user private key are a pair of keys, and transmitting the user public key causes the tape drive to use the user public key to remove the signature to obtain the key encryption key.

44. The system according to claim 42, wherein transmitting the key encryption key to the tape drive causes the tape drive to store the key encryption key in the non-volatile memory of the tape cartridge and later retrieve the key encryption key from the non-volatile memory of the tape cartridge when the tape cartridge is reinserted into the tape drive for encrypting data read from the tape medium.

45. The system according to claim 42, wherein the key encryption key is transmitted to the tape drive such that the tape drive stores the key encryption key in the non-volatile memory of the tape cartridge, and the key encryption key is to overwrite a pre-existing key encryption key stored in the non-volatile memory of the tape cartridge.

46. A method implemented in a user computer for a user to store data in a tape medium in a tape cartridge, the method comprising: writing plaintext data associated with the user to the tape medium in the tape cartridge; and writing a key encryption key including an encrypted user encryption key associated with the user to the non-volatile memory of the tape cartridge, wherein storing the key encryption key in the non-volatile memory of the tape cartridge causes the tape drive into which the tape cartridge is inserted to decrypt the key encryption key to generate the user encryption key for use by an encryption engine of the tape drive to encrypt plaintext data read from the tape medium in the tape cartridge for return in response to a read request.

47. The method according to claim 46, further comprising: signing the key encryption key with a user secret key associated with the user; and writing a user public key, wherein the user secret key and the user public key are a pair of keys in a cryptosystem, and storing the key encryption key in the non-volatile memory of the tape cartridge causes the tape drive to use the user public key to verify the signature of the signed key encryption key.

48. The method according to claim 46, further comprising: encrypting the user encryption key with a product-specific public key associated with the tape drive to form the key encryption key, wherein storing the key encryption key in the non-volatile memory of the tape cartridge causes the tape drive to decrypt the key encryption key with a product-specific private key maintained in the tape drive to generate, wherein the product-specific public key and the product-specific private key are a pair of keys in a cryptosystem.

49. The method according to claim 46, further comprising: sending a read request for the plaintext data in the tape medium to the tape drive, wherein the read request causes the encryption engine of the tape drive to use the user encryption key to encrypt the requested plaintext data from the tape medium for returning the encrypted requested plaintext to the user computer.

50. The method according to claim 46, further comprising: sending a write request including encrypted write plaintext data encrypted with the user encryption key for writing to the tape medium, wherein the write request causes the encryption engine of the tape drive to decrypt the encrypted write plaintext data with the user encryption key to generate the write plaintext data to be written to the tape medium.