Allowed Encryption
An authorized encryption scheme using watermarks verifies that data is encrypted by an authorized layer, preventing ransomware and exfiltration attacks by ensuring only certified applications can encrypt data, thus securing cloud storage systems.
Patent Information
- Application Number
- JP2023544596
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-03-05
- Filing Date
- 2022-02-17
- Publication Date
- 2025-08-27
- Estimated Expiration
- 2042-02-17
AI Technical Summary
Unauthorized encryption of data by attackers poses a significant security challenge, leading to ransomware-style attacks and exfiltration of sensitive information, which can be costly and irrecoverable.
Implementing an authorized encryption scheme that verifies encryption was performed by an authorized layer using watermarks, ensuring only authenticated and certified applications can encrypt data, and storing watermarks with encrypted data to authenticate the encryption process.
This approach effectively blocks ransomware-style attacks and limits exfiltration by ensuring data is encrypted with authorized methods, providing secure data integrity and preventing unauthorized storage of encrypted data.
Smart Images

Figure 0007730257000001 
Figure 0007730257000002 
Figure 0007730257000003
Abstract
Description
[Technical Field]
[0001] The present invention relates generally to encryption, and more particularly to permissioned encryption in cloud storage systems and networks. [Background technology]
[0002] Unauthorized encryption of data, such as encryption of a victim's data by an attacker using a key unknown to the victim, is a major security challenge. Such ransomware-style attacks cause a denial of service at the victim that may be costly or irrecoverable. For example, such attacks include ransomware-style attacks in which a ransom is demanded in exchange for an encryption key needed to unlock the victim's data.
[0003] Malware may also and / or alternatively perform unauthorized data transfer (eg, data is copied, transferred, captured, etc.) without authorization in an exfiltration attack.
[0004] What is needed is a way to ensure that encrypted data within a system is encrypted in an authorized manner so that the data owner can decrypt the data. Summary of the Invention
[0005] An authorized encryption scheme according to one aspect of the present invention can verify that the encryption was performed by an authorized encryption layer and not by an unauthorized process. Ransomware-style attacks are thereby advantageously blocked. Exfiltration-style attacks can also be highly limited by requiring that data be encrypted using authorized encryption by authenticated and / or certified applications that are authorized to use authorized encryption.
[0006] According to one approach, a computer program product comprises one or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media, the program instructions including program instructions for authenticating an application as authorized to perform encryption and for receiving data at an authenticated encryption layer. The program instructions include program instructions for encrypting data using an encryption key, where the encryption key is unavailable to the application, and for generating a watermark token for the encrypted data. The program instructions include program instructions for generating a watermark for the encrypted data using the watermark token and the watermark key, and for transmitting the encrypted data, the watermark token, and the watermark to a storage system. The storage system: When storing encrypted data, Using a watermark key dark The computer program product is configured to verify the encrypted data. The computer program product advantageously provides the ability to verify that the encryption was performed by an authorized encryption layer and not by an unauthorized process.
[0007] The computer program product optionally performs a pre-filter prior to encryption. function and in response to determining that the data has been pre-encrypted, De Data from being encrypted with the encryption key This optional approach provides an additional layer of security against ransomware-style attacks.
[0008] According to one approach, a computer-implemented method includes authenticating an application as authorized to perform encryption, receiving data at the authenticated encryption layer, encrypting the data using an encryption key, where the encryption key is unavailable to the application, generating a watermark token for the encrypted data, generating a watermark for the encrypted data using the watermark token and the watermark key, and transmitting the encrypted data, the watermark token, and the watermark to a storage system. When storing encrypted data, Using a watermark key dark The computer-implemented method is configured to verify the encrypted data. The computer-implemented method advantageously provides the ability to verify that the encryption was performed by an authorized encryption layer and not by an unauthorized process.
[0009] Another approach includes a computer program product comprising one or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media, the program instructions including: receiving encrypted data, a watermark token, metadata, and a first watermark for the encrypted data at a storage system; and receiving a watermark key associated with the metadata. The program instructions include: generating a second watermark for the encrypted data using the watermark token and the watermark key; and comparing the second watermark for the encrypted data with the first watermark for the encrypted data. The computer program product advantageously provides the ability to verify authorized encryption by the storage system before writing a block and / or after reading a block. Blocks that fail verification are not written to storage, or similarly, reads are not returned to the requester.
[0010] The computer program product optionally comprises program instructions for sending a warning to a user in response to determining that the second watermark does not match the first watermark. This optional approach provides the ability to warn a user that the data may have been tampered with before reaching the storage system.
[0011] According to one approach, a computer-implemented method includes receiving encrypted data, a watermark token, metadata, and a first watermark for the encrypted data at a storage system, receiving a watermark key associated with the metadata, generating a second watermark for the encrypted data using the watermark token and the watermark key, and comparing the second watermark for the encrypted data with the first watermark for the encrypted data. The computer-implemented method beneficially provides the ability to verify authorized encryption by the storage system before writing a block and / or after reading a block. Blocks that fail verification are not written to storage, or similarly, reads are not returned to the requester.
[0012] Another approach includes a computer program product comprising one or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media, the program instructions including program instructions for authenticating an application as authorized to perform encryption and for receiving data at an authenticated encryption layer. The program instructions include program instructions for encrypting data using an encryption key, where the encryption key is unavailable to the application, and program instructions for generating a watermark token for the encrypted data using a mixed key. The program instructions further include program instructions for generating a watermark for the encrypted data using the watermark token and the watermark key, and program instructions for transmitting the encrypted data, the watermark token, and the watermark to a storage system. The storage system: When storing encrypted data, Using a watermark key dark The computer program product provides the ability to detect alterations of the watermark by the Authencrypt verifier using modifications to the watermark process, for example, the mixed key.
[0013] The computer program product optionally provides that the watermark is a keyed hash message authentication code. This optional approach produces an unforgeable representation, called a watermark token, of the encrypted data, which provides additional security against forgery.
[0014] Other aspects and techniques of the present invention will become apparent from the following detailed description, when considered in conjunction with the drawings, illustrating by way of example the principles of the invention. [Brief explanation of the drawings]
[0015] [Figure 1] 1 illustrates a cloud computing environment in accordance with an aspect of the present invention.
[0016] [Figure 2] 1 illustrates an abstraction model layer according to one aspect of the present invention.
[0017] [Figure 3] FIG. 1 is a diagram of a high-level architecture according to one aspect of the present invention.
[0018] [Figure 4] FIG. 1 is a diagram of a high-level architecture according to one aspect of the present invention.
[0019] [Figure 5] 1 is a flowchart of a method according to one aspect of the present invention.
[0020] [Figure 6] 1 is a flowchart of a method according to one aspect of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0021] The following description is made for the purpose of illustrating the general principles of this invention and is not meant to limit the inventive concepts claimed herein. Furthermore, particular features described herein can be used in combination with other described features in each of the various possible combinations and permutations.
[0022] Unless otherwise specifically defined herein, all terms are to be given their broadest possible interpretation, including the meanings implied by this specification and the meanings understood by a person skilled in the art and / or defined in dictionaries, treatises, etc.
[0023] It should also be noted that, as used in this specification and the appended claims, the singular forms "a," "an," and "the" include plural referents unless specifically stated otherwise. It will be further understood that the terms "comprises" and / or "comprising," as used herein, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0024] The following description discloses several aspects of detecting authorized encryption and blocking storage of data encrypted with unauthorized encryption.
[0025] In one general aspect, a computer program product comprises one or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media, the program instructions including program instructions for authenticating an application as authorized to perform encryption and for receiving data at an authenticated encryption layer. The program instructions include program instructions for encrypting data using an encryption key, where the encryption key is unavailable to the application, and for generating a watermark token for the encrypted data. The program instructions include program instructions for generating a watermark for the encrypted data using the watermark token and the watermark key, and for transmitting the encrypted data, the watermark token, and the watermark to a storage system. The storage system: When storing encrypted data, Using a watermark key dark The device is configured to verify the encrypted data.
[0026] In another general aspect, a computer-implemented method includes authenticating an application as authorized to perform encryption, receiving data at the authenticated encryption layer, encrypting the data using an encryption key, where the encryption key is unavailable to the application, generating a watermark token for the encrypted data, generating a watermark for the encrypted data using the watermark token and the watermark key, and transmitting the encrypted data, the watermark token, and the watermark to a storage system. When storing encrypted data, Using a watermark key dark The device is configured to verify the encrypted data.
[0027] In another general aspect, a computer program product comprises one or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media, the program instructions having program instructions for receiving encrypted data, a watermark token, metadata, and a first watermark of the encrypted data at a storage system, and program instructions for receiving a watermark key associated with the metadata, the program instructions having program instructions for generating a second watermark of the encrypted data using the watermark token and the watermark key, and program instructions for comparing the second watermark of the encrypted data to the first watermark of the encrypted data.
[0028] In one general aspect, a computer-implemented method includes receiving, at a storage system, encrypted data, a watermark token, metadata, and a first watermark of the encrypted data; receiving a watermark key associated with the metadata; generating a second watermark of the encrypted data using the watermark token and the watermark key; and comparing the second watermark of the encrypted data to the first watermark of the encrypted data.
[0029] In another general aspect, a computer program product comprises one or more computer-readable storage media and program instructions collectively stored on the one or more computer-readable storage media, the program instructions including program instructions for authenticating an application as authorized to perform encryption and for receiving data at an authenticated encryption layer. The program instructions include program instructions for encrypting data using an encryption key, where the encryption key is unavailable to the application, and program instructions for generating a watermark token for the encrypted data using a mixed key. The program instructions further include program instructions for generating a watermark for the encrypted data using the watermark token and the watermark key, and program instructions for transmitting the encrypted data, the watermark token, and the watermark to a storage system. The storage system: When storing encrypted data, Using a watermark key dark The device is configured to verify the encrypted data.
[0030] Although this disclosure includes detailed descriptions of cloud computing, it should be understood that implementation of the teachings described herein is not limited to cloud computing environments. Rather, aspects of the present invention may be implemented in conjunction with any other type of computing environment now known or later developed.
[0031] Cloud computing is a service delivery model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal administrative effort or interaction with the service provider. The cloud model can include at least five characteristics, at least three service models, and at least four deployment models.
[0032] The characteristics are as follows:
[0033] On-Demand Self-Service: Cloud consumers can unilaterally provision computing capacity, such as server time and network storage, automatically as needed, without requiring human interaction with the provider of the service.
[0034] Wide network access: Capabilities are available over the network and accessed through standard mechanisms that facilitate use by heterogeneous thin or thick client platforms (eg, cell phones, laptops, and PDAs).
[0035] Resource Pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically allocated and reallocated according to demand. Consumers generally have no control or knowledge over the exact location of the resources provided, although there is a type of location independence in that they may be able to specify location at a higher level of abstraction (e.g., country, state, or data center).
[0036] Rapid scalability: Capacity can be provisioned quickly and elastically, sometimes automatically, and instantly scaled out or quickly released and instantly scaled in. To the consumer, the capacity available for provisioning often appears unlimited, and any quantity can be purchased at any time.
[0037] Metered Services: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at a level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource utilization can be monitored, controlled, and reported, thereby providing transparency to both providers and consumers of the services being utilized.
[0038] The service model is as follows:
[0039] Software as a Service (SaaS): The consumer is offered the ability to use a provider's applications running on a cloud infrastructure. The applications are accessible from a variety of client devices through a thin-client interface such as a web browser (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.
[0040] Platform as a Service (PaaS): The ability offered to consumers is to deploy applications they create or acquire, written using programming languages and tools supported by the provider, onto a cloud infrastructure. The consumer does not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but does control the deployed applications and, in some cases, the configuration of the application's hosting environment.
[0041] Infrastructure as a Service (IaaS): The ability provided to consumers is to provision processing, storage, network, and other basic computing resources, and the consumer can deploy and run any software, which may include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure, but rather controls the operating systems, storage, and deployed applications, and in some cases has limited control over selected networking components (e.g., host firewalls).
[0042] The deployment model is as follows:
[0043] Private Cloud: Cloud infrastructure is operated exclusively for the organization. It can be managed by the organization or a third party and can exist on-premise or off-premise.
[0044] Community Cloud: Cloud infrastructure is shared by several organizations to support a specific community with common interests (e.g., mission, security requirements, policies, and compliance considerations). It can be managed by the organization or a third party and can exist on-premises or off-premises.
[0045] Public Cloud: Cloud infrastructure is available to the general public or large industry organizations and is owned by organizations that sell cloud services.
[0046] Hybrid Cloud: A cloud infrastructure is a combination of two or more clouds (private, community, or public) that remain distinct entities but are tied together by standardized or proprietary technologies (e.g., cloud bursting for load balancing between clouds) that enable data and application portability.
[0047] Cloud computing environments are service-oriented, emphasizing statelessness, low coupling, modularity, and semantic interoperability. At the heart of cloud computing is an infrastructure that comprises a network of interconnected nodes.
[0048] Referring now to FIG. 1 , an illustrative cloud computing environment 50 is illustrated. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 with which local computing devices used by cloud consumers can communicate, such as, for example, a personal digital assistant (PDA) or mobile phone 54A, a desktop computer 54B, a laptop computer 54C, and / or an automobile computer system 54N. The nodes 10 may communicate with each other. They may be physically or virtually grouped (not shown) in one or more networks, such as a private cloud, a community cloud, a public cloud, or a hybrid cloud, or combinations thereof, as described above. This enables the cloud computing environment 50 to provide infrastructure, platforms, and / or software as a service for which cloud consumers are not required to maintain resources on their local computing devices. It is understood that the types of computing devices 54A-N illustrated in FIG. 1 are for illustrative purposes only, and that the computing nodes 10 and the cloud computing environment 50 can communicate with any type of computerized device over any type of network and / or network-addressable connection (e.g., using a web browser).
[0049] Referring now to Figure 2, a set of functional abstraction layers provided by cloud computing environment 50 (Figure 1) is shown. It should be understood in advance that the components, layers, and functions shown in Figure 2 are for illustrative purposes only, and aspects of the present invention are not limited thereto. As shown, the following layers and corresponding functions are provided:
[0050] Hardware and software layer 60 comprises hardware and software components. Examples of hardware components include mainframe 61; RISC (reduced instruction set computer) architecture-based servers 62; servers 63; blade servers 64; storage devices 65; and networks and networking components 66. In some embodiments, software components include network application server software 67 and database software 68.
[0051] The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual servers 71; virtual storage 72; virtual networks, including virtual private networks 73; virtual applications and operating systems 74; and virtual clients 75.
[0052] In one example, management layer 80 may provide the functions described below. Resource provisioning 81 provides dynamic procurement of computing and other resources utilized to execute tasks within the cloud computing environment. Metering and pricing 82 provides cost tracking as resources are utilized within the cloud computing environment and billing or invoicing for the consumption of these resources. In one example, these resources may include application software licenses. Security provides identity verification for cloud consumers and tasks, as well as protection for data and other resources. User portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 provides cloud computing resource allocation and management to ensure required service levels are met. Service level agreement (SLA) planning and fulfillment 85 provides proactive coordination and procurement of cloud computing resources in anticipation of future requirements according to SLAs.
[0053] The workload layer 90 provides examples of functions for which a cloud computing environment can be utilized. Examples of workloads and functions that can be provided from this layer include mapping and navigation 91; software development and lifecycle management 92; virtual classroom instruction delivery 93; data analytics processing 94; transaction processing 95; and Authencryption 96.
[0054] Unauthorized encryption of data, such as encryption of a victim's data by an attacker using a key unknown to the victim, is a major security challenge. Such ransomware-style attacks cause a denial of service at the victim that may be costly or irrecoverable. At least some aspects of the present disclosure provide a method for ensuring that encrypted data in a system is encrypted in an authorized manner so that the data owner can decrypt the data. The encryption is authenticated by creating a "watermark" that verifies that the encryption was performed by an authorized encryption layer and not an unauthorized process. Ransomware-style attacks are thereby beneficially blocked. Exfiltration-style attacks are also highly limited by requiring that data be encrypted using authorized encryption by authenticated and / or certified applications authorized to use authorized encryption.
[0055] At least some aspects of the present disclosure lock down users of encryption to prevent data from being stored for which the system does not have the key. Various aspects described herein provide a secure method for preventing storage of data with unauthorized encryption by allowing the storage system to distinguish between authorized and unauthorized uses of encryption without the storage system having access to the encryption key. In various aspects, it is assumed that all communication between independent components occurs via mutually authenticated, secure (e.g., encrypted) sessions. It may also be assumed that all data stored within the system is encrypted. While measures for unencrypted data may be included in at least some approaches, unencrypted data may not be protected from exfiltration.
[0056] Authenticated encryption (e.g., "Authencrypt") uses keys known to the system. Registered keys may be stored in a key server, and registered keys are only usable by Authencrypt. In a preferred embodiment, registered keys are not available to applications. Keys not known to the system cannot be used (e.g., are not used) by Authencrypt. Authencrypt can only be used by authorized applications. In various approaches, a policy manager maintains authorization information for applications, in a manner known in the art. For example, policies may be implemented in a derivative of the Extensible Access Control Markup Language (XACML) with associated policy enforcement points, policy decision points, etc. Thus, unauthorized encryption can be used by applications that are not authorized by the storage Blocked in In various ways, authorized encryption function may exist on the host and Authencrypt verification function In one approach, unauthorized encryption occurs before storage. preventionIt may be possible, but the storage preferably also verifies that the encryption is unauthorized.
[0057] In one exemplary and illustrative aspect, the Authencrypt system includes a host having the capability to write to storage. An authorized application attempts to write data to the storage, and an unauthorized application attempts to write data to the storage. The storage system records the data from the authorized application and rejects the data from the unauthorized application, in accordance with at least some aspects described herein. Ransomware cannot place encrypted data on the storage. If the ransomware uses its own encryption key, data encrypted with the ransomware's encryption key is detected and prevented from being written to the storage. prevention Authencrypt, in one approach, obtains all keys from a key server, where the key server has keys associated with at least some of the encrypted data in storage (e.g., there may be multiple keys associated with different portions of the encrypted data in storage). In a preferred embodiment, plaintext cannot be extracted from storage (e.g., to prevent leak-type attacks), and only authorized encryption is allowed.
[0058] In a preferred embodiment, all data written to storage is stored using authorized encryption and no clear text is stored in storage. Encryption and decryption is preferably restricted to authorized applications. Access to encryption keys is restricted to authorized encryption layers. Attempts to write unauthorized encrypted data are detected and the storage Blocked in (e.g., unauthorized encrypted data is not stored.) Authorizing new applications may require certification of the application and / or manual authorization by multiple parties, in a manner known in the art.
[0059] In preferred embodiments, protection against unauthorized encryption is provided using a layered approach. The only encryption permitted for data traversing the system is preferably authorized encryption. All encryption keys for authorized encryptions may be accessible by the system owner, and such encryptions may be distinguished from other encryptions without requiring knowledge of the encryption keys. This allows detection of unauthorized encryption without the requirement that the detector have access to the encryption keys or the plaintext data. These above-mentioned features increase system security by limiting the scope of keys and plaintext that are visible. Authorized Encryption function can be encapsulated in, for example, hardware, accelerators, trusted execution environments, etc., which generally improves security in the key and encryption process.
[0060] Figure 3 is a diagram of a high-level architecture according to various configurations. Architecture 300 may be implemented in accordance with the present invention in a variety of configurations, particularly in any of the environments shown in Figures 1-2 and 4-5. Of course, more or fewer elements than those specifically illustrated in Figure 3 may be included in architecture 300, as will be understood by those skilled in the art upon reading this specification.
[0061] Architecture 300 illustrates an exemplary data system according to one aspect. Architecture 300 includes a host system 302 and a storage system 304. Storage system 304 can be any type of storage system known in the art. It should be understood by those skilled in the art that storage system 304 can have more or fewer components than those listed herein. Architecture 300 includes a key server 306 and a watermark key server 308.
[0062] The host system 302 is function 310 and authorized applications 312. function310 may be synonymously referred to as "Authencrypt" throughout this disclosure. function 310 includes an encryptor / decryptor 314 , a watermark generator 316 , a pre-filter 318 , and an Authencrypt manager 320 .
[0063] 3, exemplary operations are shown for encrypting data sent from an authorized application 312. In a preferred embodiment, the authorization of the authorized application 312 is checked and the authorized encryption for the authorized application 312 is function Authorization to use 310 is verified prior to data transmission by Authencrypt Manager 320. As will be apparent to those skilled in the art upon reading this disclosure, authorization can be checked in any manner known in the art and with different levels of security. In one approach, a permission list can be used. In another approach, an application secure hash can be checked. In yet another approach, a full attestation of the application with authorization can be performed. If the application fails to obtain encryption authorization, processing of the data is suspended. prevention For example, data is not encrypted via authorized encryption. In at least some approaches, a notice may be logged and / or a warning may be sent to an administrator indicating that an unauthorized application has attempted to access Authencrypt.
[0064] Once an application is authorized (e.g., authorized application 312), an encryption key is selected for use. The encryption key may be associated with the authorized application 312 in any manner known in the art. In one approach, each system may have a single encryption key used for each of the system's authorized applications. In another approach, the encryption key may be a function of the application, the user, the system owner, a data set, a set of files, a set of volumes, etc. Any of the above information may be sent to the Authencrypt Manager 320 as a request for access by the authorized application 312 in operation 322. The Authencrypt Manager 320 may generate a new key and / or determine the identity of the encryption key associated with the request. The Authencrypt Manager 320 sends this information (e.g., information associated with the request for a new key or the identity of the encryption key associated with the request) to the key server 306 in operation 324.
[0065] In an alternative approach, the key server 306 receives the Authencrypt of Key generation is performed in response to a request to the key server 306 to generate a new key.
[0066] In a preferred embodiment, the key server 306 maintains the encryption keys and associated key identifiers (Key IDs) used by Authencrypt to encrypt data. In a preferred approach, the Key IDs are not easily predictable and / or determinable from the key itself. Random values and / or values encrypted under a separate key may be used to generate the Key IDs. Any other technique for generating Key IDs may be used. A Key ID that is not easily predictable and / or determinable from the key itself prevents unauthorized entities from gaining access to the encryption keys. For example, malware may be prevented from gaining access to an authorized process for a given client private data Key ID. It is beneficial to make it relatively difficult for a process to use the information to deduce other Key ID values, thereby limiting their ability to exfiltrate and / or modify data under other keys. In a preferred embodiment, the encryption keys stored within the key server 306 are not available to authorized applications 312. In various approaches, authorized applications 312 may have access to the Key IDs of encryption keys used to encrypt data to / from the authorized application 312. It will be apparent to those skilled in the art after reading this disclosure that, in various aspects, having access to a Key ID is not sufficient to gain access to data. Specifically, Authencrypt Manager 320 performs further checks, as described in more detail below, to determine that an application is authorized to utilize the Key ID.
[0067] In at least some approaches, the key server 306 associates a key ID with a stored encryption key (e.g., key k1 326, key k2 328, and key k3 330, as shown). As shown in FIG. 3, the Authencrypt manager 320 sends the key ID associated with the encryption key (in this case, key k1 326) to the key server 306. The Authencrypt manager 320 and / or the key server 306 may store metadata associated with the encryption key, where the metadata describes where the encryption key is used (e.g., which authorized application is associated with the encryption key). The key server 306 metadata may also include the key ID as a means to reference a particular encryption key, in a manner known in the art. For security purposes, the information used to identify the key is not configured to allow an observer to derive or guess the key. In some approaches, the Authencrypt manager 320 may generate a new key. In a preferred approach, the Authencrypt Manager 320 is securely isolated from authorized applications 312 in a manner known in the art, including via a Hardware Security Module (HSM), a Trusted Execution Environment (TEE), etc.
[0068] In a preferred embodiment, the Authencrypt Manager 320 grants and / or executes authorization for the application as part of operation 322. The Authencrypt Manager 320 communicates with the Key Server 306 to obtain an existing key or a new key based on a request from the application. In response to a request from an already authorized application (e.g., authorized application 312), the Authencrypt Manager 320 may determine that the application is associated with an existing Key ID. The application's existing Key ID and any associated certificates may be passed through the Authencrypt Manager 320. The Authencrypt Manager 320 verifies that the application is authorized to access the requested Key ID. If the application is authorized, the Authencrypt Manager 320 may grant authorization and instruct the Key Server 306 to make the key available in the Encrypter / Decrypter 314 in operation 332. For a new data set, the Authencrypt Manager 320 receives the Key ID in operation 324, and the Authencrypt Manager 320 passes the Key ID to the Watermark Key Server 308. In a preferred approach, the watermark key server may associate a new watermark with any combination of data request, encryption key, key ID, etc., in a manner that will be apparent to those skilled in the art upon reading this disclosure.
[0069] In a preferred approach, data requests sent to storage system 304 are associated with a key ID. The watermark verifier uses the key ID to obtain the watermark key to be used for verification. In at least some approaches, the watermark verifier can obtain the correct watermark key without interacting with Authencrypt Manager 320.
[0070] In an alternative approach, Authencrypt Manager 320 may use the key ID to obtain the watermark key from Watermark Key Server 308. Authencrypt Manager 320 may pass the watermark key to Storage System 304 in operation 319. In various approaches, Authencrypt Manager 320 may alternatively pass the watermark key to Watermark Generator 316 in operation 321.
[0071] The key server 306 securely transmits key k1 326 to the encryptor / decryptor 314 in operation 332. In an alternative embodiment, the key server 306 securely transmits key k1 326 to the Authencrypt manager 320, which transmits key k1 326 to the encryptor / decryptor 314. The encryptor / decryptor 314 may encrypt and / or decrypt using key k1 326 in a manner known in the art. For example, in the case of symmetric encryption, as shown, the encryptor / decryptor 314 uses the same key for encryption and decryption. If asymmetric encryption is used, the appropriate encryption or decryption key is used, as will be understood by those skilled in the art upon reading this disclosure. In a preferred embodiment, authorized encryption function 310 will not accept any encryption keys because they may be malicious. In contrast, permitted encryption function 310 indicates that the system owner has authorized encryption function Used by 310 R It may be necessary to have access to a copy of any key, thereby preventing an attacker from using encryption with an unknown key in the system (e.g., as in a ransomware-style attack). function 310 and key server 306 may authenticate each other in ways known in the art to provide additional security against spoofing. The passing of the key via operation 332 may also be performed in a secure manner, such as over an encrypted link or using a secure key exchange protocol.
[0072] The authorized application 312 may, in operation 334, send the data to be encrypted to the authorized encryption function 310 (e.g., Authencrypt layer). In a preferred embodiment, the data is transmitted over a secure link, as described above. In various approaches, as described in more detail below, an optional pre-filter 318 receives the data and checks whether the data is already encrypted. In operation 336, the pre-filter 318 detects encryption. function The data that passes through is sent to the encryptor / decryptor 314. The encryptor / decryptor 314 encrypts the data using the key k1 326 obtained from the key server 306. In operation 338, the encrypted data is sent to the watermark generator 316.
[0073] In a preferred embodiment, the watermark generator 316 may pass metadata (e.g., key ID) to the watermark key server 308 so that the correct watermark key can be selected. For example, as shown, in operation 342, watermark key w1 340 is selected and sent to the watermark generator 316. The associated watermark but , is calculated by the watermark generator 316 using the watermark key w1 340. In operation 344, the encrypted data and the generated watermark are output. In various approaches, authorized encryption function310 and watermark key server 308 may authenticate each other to provide security against spoofing. Watermark key server 308 may include metadata associated with the watermark keys that describes where the watermark keys can be used (e.g., a set of watermark key IDs, a list of applications, a set of files, a set of volumes, etc.). As shown in FIG. 3, Authencrypt manager 320 sends information to watermark key server 308 that enables watermark key server 308 to determine applicable watermark keys. Watermark key server 308 may also maintain watermark key IDs that are used as references to associated watermark keys, similar to how key IDs can be references to encryption keys from key server 306. The passing of watermark keys, such as in operation 342, is preferably performed in a secure manner, such as via an encrypted link, a secure key exchange protocol, etc.
[0074] In various approaches, the following definitions may be applicable to performing write operations as described herein and shown in FIG.
[0075] Definition:
[0076] pi= Input average Literature
[0077] ci=pi The output is ciphertext
[0078] Watermark Token for txi=ci As explained below, the watermark token can be used by the detector to verify that the received parameters are correct.
[0079] k1 = data encryption key (from key server)
[0080] w1 = Watermark key (from watermark key server)
[0081] wi = encrypted data block ci of Watermark
[0082] In various approaches, the watermark generator 316 generates a value that uniquely identifies the encrypted data (e.g., of Any number of methods for creating a watermark may be used. In a preferred embodiment, a keyed hash message authentication code (HMAC) may be used, in a manner that will be understood by those skilled in the art.
[0083] The hash function can be any type of hash, depending on the level of security desired as determinable by one skilled in the art. Exemplary hash functions include MD5, SHA256, etc. In one approach, the hash function can be used without an HMAC, as in the SHA3 hash function. In the above approach, a keyed MAC, as defined below, can be used.
[0084] MAC=hash(key||ci)
[0085] The use of a watermark key that is different from the encryption key allows the encrypted data to be watermarked without access to the unencrypted data (e.g., plaintext data) and / or the encryption key. of This allows the watermark to be verified. Access to the watermark key allows the storage to verify that encryption is authorized, without access to the encryption key or plaintext. Other features prevent a party from tampering with the encrypted data or the watermark in an undetectable manner. The encrypted data can be detected in a secure manner.
[0086] In various aspects, the three basic operations used to create a watermark can be mathematically described as follows:
[0087] ci= encryption (k1,pi )
[0088] txi=MAC(ci)
[0089] wi=HMAC(w1,ci||txi)
[0090] After this operation, the authorized encrypted data is ready to be sent to storage. This can be achieved by the following operations:
[0091] Send to storage:{ci,txi,wi}
[0092] The storage system also receives metadata (e.g., from the watermark generator, as described above) that identifies the watermark key associated with this tuple. The watermark generator passes the metadata to a watermark key server, in a manner known in the art, so that the appropriate watermark key can be selected. For example, in various aspects, when a watermark key is associated with a file, a link between the watermark generator and the storage system is established such that the metadata is associated with a link in the storage controller that contains the metadata associated with the correct watermark key. Once the link is established, the watermark key is retrieved and stored by the storage system, and is used to retrieve and store the watermark key for the block of data in the request. whereas In an alternative implementation, there may be a separate watermark key for every block of data.
[0093] Verification is performed by the storage unit before writing a block and / or after reading a block. Blocks that fail verification are not written to storage, or similarly, reads are not returned to the requester. The operation of at least some aspects of verification is mathematically described below:
[0094] Receive (ci, txi, wi)
[0095] Get w1 from the watermark key server
[0096] wi'=HMAC(w1,ci||txi)
[0097] Verification wi==wi'
[0098] In a preferred embodiment, the storage system calculates the watermark using ci and txi passed along with the watermark. Storage systems are independent The storage system independently receives the watermark key from the watermark key server, as described above. As will be apparent to those skilled in the art upon reading this disclosure, verification fails if ci or txi are not values generated by the watermark generator. For example, verification may fail if a malicious actor tampers with the values (of ci and / or txi) before they reach storage. HMAC provides additional security against forgery of either of these values.
[0099] As will be apparent to those skilled in the art upon reading this disclosure, for an authorized application, an authorized read of encrypted data is substantially the reverse of a write operation. In a preferred embodiment, the storage unit validates the block before returning it to the requester. In one approach, the first validation described below duplicates the validation performed at the storage unit. However, if the block fails the first validation, the second validation allows the system to determine where the error occurred. Note that if the first validation is successful, txi must be explicitly validated so that the application can proceed to decrypt the data. In some embodiments, the operation of the system upon receiving a block from storage is mathematically described below. In an alternative embodiment, only one of the two validations (the first) is sufficient.
[0100] Read (decrypt):
[0101] Read {ci,txi,wi} from storage
[0102] Get w1 from the watermark key server
[0103] wi'=HMAC(w1,ci||txi)
[0104] Validation wi==wi' (if validation fails, an error is reported)
[0105] txi'=MAC(ci)
[0106] Validation txi'=txi (If validation fails, an error is reported)
[0107] Obtain k1 from the key server
[0108] pi = decryption(k1,ci)
[0109] In some approaches, other types of watermarks may include hashing the encrypted data and encrypting the hash with a watermark key, hashing the encrypted data with a watermark key, etc. Asymmetric encryption techniques may be used, including PKI signatures, where a hash of the encrypted data is then encrypted with a private key. A public key may be used to verify the signature, as will be apparent to those skilled in the art upon reading this disclosure.
[0110] In a manner that will be apparent to those skilled in the art upon reading this disclosure, those skilled in the art may modify the various operations described herein to achieve a desired level of security based on design requirements and the selection of operations used to create the watermark. Watermarks provide the ability to check the authenticity of encryption without knowing the encryption key. Watermarks provide resistance to forgery and the ability to detect alterations to the watermark and / or encrypted data. Performing these operations using symmetric encryption is often preferred due to the increased performance that can be achieved, resistance to quantum attacks, smaller key sizes, etc.
[0111] 3, in operation 344, the encrypted data, watermark token, and associated watermark represent the authorized encryption of input data from authorized application 312. When storing the encrypted data, the encrypted data, watermark token, and associated watermark are securely transmitted to storage system 304 via operation 344. The storage system includes storage 346 and an Authencrypt verifier 348. In a preferred embodiment, all data transferred to and from storage system 304 passes through Authencrypt verifier 348. Authencrypt verifier 348 verifies that the encrypted data represents the authorized encryption. function Detect unauthorized encrypted data by determining whether it was sent in a manner that bypasses 310 (e.g., sent directly to storage system 304). The Authencrypt verifier 348 and its associated functionality may be encapsulated, for example, in hardware, an accelerator, a trusted execution environment, etc., which increases security in the watermark key and watermark generation process.
[0112] Prior to storing the data, the Authencrypt verifier 348 may obtain a watermark key associated with the data from the watermark key server 308 at operation 350. In various approaches, the Authencrypt verifier 348 includes a watermark generator and a comparator. The watermark generator may calculate a watermark associated with the received encrypted data (e.g., received via operation 344) and compare the calculated watermark with the watermark received with the encrypted data. If the watermarks do not match, the encrypted data is not stored. In some approaches, the watermarks must match within a predetermined range. For example, in some approaches, the watermarks must be identical to be considered a "match." In other approaches, a predetermined portion, percentage, subcomponent, etc. of the watermark must match. In at least some aspects, in response to determining that the watermarks do not match, a notice may be logged and / or a warning may be sent to an administrator indicating that an attempt to store unauthorized data has been made. If the watermarks match, the encrypted data, watermark token, and associated watermark are transferred to storage 346 at operation 352. In a preferred embodiment, storage system 304 stores the associated watermark and watermark token along with the encrypted data so that the encrypted data can be inspected for alterations. Verification can be performed without Authencrypt verifier 348 having access to the plaintext of the key used to create the ciphertext (e.g., the encrypted data). In one approach, if the watermark is generated as a cryptographic hash (e.g., as a PKI signature), the detection operation of Authencrypt verifier 348 involves decrypting the watermark with the watermark key and translating the decrypted watermark into the encrypted data in a manner that will be apparent to those skilled in the art upon reading this disclosure. of This involves comparing the computed hash.
[0113] Authencrypt verifier 348 may verify that the data was encrypted with Authencrypt and that it has not been modified at any time, such as when read, during a scrub operation (e.g., checking data integrity), etc. In some approaches, to verify the data, information identifying the encryption key (e.g., Key ID) and / or information identifying the watermark key (e.g., Watermark Key ID) may be stored in storage 346.
[0114] Detecting that input data is encrypted may be performed in a manner known in the art. For example, data from an authorized application may have a format and / or characteristics that may be determined from unencrypted data but are absent from encrypted data. Other techniques for detecting that input data is encrypted include entropy measurements, statistical tests, etc., used to assign a probability that a portion of data is encrypted. The system may use multiple data chunks, blocks, etc. to improve the accuracy of the detection probability. If the storage system supports continuous data protection, snapshots, or other means for temporarily storing data (e.g., supports rollback), detection may occur after a predetermined number of data pieces have been processed. An event, such as a snapshot, may be triggered if a high probability of encrypted input is detected.
[0115] The storage system 304 may include further encryption of the encrypted data and associated watermark. The further encryption may be securely implemented to prevent an attacker from using the further encryption as a means to encrypt data so that the owner of the data cannot decrypt it (e.g., access the data in the clear). One secure implementation of the further encryption may include a self-encrypting storage unit.
[0116] In some embodiments, the storage system 304 may support the storage of unencrypted data. and Plaintext data and and reject unauthorized encryption, thereby allowing plaintext data to be stored. function (e.g., pre-filter 318) may be added to storage system 304. memory , may be limited to data that is less sensitive to unauthorized disclosure in a manner determinable by one skilled in the art, as allowing such data reduces security against leak-type attacks on plaintext data.
[0117] As described above, encryption keys, watermark keys, mixed keys (described in more detail below, see FIG. 4), etc. may be stored on a key server. The key server may be a distributed key server for additional resiliency. The keys, mixed keys, and / or watermark keys may be stored in any other manner known in the art. For example, the keys, mixed keys, and / or watermark keys may be stored on separate storage devices or the same storage device; the keys, mixed keys, and / or watermark keys may be generated and / or managed by a key manager of a type known in the art; the keys, mixed keys, and / or watermark keys may be stored on the host system, the storage system, or any combination thereof; etc. As shown in FIG. 3, the keys and watermark keys are stored separately to provide isolation. A container-like system, or TEE, may be used to isolate the keys, mixed keys, and / or watermark keys from system administrators, other users without root privileges, etc.
[0118] In a preferred embodiment, the Authencrypt Manager 320 manages authorized encryption function In some approaches, the Authencrypt Manager 320 is integrated into the TEE (e.g., the Authorized Encryption Engineer) within the host. function310). In yet a further approach, Authencrypt Manager 320 may be incorporated into a separate secure component such as Key Server 306, Watermark Key Server 308, an HSM or TEE in another host, etc. In each of these alternative approaches, all links between Authencrypt Manager 320 and other components are secured with authentication, encryption, integrity protection, etc. for data security.
[0119] Data of any type can be written and / or read, including data blocks, files, objects, any other data format, or any combination thereof. The trust level of the Authencrypt verifier 348 allows the Authencrypt verifier 348 to have access to the ciphertext (e.g., encrypted data), the watermark, and the watermark key. The Authencrypt verifier 348 may alter blocks of ciphertext and adjust the watermark. Figure 4 shows how alteration of the watermark by the Authencrypt verifier is detected using modifications to the watermark process.
[0120] Figure 4 is a diagram of a high-level architecture according to various configurations. Architecture 400 may be implemented in accordance with the present invention in a variety of configurations, particularly in any of the environments shown in Figures 1-3 and 5-6. Of course, more or fewer elements than those specifically illustrated in Figure 4 may be included in architecture 400, as will be understood by those skilled in the art upon reading this specification.
[0121] Architecture 400 illustrates an exemplary data system according to one aspect. It should be understood by those skilled in the art that Figure 4 shares common components with Figure 3, and common features have common numbers and functions.
[0122] Each watermark key is associated with an additional mixed key (e.g., mixed key h1 402, mixed key h2 406, mixed key h3 410, etc.). For example, watermark key w1 340 is associated with additional mixed key h1 402, watermark key w2 404 is associated with additional mixed key h2 406, and watermark key w3 408 is associated with additional mixed key h3 410. In an exemplary implementation, mixed key h1 402 is associated with the additional mixed key h1 402 (e.g., authorized encryption key h1 402). function 310 for the encrypted data. The mixed key h1 402 is used to create the watermark token (generated for the encrypted data by Authencrypt verifier 348). The mixed key h1 402 is not available to the Authencrypt verifier 348. In a preferred embodiment, the mixed key is encoded into ciphertext as part of the watermark creation. For example, as described below, plaintext block pi is encrypted with key k1 326 to produce ciphertext block ci:
[0123] ci= encryption (k1,pi)
[0124] The watermark token is created as follows:
[0125] txi=HMAC(h1,ci)
[0126] In various aspects, the mixed key is used as a key for a first HMAC to generate an unforgeable representation (e.g., a signature) of the encrypted data, called a watermark token. At operation 412, the mixed key h1 402 may be sent to the watermark generator 316 in a manner known in the art. In an alternative approach, the encryption key (e.g., key k1 326) and the mixed key (e.g., mixed key h1 402) are provided to the Authencrypt Manager 320. In this alternative approach, the Authencrypt Manager 320 provides the encryption key to the encryptor / decryptor 314, and the Authencrypt Manager 320 provides the mixed key to the watermark generator 316. This unforgeable representation is used in a second HMAC to generate the watermark wi. The two HMACs are made to allow the storage to verify the encryption without having access to the encryption key k1.
[0127] 3, the watermark key w1 340 is obtained from the watermark key server 308. The watermark is created as follows:
[0128] wi=HMAC(w1,ci||txi)
[0129] To store the data, in operation 344, the plaintext block pi of The ciphertext ci, the watermark token txi, the metadata, and the watermark wi are sent to the storage system 304. As described above with reference to Figure 3, the Authencrypt verifier 348 obtains the watermark key w1 340 from the watermark key server 308. The watermark for the ciphertext ci is calculated as follows:
[0130] wi'=HMAC(w1,co||txt), And compared with wi 4 and described herein, the Authencrypt verifier 348 does not have sufficient information to alter ci to ci′ and create a watermark wi′ that matches ci′, where the Authencrypt verifier 348 does not have access to the mixed key h1 402. When the ciphertext is altered to ci′, the watermark is calculated as follows:
[0131] wi'=HMAC(w1,ci'||txi)
[0132] Without access to h1, the value of txi' that matches ci' cannot be calculated. When the data is verified by the host system 302 upon reading, it calculates:
[0133] txi'=HMAC(h1,ci')≠txi,
[0134] wi''=HMAC(w1,ci'||txi')≠wi', In this way, the alteration is detected.
[0135] Another form of attack is to use the contents of a previously written block with authorized encryption to write a different block. to This includes replay attacks where a block is substituted. The substituted block can be from another location, or the substituted block can be a previous copy of a block from the same location. The former type includes, for example, The relevant This can be detected by using Advanced Encryption Standard Ciphertext Stealing (AES-XTS) encryption, where location is part of the encryption algorithm. The latter can be prevented in some ways by introducing a sequence number into the watermark and / or metadata, in a manner that will be apparent to those skilled in the art upon reading this disclosure. The sequence number si for a plaintext block pi is given by: the place toThe size of the value may indicate the number of times it has been written. In some aspects, the size of the value determines the level of security. For example, an 8-bit value allows for 256 unique sequence numbers before wrapping. A larger value, such as 4 bytes, would yield over 4 billion unique sequence numbers. The size of the sequence number determines the probability that an attacker can achieve a valid replay value and the location to It may be determined by the maximum number of times it can be written. The sequence number si may be a simple count, a nonce, a hash of the count, a timestamp, etc.
[0136] The watermark token generation can be updated accordingly to include si:
[0137] txi:HMAC(h1,ci||si)
[0138] In operation 344, the sequence number si may be sent to the storage system 304 along with ciphertext (e.g., encrypted data), where the sequence number si is encrypted to prevent the sequence number si from being decrypted at the storage system 304. In one exemplary approach, the sequence number si is encrypted with key k1 326, watermark key w1 340, along with mixed key h1 402, etc.
[0139] Additional metadata may be added to the data and / or watermark. For example, Key ID and / or Watermark Key ID information may be added to the data and / or watermark. In some approaches, the Watermark Key ID may be attached to the watermark, allowing the Authencrypt verifier 348 to determine the correct watermark key without an external reference. In one aspect, the Key ID may be included with the data and verified when the data is decrypted. Data integrity information may be included with the encrypted data, including a Cyclic Redundancy Check (CRC), hash, Message Authentication Code (MAC), etc., to provide an end-to-end integrity check, in a manner that will be apparent to those skilled in the art upon reading this disclosure.
[0140] Referring now to Figure 5, there is shown a flowchart of a method 500 according to one embodiment. Method 500 may be performed in accordance with the present invention in various embodiments, particularly in any of the environments shown in Figures 1-4 and 6. Of course, more or fewer operations than those specifically illustrated in Figure 5 may be included in method 500, as will be understood by those skilled in the art upon reading this specification.
[0141] The steps of method 500 may be performed by any suitable component of an operating environment. For example, in various aspects, method 500 may be performed partially or entirely by a computer or some other device having one or more processors therein. A processor, e.g., a processing circuit, chip, and / or module, implemented in hardware and / or software and preferably having at least one hardware component, may be utilized in any device to perform one or more steps of method 500. Exemplary processors include, but are not limited to, a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or the like, combinations thereof, or any other suitable computing device known in the art.
[0142] As shown in FIG. 5, method 500 includes operation 502. Operation 502 includes authenticating an application as authorized to perform encryption. In a preferred embodiment, an authorized encryption layer (e.g., an authorized encryption layer) on the host system performs authentication of the application in a manner known in the art. In various approaches, the application must be authorized to perform encryption and / or store encrypted data within the storage system. In any manner known in the art, a host system, user, system, etc. may determine whether an application or applications are authorized before the application requests to read and / or write encrypted data from and / or to the storage system. In a preferred embodiment, unencrypted data is not stored within the storage system.
[0143] In various aspects, in response to determining that the application is not authorized for encryption, the authenticated encryption layer blocks read requests, write requests, etc. from the unauthorized application. preventionIn some aspects, the system may log the incident and / or send a warning to a user of the system to indicate a possible attack from a malicious actor. In response to determining that the application is authorized for encryption, method 500 proceeds to operation 504.
[0144] Operation 504 includes receiving data at the authenticated encryption layer. In at least some approaches, an authorized application may send data to the authenticated encryption layer in a write request. The data may include any data format known in the art. The data may be in the form of a data file, chunks, blocks, etc., or any combination thereof. In various approaches, the data is received at the authenticated encryption layer in any manner known in the art. In a preferred aspect, the data is received only in response to determining that the application sending the data is authorized.
[0145] In one approach, the authenticated encryption layer is a pre-filter. function In a preferred embodiment, a prefilter function performs an encryption detection function that includes determining whether the data has been pre-encrypted. More specifically, the pre-filter encryption detection function determines whether the data has been previously encrypted with an encryption key that is unknown (e.g., unknown) at an authenticated encryption layer, a storage system, a host system, etc., or any combination thereof. function determines whether the data is encrypted with any encryption key. In response to determining that the data is encrypted, the authenticated encryption layer: to data Further Processing Prevent (e.g., an error may be output, data to Further encryption Prevent(The data may be encrypted, the write and / or read request may be denied, etc.). As noted above, an error may be logged and / or a warning may be sent to the user. Specifically, in response to determining that the data is encrypted, the authenticated encryption layer may prevention In one exemplary embodiment, the authenticated encryption layer blocks write requests to encrypted data, even if the requests are from authorized applications. prevention The authenticated encryption layer preferably only encrypts unencrypted data for authorized applications.
[0146] In various aspects, in response to authenticating the application as authorized for encryption, the authenticated encryption layer for In at least some approaches, the encryption key and watermark key may be stored in separate key servers. whereas For example, the encryption key is stored in the first key server. whereas The watermark key can be requested and sent to the watermark key server. whereas In other aspects, the encryption key and the watermark key are requested from the same key server. The key server may be located on the host system, may be encapsulated from the host system and / or the storage system, may be located on the storage system, etc. In preferred aspects, the storage system does not have access to the encryption key.
[0147] Operation 506 includes encrypting the data with an encryption key. The encryption key may be used to encrypt the data in a manner known in the art. In a preferred embodiment, the encryption key is not available to the application. The encryption key may be requested by an authorized encryption layer and sent directly to the authorized encryption layer in response to a request, preferably bypassing authorized applications.
[0148] In various approaches, the authenticated encryption layer requests encryption and / or watermark keys based on the credentials of authorized applications. For example, each authorized application may be associated with a single encryption key and a single watermark key. In another example, each authorized application may be associated with a set of encryption keys and a set of watermark keys. Any combination of applications, encryption keys, watermark keys, etc. may be used in accordance with at least some aspects described throughout this disclosure.
[0149] Act 508 includes generating a watermark token for the encrypted data. In various approaches, generating the watermark token includes: dark Encrypted data, In case of infringement This may include any process of converting a watermark token into a random string of characters (e.g., a token) that has no significant value. Any tokens as referred to herein may serve as references to the original data, but the token cannot be used to infer their value (e.g., to access the data). In at least some approaches, the watermark token is a message authentication code (MAC) of the encrypted data. In various approaches, an authenticated encryption layer results in metadata associated with the watermark token and / or the watermark key.
[0150] In preferred embodiments, generating a watermark token for the encrypted data includes incorporating a mixed key. In some embodiments, the mixed key is received at the authenticated encryption layer from a key server that provided the encryption key to the authenticated encryption layer. The mixed key may be encoded into the encrypted data as part of creating the watermark using an HMAC function. For example, the mixed key may be encoded into the encrypted data as part of creating the watermark using an HMAC function to generate the watermark token for the encrypted data. ofIn the second HMAC function, the watermark token may be used to generate a watermark (e.g., in a manner similar to generating the watermark in operation 510 below).
[0151] Act 510 includes generating a watermark for the encrypted data using the watermark token and the watermark key. In various aspects, the watermark for the encrypted data may be generated in any manner known in the art. In one approach, the watermark is a keyed hash message authentication code using the watermark key and the watermark token in a manner that will be apparent to those skilled in the art upon reading this disclosure. In various approaches, a mixed key is used in a first HMAC to generate the watermark token. of When used as a key, the watermark token can be used in a second HMAC to generate the watermark. In these approaches, the two HMACs provide the storage system with the ability to verify authorized encryption without having access to the encryption key or the mixed key. For example, without the mixed key, the storage system cannot duplicate the watermark token and any alterations to the data will be detected.
[0152] Operation 512 includes transmitting the encrypted data, the watermark token, and the watermark to a storage system. In some approaches, the storage system may be a subsystem of a computer for performing the method, such as a data storage drive that is part of the computer and / or directly coupled to the computer. In various approaches, metadata associated with the watermark and / or the watermark key is transmitted to the storage system. The storage system may request the associated watermark key from a key server based on the metadata, in a manner that will be apparent to those skilled in the art upon reading this disclosure. As described in more detail below with reference to FIG. 6, in a preferred embodiment, the storage system is configured to verify the encrypted data using the watermark key. In response to the storage system verifying the encrypted data, the encrypted data and the watermark for the encrypted data are stored in the storage system in a manner known in the art.
[0153] Referring now to Figure 6, there is shown a flowchart of a method 600 according to one embodiment. Method 600 may be performed in accordance with the present invention in various embodiments, particularly in any of the environments shown in Figures 1-5. Of course, more or fewer operations than those specifically illustrated in Figure 6 may be included in method 600, as will be understood by those skilled in the art upon reading this specification.
[0154] The steps of method 600 may be performed by any suitable component of an operating environment. For example, in various aspects, method 600 may be performed partially or entirely by a computer or some other device having one or more processors therein. A processor, e.g., a processing circuit, chip, and / or module, implemented in hardware and / or software and preferably having at least one hardware component, may be utilized in any device to perform one or more steps of method 600. Exemplary processors include, but are not limited to, a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or the like, combinations thereof, or any other suitable computing device known in the art.
[0155] As shown in FIG. 6, method 600 includes operation 602. Operation 602 includes receiving encrypted data, a watermark token, metadata, and a first watermark of the encrypted data at a storage system. The encrypted data may be received from an authenticated encryption layer in a host system. The encrypted data may be part of a write request from an authorized application to write the encrypted data to the storage system. In a preferred embodiment, the metadata is associated with the first watermark, the watermark token, and / or a watermark key used to generate the first watermark. The watermark token may be of the encrypted data. As described above with reference to FIG. 5, in a preferred embodiment, the watermark token is generated as per operation 508 of method 500. As described above with reference to FIG. 5, in a further preferred embodiment, the watermark token is generated as per operation 510 of method 500. In an even further preferred embodiment, the storage system does not have access to the encryption key used when the encrypted data is encrypted.
[0156] Operation 604 includes receiving a watermark key associated with the metadata. In a preferred approach, the storage system requests the watermark key from a key server based on the metadata received with the encrypted data and the first watermark, in a manner that will be apparent to those skilled in the art upon reading this disclosure.
[0157] Operation 606 includes generating a second watermark of the encrypted data using the watermark key. The watermark of the encrypted data may be generated in a manner similar to that described with reference to operation 510 of FIG. 5.
[0158] Operation 608 includes comparing the second watermark of the encrypted data to the first watermark of the encrypted data. In a preferred embodiment, in response to determining that the second watermark matches the first watermark, method 600 includes storing the encrypted data, the watermark token, and the first watermark. In some approaches, the second watermark matches the first watermark within a predetermined range. For example, in some approaches, the watermarks must be identical to be considered a "match." In other approaches, a predetermined portion, percentage, subcomponent, etc. of the watermark must match. In various embodiments, method 600 includes sending an alert to a user in response to determining that the second watermark does not match the first watermark.
[0159] In a preferred embodiment, the method 600, in response to determining that the second watermark does not match the first watermark, is to be remembered of prevention In some embodiments, the encrypted data and the first watermark are is to be remembered of preventionFor example, a storage system may receive encrypted data pending verification and temporarily store it in a cache, as will be apparent to those skilled in the art upon reading this disclosure.
[0160] The storage system is preferably configured to verify the encrypted data for storage before writing a block and / or after reading a block. Blocks that fail verification are not written to storage, or similarly, reads are not returned to the requester. In various aspects, the storage system uses the encrypted data and watermark token received with the first watermark to verify the encrypted data for storage. The storage system Independent hand calculation do If the encrypted data and / or the associated value of the watermark token are not values generated by an authenticated encryption layer, the verification fails. In at least some approaches, the storage system performs a second verification of the encrypted data, where the storage system uses a MAC of the encrypted data and independently calculates a watermark token. If the calculated watermark token does not match the received watermark token, an error may be reported, the request may be rejected, etc.
[0161] In a preferred approach using a mixed key, the storage system does not have access to the mixed key used to generate the watermark token, thereby improving the security of the system. In other approaches where the storage system has access to the mixed key, the storage system may perform a second verification of the encrypted data by independently calculating a watermark token using the mixed key and an HMAC of the encrypted data, as will be apparent to those skilled in the art upon reading this disclosure.
[0162] The present invention may be a system, method, and / or computer program product at any possible level of technical detail integration. The computer program product may include a computer-readable storage medium (or multiple computer-readable storage media) having computer-readable program instructions for causing a processor to perform aspects of the present invention.
[0163] A computer-readable storage medium may be a tangible device that can hold and store instructions for use by an instruction-execution device. A computer-readable storage medium may be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory sticks, floppy disks, mechanically encoded devices such as punch cards or ridge structures in grooves in which instructions are recorded, and any suitable combination of the foregoing. Computer-readable storage medium, as used herein, should not be construed as a transitory signal per se, such as an electric wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse passing through a fiber optic cable), or an electrical signal transmitted through a wire.
[0164] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface within each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing / processing device.
[0165] The computer-readable program instructions for carrying out the operations of the present invention may be either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for an integrated circuit, or source or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk®, C++, etc., and procedural programming languages such as the “C” programming language or similar programming languages. The computer-readable program instructions may run entirely on the user's computer, as a standalone software package, partially on the user's computer, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (e.g., through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry in order to perform aspects of the present invention.
[0166] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0167] These computer-readable program instructions may be provided to a processor of a computer or other programmable data processing apparatus to produce a machine, whereby the instructions, executed by the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. These computer-readable program instructions may also be stored on a computer-readable storage medium that may direct a computer, programmable data processing apparatus and / or other device to function in a particular manner, whereby the computer-readable storage medium on which the instructions are stored comprises an article of manufacture including instructions that implement aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.
[0168] The computer-readable program instructions may be loaded onto a computer, other programmable data processing apparatus, or other device, and cause the computer, other programmable apparatus, or other device to execute a series of operational steps to produce a computer-implemented process, such that the instructions executing on the computer, other programmable apparatus, or other device implement the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.
[0169] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions, including one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the figures. For example, two blocks shown in succession may actually be implemented as a single step, or may be executed simultaneously, substantially simultaneously, partially, or fully overlapping in time, or the blocks may possibly be executed in the reverse order, depending on the functionality involved. It should also be noted that each block of the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or executes a combination of dedicated hardware and computer instructions.
[0170] Additionally, systems according to various embodiments may include a processor and logic integrated with and / or executable by the processor, the logic configured to perform one or more of the process steps described herein. "Integrated with" means that the processor has logic embedded as hardware logic, such as in an application-specific integrated circuit (ASIC), FPGA, etc. "Executable by the processor" means that the logic is hardware logic; software logic, such as firmware, part of an operating system, part of an application program, etc., or any combination of hardware and software logic accessible by the processor and configured to cause the processor to perform some function when executed by the processor. Software logic may be stored in local and / or remote memory of any memory type known in the art. Any processor known in the art may be used, including software processor modules and / or hardware processors, such as ASICs, FPGAs, central processing units (CPUs), integrated circuits (ICs), graphics processing units (GPUs), etc.
[0171] It will be apparent that the various features of the above-described systems and / or methods may be combined in any manner to create multiple combinations from the description provided above.
[0172] It will further be appreciated that embodiments of the present invention may be provided in the form of a service that is deployed on behalf of a customer to provide the service on demand.
[0173] The description of various embodiments of the present invention has been presented for illustrative purposes, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the described embodiments. The terminology used herein has been selected to best explain the principles of the embodiments, practical applications of, or technical improvements to, the technology found in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
1. On your computer: steps to authenticate the application as authorized to perform cryptography; receiving data with an authenticated encryption layer; encrypting the data using an encryption key, the encryption key being available to the authenticated encryption layer and not available to the application; generating a watermark token for the encrypted data; generating a watermark for the encrypted data using the watermark token and a watermark key; and transmitting the encrypted data, the watermark token, and the watermark to a storage system, the storage system being configured to verify the encrypted data using the watermark key upon storing the encrypted data; A computer program for executing
2. The computer program product of claim 1 , wherein generating a watermark token for the encrypted data comprises using a mixed key.
3. The computer program product of claim 1 or 2, wherein the watermark is a keyed hash message authentication code.
4. The computer, requesting the encryption key for the data in response to authenticating the application as authorized to perform encryption; and requesting the watermark key for the data; 3. The computer program according to claim 1, further comprising:
5. The computer, determining, prior to said step of encrypting said data with an encryption key, whether said data has been previously encrypted with an unknown encryption key using a pre-filter function; and and in response to determining that the data has been previously encrypted with the unknown encryption key, preventing encryption of the data with the encryption key.
3. The computer program according to claim 1, further comprising:
6. The computer, 3. The computer program product of claim 1, further comprising: a program for causing the application to execute a procedure for preventing the application from encrypting the data using the encryption key in response to determining that the application is not authorized to perform encryption.
7. On your computer: receiving, at a storage system, encrypted data, a watermark token, metadata, and a first watermark for the encrypted data; receiving a watermark key associated with the metadata; generating a second watermark of the encrypted data using the watermark token and the watermark key; and comparing the second watermark of the encrypted data with the first watermark of the encrypted data. A computer program for executing
8. The computer, 8. The computer program product of claim 7, further comprising, in response to determining that the second watermark matches the first watermark, storing the encrypted data and the first watermark.
9. The computer, 8. The computer program product of claim 7, further comprising: in response to determining that the second watermark does not match the first watermark, preventing the encrypted data and the first watermark from being stored.
10. The computer, 10. The computer program product of claim 9, further comprising the step of: sending a warning to a user in response to determining that the second watermark does not match the first watermark.
11. The computer program product of claim 7 , wherein the storage system does not have access to an encryption key used to encrypt the encrypted data.
12. authenticating the application as authorized to perform encryption; receiving data with an authenticated encryption layer; encrypting the data using an encryption key, the encryption key being available to the authenticated encryption layer and not available to the application; generating a watermark token for the encrypted data; generating a watermark for the encrypted data using the watermark token and a watermark key; and transmitting the encrypted data, the watermark token, and the watermark to a storage system, the storage system being configured to verify the watermark key with the encrypted data upon storing the encrypted data. A computer-implemented method comprising:
13. The computer-implemented method of claim 12, wherein generating the watermark token includes using a mixed key.
14. 14. The computer-implemented method of claim 12 or claim 13, wherein the watermark is a keyed-hash message authentication code.
15. requesting the encryption key for the data in response to authenticating the application as authorized to perform encryption; and requesting the watermark key for the data 14. The computer-implemented method of claim 12 or claim 13, comprising:
16. The method of claim 15, further comprising: determining, prior to encrypting the data with an encryption key, whether the data has been previously encrypted with an unknown encryption key by a pre-filter function; and and in response to determining that the data has been previously encrypted with the unknown encryption key, preventing encryption of the data with the encryption key.
14. The computer-implemented method of claim 12 or claim 13, comprising:
17. 14. The computer-implemented method of claim 12 or 13, further comprising preventing the application from encrypting the data with the encryption key in response to determining that the application is not authorized to perform encryption.
18. receiving, at a storage system, encrypted data, a watermark token, metadata, and a first watermark for the encrypted data; receiving a watermark key associated with the metadata; generating a second watermark of the encrypted data using the watermark token and the watermark key; and comparing the second watermark of the encrypted data with the first watermark of the encrypted data. A computer-implemented method comprising:
19. 20. The computer-implemented method of claim 18, comprising, in response to determining that the second watermark matches the first watermark, storing the encrypted data and the first watermark.
20. 20. The computer-implemented method of claim 18, comprising, in response to determining that the second watermark does not match the first watermark, preventing the encrypted data and the first watermark from being stored.
21. 21. The computer-implemented method of claim 20, comprising, in response to determining that the second watermark does not match the first watermark, sending a warning to a user.
22. 20. The computer-implemented method of claim 19, wherein the storage system does not have access to an encryption key used to encrypt the encrypted data.
Citation Information
Patent Citations
Watermarking digital objects
JP2001518651A
Video and sound recording apparatus, and data processing method
JP2011142425A
Storage device and program
JP2020030527A
Method and apparatus for watermarking of digital content, method for extracting information
US20190294761A1
Storage device and program
US20200065528A1