Adaptive Re-keying Engine for Storage Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data at rest encryption systems face inefficiencies in re-keying processes due to static re-key policies, which can lead to prolonged computation times and significant resource usage, failing to optimally manage storage system resources and maintain cryptographic key compliance.
Innovation Solution
An adaptive re-keying process that dynamically selects the optimal re-keying procedure based on utilization information, utilizing a re-keying engine to prioritize and schedule re-keying operations, minimizing system impact and ensuring compliance by dynamically calculating re-key timing and resource allocation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If re-keying is performed frequently to maintain cryptographic compliance, then security compliance is improved, but system computation resources and time are excessively consumed
Solution Approach 1:
The patent implements dynamic re-keying policies that adjust re-keying frequency and timing based on current system conditions including workload, available resources, and compliance requirements. The system transitions from static predetermined re-keying schedules to adaptive policies that can be modified in real-time to balance security compliance with system performance and resource utilization.
2Reliability
If re-keying is performed on large data volumes, then cryptographic compliance is maintained, but computation time is significantly prolonged
Solution Approach 1:
The patent segments large data volumes into smaller partitions or chunks that can be re-keyed independently and in parallel. This division allows the re-keying process to be distributed across multiple processing units or time slots, reducing the overall computation time while maintaining compliance with cryptographic key rotation requirements for the entire data set.
3Ease of operation
If static re-key policies are used to simplify management, then operational simplicity is improved, but adaptability to varying system conditions is reduced
Solution Approach 1:
The patent incorporates feedback mechanisms that continuously monitor system conditions such as workload, resource availability, and compliance status, then use this information to dynamically adjust re-keying policies. The system automatically receives feedback from the environment and modifies its re-keying behavior accordingly, maintaining both ease of operation through automation and adaptability to changing conditions.
Data Source
AI summary
Techniques for adaptive re-keying of encrypted data are provided. For example, a method comprises the following steps. Utilization information associated with a storage system is obtained, wherein the storage system comprises a set of storage devices. The method dynamically selects a re-keying process from a plurality of different re-keying processes based on at least a portion of the obtained utilization information. At least a portion of the set of storage devices are re-keyed in accordance with the selected re-keying process.


