Adaptive Re-keying Engine for Storage Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data at rest encryption systems face inefficiencies in re-keying processes due to static re-key policies, which can lead to prolonged computation times and significant resource usage, failing to optimally manage storage system resources and maintain cryptographic key compliance.

Innovation Solution

An adaptive re-keying process that dynamically selects the optimal re-keying procedure based on utilization information, utilizing a re-keying engine to prioritize and schedule re-keying operations, minimizing system impact and ensuring compliance by dynamically calculating re-key timing and resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If re-keying is performed frequently to maintain cryptographic compliance, then security compliance is improved, but system computation resources and time are excessively consumed

Engineering Contradiction:
Improvecryptographic key complianceVSAvoidsystem computation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic re-keying policies that adjust re-keying frequency and timing based on current system conditions including workload, available resources, and compliance requirements. The system transitions from static predetermined re-keying schedules to adaptive policies that can be modified in real-time to balance security compliance with system performance and resource utilization.

Inventive Principle:
Principle #15Dynamics

2Reliability

If re-keying is performed on large data volumes, then cryptographic compliance is maintained, but computation time is significantly prolonged

Engineering Contradiction:
Improvecryptographic key complianceVSAvoidre-keying computation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments large data volumes into smaller partitions or chunks that can be re-keyed independently and in parallel. This division allows the re-keying process to be distributed across multiple processing units or time slots, reducing the overall computation time while maintaining compliance with cryptographic key rotation requirements for the entire data set.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If static re-key policies are used to simplify management, then operational simplicity is improved, but adaptability to varying system conditions is reduced

Engineering Contradiction:
Improvere-key policy managementVSAvoidresponse to system utilization conditions
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent incorporates feedback mechanisms that continuously monitor system conditions such as workload, resource availability, and compliance status, then use this information to dynamically adjust re-keying policies. The system automatically receives feedback from the environment and modifies its re-keying behavior accordingly, maintaining both ease of operation through automation and adaptability to changing conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11595204B2Adaptive re-keying in a storage system
Publication Date: 2023.02.28 EMC IP HLDG CO LLC
  • US11595204B2 patent drawing
  • US11595204B2 patent drawing
  • US11595204B2 patent drawing

AI summary

Techniques for adaptive re-keying of encrypted data are provided. For example, a method comprises the following steps. Utilization information associated with a storage system is obtained, wherein the storage system comprises a set of storage devices. The method dynamically selects a re-keying process from a plurality of different re-keying processes based on at least a portion of the obtained utilization information. At least a portion of the set of storage devices are re-keyed in accordance with the selected re-keying process.