Per-Object Encryption via Container Files in Storage Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Controller-based encryption in data storage systems lacks granularity, encrypting all data on a disk uniformly, which fails to prevent data leakage between different data objects and is not applicable in scenarios without a disk controller, such as flash drives or virtual machines.
Innovation Solution
Implementing object-level encryption by realizing data objects as container files within file systems and encrypting each container file using a unique encryption key, allowing for per-data-object encryption, even when multiple objects are hosted on the same storage device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If controller-based encryption is used to encrypt all data on a disk, then basic protection against unauthorized access is provided, but data leakage between different data objects cannot be prevented and the system is not applicable when no disk controller exists
Solution Approach 1:
The patent segments the encryption scope from disk-level to object-level by introducing container files that individually encapsulate different data objects. Each container file can be independently encrypted with its own encryption key, allowing fine-grained control over encryption granularity while maintaining basic security protection.
Solution Approach 2:
The patent introduces container files as intermediary structures between the disk controller and actual data objects. These container files serve as the encryption target instead of encrypting entire disks, enabling per-object encryption while working within existing disk controller architectures and making the system applicable even when traditional disk controllers are absent.
2Ease of manufacture
If controller-based encryption encrypts all data on a disk uniformly, then implementation is simple, but different data objects cannot be encrypted differently
Solution Approach 1:
The patent divides the uniform encryption approach into segmented object-level encryption by creating individual container files for each data object. This allows each object to be encrypted with different parameters while maintaining a standardized container file structure that simplifies the overall implementation process.
Solution Approach 2:
The patent applies local quality by allowing different encryption keys and parameters to be applied to different container files (data objects) while maintaining a consistent container file structure. This enables customized encryption for each object without requiring complex system-wide encryption management.
3Reliability
If per-data-object encryption is implemented by encrypting container files, then data leakage between data objects is prevented, but system complexity increases
Solution Approach 1:
The patent implements self-service by having each container file independently manage its own encryption key and encryption state. The storage system automatically handles the encryption and decryption operations for each container file without requiring complex external key management infrastructure, thus preventing data leakage while limiting the increase in system complexity.
Data Source
AI summary
Techniques for providing encryption of individual data objects in a data storage system include realizing data objects in the form of container files stored in a set of file systems, and encrypting individual ones of the data objects by encrypting the container files realizing the data objects using encryption keys associated with the individual data objects. By independently encrypting the container files that realize individual data objects, the disclosed system provides per-data object encryption. Each data object may be encrypted differently, e.g. using a different encryption key, even when multiple data objects are hosted over the same storage device or over a shared set of storage devices.


