Per-Object Encryption via Container Files in Storage Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Controller-based encryption in data storage systems lacks granularity, encrypting all data on a disk uniformly, which fails to prevent data leakage between different data objects and is not applicable in scenarios without a disk controller, such as flash drives or virtual machines.

Innovation Solution

Implementing object-level encryption by realizing data objects as container files within file systems and encrypting each container file using a unique encryption key, allowing for per-data-object encryption, even when multiple objects are hosted on the same storage device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If controller-based encryption is used to encrypt all data on a disk, then basic protection against unauthorized access is provided, but data leakage between different data objects cannot be prevented and the system is not applicable when no disk controller exists

Engineering Contradiction:
Improvedata protectionVSAvoidencryption granularity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the encryption scope from disk-level to object-level by introducing container files that individually encapsulate different data objects. Each container file can be independently encrypted with its own encryption key, allowing fine-grained control over encryption granularity while maintaining basic security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces container files as intermediary structures between the disk controller and actual data objects. These container files serve as the encryption target instead of encrypting entire disks, enabling per-object encryption while working within existing disk controller architectures and making the system applicable even when traditional disk controllers are absent.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If controller-based encryption encrypts all data on a disk uniformly, then implementation is simple, but different data objects cannot be encrypted differently

Engineering Contradiction:
Improveencryption implementationVSAvoidper-object encryption
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent divides the uniform encryption approach into segmented object-level encryption by creating individual container files for each data object. This allows each object to be encrypted with different parameters while maintaining a standardized container file structure that simplifies the overall implementation process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by allowing different encryption keys and parameters to be applied to different container files (data objects) while maintaining a consistent container file structure. This enables customized encryption for each object without requiring complex system-wide encryption management.

Inventive Principle:
Principle #3Local quality

3Reliability

If per-data-object encryption is implemented by encrypting container files, then data leakage between data objects is prevented, but system complexity increases

Engineering Contradiction:
Improvedata leakage preventionVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by having each container file independently manage its own encryption key and encryption state. The storage system automatically handles the encryption and decryption operations for each container file without requiring complex external key management infrastructure, thus preventing data leakage while limiting the increase in system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10146703B1Encrypting data objects in a data storage system
Publication Date: 2018.12.04 EMC IP HLDG CO LLC
  • US10146703B1 patent drawing
  • US10146703B1 patent drawing
  • US10146703B1 patent drawing

AI summary

Techniques for providing encryption of individual data objects in a data storage system include realizing data objects in the form of container files stored in a set of file systems, and encrypting individual ones of the data objects by encrypting the container files realizing the data objects using encryption keys associated with the individual data objects. By independently encrypting the container files that realize individual data objects, the disclosed system provides per-data object encryption. Each data object may be encrypted differently, e.g. using a different encryption key, even when multiple data objects are hosted over the same storage device or over a shared set of storage devices.