Controller Key Wrapping in Storage Metadata for Efficient Data Shredding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional storage systems face performance issues due to the complexity and latency associated with shredding encrypted data items, as they require decryption and re-encryption of all data items, which is inefficient for large data sets or frequent deletions.
Innovation Solution
Implementing controller key wrapping of data encryption keys in metadata within storage systems, allowing the input-output controller to read and write data without communicating with the key manager, reducing latency and improving performance through efficient shredding of data items by deleting class keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional shredding process is used (decrypting and re-encrypting all data items), then data security is improved, but system performance and productivity deteriorate
Solution Approach 1:
The patent segments the encryption key management by storing wrapped data encryption keys in metadata of individual data items rather than requiring centralized key manager involvement for each operation. This segmentation allows the input-output controller to independently perform encryption/decryption operations using locally stored controller keys and wrapped data encryption keys, eliminating the performance bottleneck of centralized key management while maintaining security.
Solution Approach 2:
The patent applies preliminary action by pre-wrapping data encryption keys with controller keys and storing them in metadata before actual data operations. This preliminary preparation of cryptographic materials enables the input-output controller to immediately perform encryption and decryption without real-time communication with the key manager, thus maintaining security requirements while dramatically improving operational performance.
2Reliability
If conventional shredding process is used (decrypting and re-encrypting all data items), then data security is improved, but processing time and latency worsen
Solution Approach 1:
By segmenting key storage to the data item level with wrapped data encryption keys in metadata, the system eliminates time-consuming centralized key retrieval operations. The input-output controller can immediately access required cryptographic keys from local metadata, reducing latency while maintaining the security guarantee that keys are properly wrapped and protected.
Solution Approach 2:
The input-output controller performs self-service by independently executing encryption and decryption operations using locally stored controller keys and wrapped data encryption keys from metadata, without requiring time-consuming communication cycles with the external key manager. This self-sufficient operation dramatically reduces processing latency while maintaining security through proper cryptographic key wrapping.
3Productivity
If data encryption keys are stored in metadata with controller key wrapping, then communication overhead is reduced, but device complexity increases
Solution Approach 1:
The controller key serves multiple functions: it encrypts data encryption keys for storage in metadata, enables the input-output controller to independently decrypt data items, and provides authentication for data operations. This multi-functionality reduces the need for separate key management mechanisms and communication protocols, thereby reducing overall system complexity despite the enhanced capabilities.
Solution Approach 2:
The wrapped data encryption key in metadata acts as an intermediary that bridges the controller key and the data encryption key. This intermediary structure allows the input-output controller to operate independently with locally stored cryptographic materials, reducing communication overhead with the key manager while the wrapping mechanism itself provides a clear, standardized interface that manages complexity.
4Productivity
If multidimensional key wrapping is implemented, then shredding efficiency is improved, but key management complexity increases
Solution Approach 1:
The multidimensional key wrapping system segments key management by organizing wrapped data encryption keys according to multiple dimensions (data items, classes, dimensions). This segmentation enables efficient shredding operations where deletion of a class key automatically invalidates all data items in that class without requiring individual data item processing, dramatically improving shredding efficiency while the modular segmented structure helps manage complexity through clear organizational boundaries.
Solution Approach 2:
The patent introduces dimensional organization to key management, allowing keys to be structured and accessed along multiple dimensions (data items, classes, dimensions). This dimensional approach enables efficient bulk operations like class-based shredding where a single key deletion can affect multiple data items across the system, improving productivity while the dimensional framework provides a systematic way to manage the increased complexity through hierarchical organization.
Data Source
AI summary
An apparatus comprises a storage system, a key manager incorporated in or otherwise associated with the storage system, and an input-output controller coupled to the key manager and configured to control storage of data items in the storage system. The key manager is configured to determine a controller key accessible to the input-output controller and a plurality of data encryption keys utilizable by the input-output controller to encrypt the data items for storage in the storage system. A given one of the data items is encrypted using a particular one of the data encryption keys and has associated metadata that includes the particular data encryption key encrypted using the controller key. The metadata may comprise an inner wrapping of the particular data encryption key using the controller key and at least one outer wrapping of the inner wrapping using at least one additional key.

