Device-Specific Key Management for Encrypted Storage Volumes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage systems face challenges in providing secure and efficient data processing for shared storage environments, particularly in handling encryption-enabled logical storage devices, where existing solutions hinder data services like compression and deduplication due to lack of key sharing between hosts and storage arrays.
Innovation Solution
Implementing end-to-end encryption techniques within a storage environment using multi-pathing software, such as MPIO drivers, that manage device-specific keys for encryption-enabled logical storage devices, allowing the storage system to process IO operations securely and enable data services like compression and deduplication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end-to-end encryption is implemented in shared storage environments, then data security is improved, but data services like compression and deduplication are hindered due to lack of key sharing
Solution Approach 1:
The encryption key management is segmented by assigning device-specific keys to individual logical storage devices. This allows the storage system to selectively share keys with authorized hosts for specific devices, enabling data services on encrypted data while maintaining security. The key management server divides key access rights by device, allowing fine-grained control over which hosts can access which encrypted data for compression and deduplication operations.
Solution Approach 2:
A key management server is introduced as an intermediary between hosts and encrypted storage devices. This intermediary manages device-specific keys and controls key sharing between hosts and storage arrays. The key management server enables data services by selectively providing keys to authorized hosts, allowing them to decrypt data for compression and deduplication while maintaining end-to-end encryption security.
2Productivity
If encryption keys are shared between hosts and storage arrays, then data services like compression and deduplication are enabled, but data security may be compromised
Solution Approach 1:
Device-specific keys are assigned to individual logical storage devices, creating localized key protection zones. Each encrypted device has its own key that is shared only with authorized hosts for that specific device. This local quality approach allows data services on specific devices without compromising security of other devices, enabling selective key sharing based on device-level granularity.
Solution Approach 2:
The system changes the key management parameter from centralized shared keys to device-specific keys. This parameter change enables controlled key sharing where each device has its own encryption key that can be selectively shared with authorized hosts. The key management server manages these device-specific key parameters, allowing hosts to obtain keys for specific devices they are authorized to access, thereby enabling data services while maintaining security through parameterized key control.
3Adaptability or versatility
If device-specific keys are used for each logical storage device, then key management complexity increases, but selective key sharing for data services becomes possible
Solution Approach 1:
The key management server provides universal key management functionality across multiple logical storage devices. Instead of implementing separate key management systems for each device, a single multi-functional key management server handles device-specific key generation, storage, and distribution for all encrypted devices. This universal approach reduces overall system complexity while enabling selective key sharing across diverse storage devices and hosts.
Data Source
AI summary
An apparatus in one embodiment comprises at least one processing device comprising a processor coupled to a memory. The at least one processing device is configured to receive in a storage system, from a host device, an identifier of an encryption-enabled logical storage device of the storage system, to utilize the identifier to obtain in the storage system a device-specific key from a key management server external to the storage system, and to utilize the obtained device-specific key to process input-output operations directed to the encryption-enabled logical storage device from the host device. The host device in some embodiments comprises at least one virtual machine and the encryption-enabled logical storage device comprises a virtual storage volume of the at least one virtual machine. Metadata associated with the virtual storage volume illustratively comprises an encryption status indicator specifying whether or not encryption is enabled for the virtual storage volume.


