Encryption Device Data Path Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data storage systems fail to ensure secure data transmission over networks to remote cloud devices, often transmitting data unencrypted or experiencing performance degradation when encrypting data prior to transmission.
Innovation Solution
Implementing an encryption device along the data path within the primary data center to encrypt data using an encryption key corresponding to the destination device, ensuring secure transmission without the need for decryption and re-encryption at the remote storage site.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is transmitted unencrypted over the network to remote cloud devices, then transmission speed is maintained, but data security is compromised
Solution Approach 1:
The encryption device performs encryption operations in advance within the primary data center before data leaves the firewall. By pre-encrypting data at the source, the system eliminates the need for decryption and re-encryption at remote storage sites, maintaining transmission speed while ensuring data security during network transit
Solution Approach 2:
An encryption device is introduced as an intermediary component within the primary data center, positioned between the data source and the network boundary. This intermediary handles encryption operations transparently, allowing data to be secured without requiring changes to remote storage systems or impacting transmission throughput
2Reliability
If data is encrypted prior to sending over the network, then data security is improved, but performance degradation occurs
Solution Approach 1:
Encryption is performed as a preliminary action within the primary data center infrastructure, utilizing available encryption keys and algorithms before data enters the network transmission pipeline. This approach secures data without requiring post-transmission processing at remote sites
Solution Approach 2:
The encryption device operates autonomously within the primary data center, managing its own encryption key retrieval and data processing without requiring intervention from remote storage systems. This self-contained approach eliminates redundant decryption and re-encryption operations that would degrade performance
3Reliability
If data is decrypted and re-encrypted at remote storage systems, then data security is maintained, but transmission efficiency decreases
Solution Approach 1:
The system performs the encryption action in advance at the primary data center, eliminating the need for subsequent decryption and re-encryption operations at remote storage systems. This single encryption step at the source maintains security while reducing total processing time
Solution Approach 2:
The encryption function is extracted from the remote storage system and relocated to the primary data center. By removing the decryption and re-encryption requirements from remote sites, the system eliminates redundant processing steps that would increase transmission time
Data Source
AI summary
Implementations described and claimed herein provide encryption in the data path. In one implementation, login parameters from a primary data center are obtained. The login parameters include an identification of a destination device. An encryption key corresponding to the destination device is received. A write command including data for writing to the destination device is received from the primary data center. The data is encrypted inside a firewall of the primary data center using the encryption key. The encrypted data is routed over a data path to the destination device. As such, the data is secure during transmission over the network to the destination device.


