Host-Based Rekeying for Secure Storage Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure storage systems face performance slowdowns and inflexibility due to the high workload of managing encryption keys and re-keying operations, which are typically handled by security appliances.

Innovation Solution

Shifting the tasks of managing key policies and initiating re-keying operations from security appliances to clients or hosts, allowing the security appliance to focus on key generation, encryption, and decryption while the host handles re-keying and key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the security appliance performs all encryption key management and re-keying operations, then security is maintained, but system performance slows down due to high workload

Engineering Contradiction:
ImprovesecurityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the key management workload into segments: the security appliance handles key generation and encryption/decryption operations, while the host system handles re-keying operations. This segmentation allows each component to specialize in specific tasks, improving overall system performance while maintaining security through distributed responsibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the re-keying operation from the security appliance and relocates it to the host system. This extraction reduces the workload on the security appliance, preventing performance degradation while maintaining security through the appliance's continued control over key generation and encryption operations.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the security appliance manages all key policies and re-keying operations, then security control is centralized, but the system becomes inflexible

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments key management responsibilities between the security appliance and host system. The appliance maintains centralized control over key generation and security policies, while the host system gains flexibility in executing re-keying operations based on local conditions and requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic key management where the host system can initiate re-keying operations based on changing security requirements or conditions. This dynamic approach allows the system to adapt to different security scenarios while maintaining the appliance's centralized security control through key generation and encryption management.

Inventive Principle:
Principle #15Dynamics

3Reliability

If re-keying operations are performed frequently to maintain security, then data security is improved, but system resources are consumed

Engineering Contradiction:
Improvedata securityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts re-keying operations from the security appliance and assigns them to the host system. This reduces the energy and resource consumption of the security appliance while maintaining data security through continued frequent re-keying operations, as the host system performs these operations using its own resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The host system performs re-keying operations autonomously based on security policies and conditions, managing its own key rotation needs without burdening the security appliance. This self-service approach allows frequent re-keying for security while the host system manages its own resource consumption for these operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9774445B1Host based rekeying
Publication Date: 2017.09.26 NETAPP INC
  • US9774445B1 patent drawing
  • US9774445B1 patent drawing
  • US9774445B1 patent drawing

AI summary

A system and method for re-keying ciphertext on a storage system is resident on a host/client communicating with a storage system. The generation of encryption keys and tracking which storage system blocks are encrypted with what keys remain with the security appliance or storage system, but the policy governing re-keying and initiating actions in accordance with that policy reside with the client/host.