In-flight Data Encryption for Distributed Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data privacy is compromised during transmission to and from storage platforms, as existing 'data-at rest' encryption techniques do not address eavesdropping risks over wide-area networks, and there is a need for scalable and transparent key management solutions.
Innovation Solution
Encrypting data before transmission to a storage platform and decrypting it only upon arrival, with the option for de-duplication and using a controller virtual machine to manage encryption and decryption processes, allowing compatibility with various key management services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data-at rest encryption is used on the storage platform, then data security during storage is improved, but data security during transmission over wide-area networks remains vulnerable to eavesdropping
Solution Approach 1:
The patent applies preliminary action by encrypting data at the source (virtual machine or controller virtual machine) before it leaves the enterprise network, rather than waiting until data reaches the storage platform. This proactive encryption ensures data is protected during transmission over wide-area networks, preventing eavesdropping risks that would exist with only data-at-rest encryption.
2Reliability
If data is encrypted at the virtual disk level before leaving the controller virtual machine, then data security over the network is improved, but the complexity of key management increases
Solution Approach 1:
The patent introduces an intermediary key management service that acts as a mediator between the encryption/decryption processes and the actual cryptographic keys. This service handles key generation, distribution, storage, and rotation transparently, reducing the complexity burden on the virtual machines and storage platform while maintaining strong encryption security.
3Reliability
If encryption and decryption processes are implemented in the storage system, then data security is improved, but compatibility with various key management services and de-duplication services may be compromised
Solution Approach 1:
The patent implements universality by designing an encryption framework that can work with multiple different key management services and coexist with other storage services like de-duplication. The modular architecture allows the same encryption infrastructure to adapt to various key management implementations and service combinations, maintaining both security and compatibility.
Data Source
AI summary
Encryption of data occurs before it is written to the storage platform; decryption occurs after it is read from the storage platform on a computer separate from the storage platform. By encrypting data before it travels over a wide-area network to a storage platform (and by only decrypting that data once it has arrived at an enterprise from the storage platform), we address data security over the network. Application data is encrypted at the virtual disk level before it leaves a controller virtual machine, and is only decrypted at that controller virtual machine after being received from the storage platform. Encryption and decryption of data is compatible with other services of the storage system such as de-duplication. Any number of key management services can be used in a transparent manner.


