In-flight Data Encryption for Distributed Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data privacy is compromised during transmission to and from storage platforms, as existing 'data-at rest' encryption techniques do not address eavesdropping risks over wide-area networks, and there is a need for scalable and transparent key management solutions.

Innovation Solution

Encrypting data before transmission to a storage platform and decrypting it only upon arrival, with the option for de-duplication and using a controller virtual machine to manage encryption and decryption processes, allowing compatibility with various key management services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data-at rest encryption is used on the storage platform, then data security during storage is improved, but data security during transmission over wide-area networks remains vulnerable to eavesdropping

Engineering Contradiction:
Improvedata securityVSAvoideavesdropping risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by encrypting data at the source (virtual machine or controller virtual machine) before it leaves the enterprise network, rather than waiting until data reaches the storage platform. This proactive encryption ensures data is protected during transmission over wide-area networks, preventing eavesdropping risks that would exist with only data-at-rest encryption.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If data is encrypted at the virtual disk level before leaving the controller virtual machine, then data security over the network is improved, but the complexity of key management increases

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary key management service that acts as a mediator between the encryption/decryption processes and the actual cryptographic keys. This service handles key generation, distribution, storage, and rotation transparently, reducing the complexity burden on the virtual machines and storage platform while maintaining strong encryption security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption and decryption processes are implemented in the storage system, then data security is improved, but compatibility with various key management services and de-duplication services may be compromised

Engineering Contradiction:
Improvedata securityVSAvoidservice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by designing an encryption framework that can work with multiple different key management services and coexist with other storage services like de-duplication. The modular architecture allows the same encryption infrastructure to adapt to various key management implementations and service combinations, maintaining both security and compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11916886B2In-flight data encryption/decryption for a distributed storage platform
Publication Date: 2024.02.27 COMMVAULT SYSTEMS INC
  • US11916886B2 patent drawing
  • US11916886B2 patent drawing
  • US11916886B2 patent drawing

AI summary

Encryption of data occurs before it is written to the storage platform; decryption occurs after it is read from the storage platform on a computer separate from the storage platform. By encrypting data before it travels over a wide-area network to a storage platform (and by only decrypting that data once it has arrived at an enterprise from the storage platform), we address data security over the network. Application data is encrypted at the virtual disk level before it leaves a controller virtual machine, and is only decrypted at that controller virtual machine after being received from the storage platform. Encryption and decryption of data is compatible with other services of the storage system such as de-duplication. Any number of key management services can be used in a transparent manner.