In-Place Storage Volume Encryption with Background Progress
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for encrypting storage devices are cumbersome and time-consuming, requiring users to wait for extended periods, often up to several hours, which discourages widespread adoption due to the inconvenience of not being able to use the computer during the encryption process.
Innovation Solution
A system that encrypts a storage volume in-place by dividing it into portions, allowing the user to continue using the device while encrypting, using a volume key to encrypt each portion separately, and maintaining encryption progress status, with the ability to resume encryption after power off or restart without data loss.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption methods are used to encrypt an unencrypted storage device, then data security is improved, but the user cannot use the computer for other tasks during the encryption process, resulting in significant loss of time and productivity
Solution Approach 1:
The patent divides the storage device into multiple segments: an encrypted portion and an unencrypted portion. The encryption process encrypts one segment at a time rather than the entire device at once, allowing the system to maintain functionality while progressively securing data. This segmentation enables the encryption operation to proceed in manageable chunks without requiring the entire device to be offline.
Solution Approach 2:
The patent creates a copy of the storage device before encryption begins. This preliminary copying action allows the encryption process to work on the copy while the original remains accessible, enabling users to continue using the computer during encryption. The copy serves as a sandbox for the encryption operation without affecting normal operations.
2Reliability
If traditional encryption methods are used to encrypt an unencrypted storage device, then data security is improved, but the user experience deteriorates due to the inability to use the computer during encryption
Solution Approach 1:
The patent introduces a virtualization layer that acts as an intermediary between the user and the physical storage device. This virtualization layer presents a virtual device to the user while the physical device undergoes encryption in the background. The intermediary absorbs the disruption caused by encryption, allowing users to interact with the virtual device as if nothing is happening, thereby maintaining ease of operation during the security enhancement process.
3Productivity
If the storage device is encrypted portion by portion, then user productivity is maintained, but the device complexity increases due to managing multiple encrypted and unencrypted portions
Solution Approach 1:
The patent creates a virtual copy of the storage device that mirrors the physical device's state. This copying approach simplifies the management of encrypted and unencrypted portions because the virtualization layer can present a unified view to the user while the physical device undergoes complex segmented encryption. The copy absorbs the complexity of managing multiple portions, allowing the physical device to maintain simple, straightforward operations.
Data Source
AI summary
Disclosed herein are systems, methods, and non-transitory computer-readable storage media for performing in-place encryption. A system configured to practice the method receives a request from a user to encrypt an unencrypted volume of a computing device and identifies, generates, and/or randomly selects a volume key. Then the system converts the unencrypted volume to an encryptable format divided into portions. The system then encrypts, based on the volume key, the encryptable volume, portion by portion, to enable the user to use the computing device while encrypting. The system can maintain an encryption progress status and display the encryption progress status. The system can monitor disk accesses to the encryptable volume, and, when the disk accesses exceed a first threshold, apply a back-off algorithm to stop encrypting until the disk accesses fall below a second threshold. Thus, the computing device can be used while the encryption occurs in the background.


