Key Management Server Tracking Replica Data Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems face challenges in managing encryption keys effectively, leading to issues with data integrity, availability, and reliability, particularly in scenarios involving replication and catastrophic failures, where improper key usage or loss can result in data unavailability and corruption.
Innovation Solution
A method and system for managing source and replica data in a storage area network using a key management server that assigns and records data encryption keys, maintains associations between source and replica objects, and employs redundancy codes to ensure key integrity and availability, allowing for recovery from failures and proper key usage verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If data is stored in encrypted form to protect against theft and inadvertent disclosure, then data security is improved, but data availability and reliability deteriorate due to key loss or improper key usage
Solution Approach 1:
The system performs preliminary actions by creating redundancy codes (such as HMACs) for encryption keys and storing them in association with the encrypted data before any potential key loss occurs. This allows the system to recover from key corruption or loss without compromising data security, as the redundancy codes enable verification and recovery of the original encryption keys.
Solution Approach 2:
The patent introduces redundancy codes as an intermediary mechanism between the encryption keys and the encrypted data. These codes serve as a mediator that enables verification of key integrity and facilitates key recovery without directly exposing the encryption keys, thus maintaining security while improving availability.
2Object-affected harmful factors
If encryption is applied to stored data to protect sensitivity, then data protection is improved, but data processing resources and complexity increase
Solution Approach 1:
The system segments the protection mechanism into two parts: the primary encryption (AES) and the redundancy verification (HMAC). This segmentation allows the main encryption algorithm to focus on security while the redundancy code handles verification and recovery, distributing the computational burden and simplifying the overall process.
Solution Approach 2:
The patent changes the parameter of verification from re-encrypting data (computationally expensive) to verifying redundancy codes (computationally efficient). This parameter change maintains data protection while significantly reducing the processing resources required for verification operations.
3Object-affected harmful factors
If standard encryption modes like CBC or XTS are used, then encryption effectiveness is improved, but key management complexity and risk of improper key usage increase
Solution Approach 1:
The system implements feedback by creating redundancy codes that provide information about the integrity of encryption keys. This feedback mechanism allows the system to detect key corruption or improper usage and trigger appropriate recovery procedures, simplifying key management by automating verification and recovery rather than relying on manual processes.
Solution Approach 2:
The patent enables the encryption system to serve itself by automatically verifying key integrity through redundancy codes and performing self-recovery when key corruption is detected. This self-service capability reduces the complexity of external key management interventions and allows the system to maintain its own security and reliability.
4Reliability
If redundancy codes are created and stored with encrypted data to verify integrity, then data reliability is improved, but storage space and processing overhead increase
Solution Approach 1:
The system applies partial action by creating redundancy codes only for the encryption keys rather than for the entire encrypted data set. This approach provides sufficient reliability for the critical key management function without the excessive storage overhead of redundant verification data for all stored information.
Data Source
AI summary
Source and replica data in a storage area network is tracked during management of data encryption keys. Association of source and replica data allows for all copies of customer information in an enterprise to be managed as a single entity for deletion or tracked for management purposes by using referenced data encryption keys upon creation of replicas. Any replica from a source storage object can be created using the source storage object data encryption key or an associated key and tracked by these keys as a subset of the number of replicas created. Management of the data encryption keys can control the lifetime of data on a storage array and in the storage area network without managing every replicated instance for the lifetime of the data.


