Proactive Copy Service Rekeying Storage Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Some data storage systems lack the capability to provide data-at-rest rekeying due to hardware limitations, posing a security risk when encryption keys are used for an extended period.

Innovation Solution

Implementing a proactive copy service that identifies a source storage device and transfers its encrypted data to spare devices using different encryption keys, effectively rekeying the information while maintaining data security, even when the source device is deemed healthy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored using a single encryption key for an extended period, then storage system simplicity is maintained, but data security deteriorates due to increased security risks from prolonged key usage

Engineering Contradiction:
Improvedata securityVSAvoidstorage system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system proactively identifies storage devices that are approaching end-of-life status and triggers a copy operation before actual failure occurs. This preliminary action allows rekeying to be performed during planned maintenance windows rather than in response to failures, maintaining security while managing complexity through controlled, scheduled operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention uses the existing proactive copy mechanism to create a copy of data from the source device to a destination device. During this copy operation, the data is rekeyed using a new encryption key on the destination device. This leverages an existing system capability to achieve rekeying without requiring a completely new complex system

Inventive Principle:
Principle #26Copying

2Reliability

If a proactive copy operation is performed to rekey data, then data security is improved through key rotation, but system performance deteriorates due to the additional data transfer and processing overhead

Engineering Contradiction:
Improvedata securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The proactive copy service is enhanced to perform dual functions: traditional data protection copying and encryption key rotation. By making the copy service universal, the system achieves rekeying without requiring a separate dedicated rekeying infrastructure, thus minimizing additional performance impact while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs rekeying on a per-device basis rather than across the entire storage system simultaneously. This partial action approach allows other storage devices to continue normal operations, limiting performance degradation to only the specific devices undergoing rekeying while maintaining overall system productivity

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If hardware limitations prevent native rekeying capability, then device simplicity is maintained, but adaptability deteriorates as the system cannot support data-at-rest rekeying

Engineering Contradiction:
Improverekeying capabilityVSAvoidhardware requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The control circuitry acts as an intermediary between the storage devices and the encryption key management system. It intercepts proactive copy operations and modifies them to include rekeying functionality, effectively adding adaptability through software-based mediation without requiring complex hardware modifications to the storage devices themselves

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The invention replaces hardware-based rekeying capabilities with a software-based solution implemented through the control circuitry. Instead of requiring specialized hardware components for rekeying, the system uses firmware or software to intercept and modify copy operations, achieving rekeying capability through logical processing rather than physical hardware

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11163459B2Rekeying information on storage devices using a proactive copy service
Publication Date: 2021.11.02 EMC IP HLDG CO LLC
  • US11163459B2 patent drawing
  • US11163459B2 patent drawing
  • US11163459B2 patent drawing

AI summary

A technique rekeys information to maintain data security. The technique involves identifying a first storage drive as a source device available to a proactive copy service. The technique further involves identifying a set of second storage drives as a set of spare devices available to the proactive copy service. The technique further involves invoking the proactive copy service which, in response to being invoked, transfers information from the first storage drive to the set of second storage drives. The information is encrypted by a first key when residing on the first storage drive and is encrypted by a set of second keys when residing on the set of second storage drives, the first key being different from each second key.