Remote Replication Host Encryption Key Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage systems face challenges in maintaining encrypted data security during failover scenarios, as decrypting data before replication can consume significant resources and expose data to unauthorized access.
Innovation Solution
A mechanism where a first storage system requests and receives a decryption key from a second storage system, ensuring that the data remains encrypted during replication and failover, with authorization determined through manual configuration or heuristic rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is decrypted prior to transferring from primary storage system to failover storage system, then data can be accessed at the failover system, but data security is compromised and processing resources are significantly consumed
Solution Approach 1:
The patent extracts the decryption key from the primary storage system and transfers it to the failover storage system. This allows the failover system to decrypt data independently without exposing plaintext data during transmission, resolving the contradiction between failover capability and data security
Solution Approach 2:
The patent introduces an encryption key as an intermediary element that enables data access without exposing the actual data. By transferring keys rather than decrypted data, the system achieves failover capability while maintaining security through this intermediary mechanism
2Reliability
If data is decrypted prior to transmission, then data can be transferred to failover storage system, but the decryption process consumes significant processing resources
Solution Approach 1:
The patent extracts only the essential decryption key from the primary system and transfers it to the failover system, avoiding the need to decrypt and re-encrypt large volumes of data. This dramatically reduces processing resource consumption while maintaining failover capability
3Reliability
If decryption keys are made generally available to applications in the system, then failover systems can access encrypted data, but encrypted data becomes vulnerable to unauthorized access
Solution Approach 1:
The patent applies local quality by providing decryption keys selectively to specific authorized systems (primary and failover storage systems) rather than making keys generally available to all applications. This localized key distribution maintains data accessibility for authorized systems while preventing unauthorized access
Data Source
AI summary
Decrypting data at a first storage system that has been encrypted at a second, separate, storage system includes the first storage system requesting a key that decrypts the data from the second storage system, the second storage system determining if the first storage system is authorized for the key, the second storage system providing the key to the first storage system in response to the first storage system being authorized, a host that is coupled to the first storage system obtaining the key from the first storage system, and the host using the key to decrypt and access the data at the first storage system. The host and the first storage system may provide failover functionality for a system that includes the second storage system. The host may obtain the key from the first storage system in response to a failure of the system that includes the second storage system.


