Remote Replication Host Encryption Key Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage systems face challenges in maintaining encrypted data security during failover scenarios, as decrypting data before replication can consume significant resources and expose data to unauthorized access.

Innovation Solution

A mechanism where a first storage system requests and receives a decryption key from a second storage system, ensuring that the data remains encrypted during replication and failover, with authorization determined through manual configuration or heuristic rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is decrypted prior to transferring from primary storage system to failover storage system, then data can be accessed at the failover system, but data security is compromised and processing resources are significantly consumed

Engineering Contradiction:
Improvefailover capabilityVSAvoiddata security vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the decryption key from the primary storage system and transfers it to the failover storage system. This allows the failover system to decrypt data independently without exposing plaintext data during transmission, resolving the contradiction between failover capability and data security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an encryption key as an intermediary element that enables data access without exposing the actual data. By transferring keys rather than decrypted data, the system achieves failover capability while maintaining security through this intermediary mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is decrypted prior to transmission, then data can be transferred to failover storage system, but the decryption process consumes significant processing resources

Engineering Contradiction:
Improvefailover capabilityVSAvoidprocessing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential decryption key from the primary system and transfers it to the failover system, avoiding the need to decrypt and re-encrypt large volumes of data. This dramatically reduces processing resource consumption while maintaining failover capability

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If decryption keys are made generally available to applications in the system, then failover systems can access encrypted data, but encrypted data becomes vulnerable to unauthorized access

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by providing decryption keys selectively to specific authorized systems (primary and failover storage systems) rather than making keys generally available to all applications. This localized key distribution maintains data accessibility for authorized systems while preventing unauthorized access

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12212656B2Remote replication with host encryption
Publication Date: 2025.01.28 EMC IP HLDG CO LLC
  • US12212656B2 patent drawing
  • US12212656B2 patent drawing
  • US12212656B2 patent drawing

AI summary

Decrypting data at a first storage system that has been encrypted at a second, separate, storage system includes the first storage system requesting a key that decrypts the data from the second storage system, the second storage system determining if the first storage system is authorized for the key, the second storage system providing the key to the first storage system in response to the first storage system being authorized, a host that is coupled to the first storage system obtaining the key from the first storage system, and the host using the key to decrypt and access the data at the first storage system. The host and the first storage system may provide failover functionality for a system that includes the second storage system. The host may obtain the key from the first storage system in response to a failure of the system that includes the second storage system.