Storage Encryption Key Management via Centralized Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional storage systems face inefficiencies in data management and encryption key protection due to redundant operations and lack of centralized control, leading to reliability issues and increased latency.

Innovation Solution

Implementing a storage system with dual storage array controllers that offload device management responsibilities, utilizing non-volatile random access memory (NVRAM) for quick data buffering, and employing erasure coding and mirroring schemes to ensure data redundancy and protection, while allowing the operating system to initiate and control processes directly on flash storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional storage systems perform redundant encryption key management operations, then data security is maintained, but system latency increases and efficiency decreases

Engineering Contradiction:
Improvedata securityVSAvoidsystem latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the encryption key management functionality from individual storage devices and consolidates it into a dedicated key management service. This separation allows encryption operations to be performed centrally rather than redundantly on each device, reducing latency while maintaining security through specialized key handling.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The key management service provides universal encryption key management across multiple storage devices and controllers. Instead of each device implementing its own encryption logic, a single multi-functional service handles key generation, distribution, and management for the entire storage system, improving efficiency without compromising security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If storage systems implement distributed key management across multiple devices, then redundancy is improved, but control complexity increases

Engineering Contradiction:
Improvekey management redundancyVSAvoidcontrol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key management service as an intermediary between storage controllers and encryption keys. This mediator handles all key-related operations centrally, providing redundancy through service replication while simplifying control by abstracting complex key management logic from individual storage devices and presenting a unified interface to controllers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If storage controllers manage all device operations directly, then control precision is maintained, but processing overhead increases

Engineering Contradiction:
Improvecontrol precisionVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments storage controller functionality into two parts: data management operations remain with storage controllers for precise control, while encryption key management operations are separated and handled by a dedicated key management service. This segmentation reduces processing overhead on controllers by offloading cryptographic operations without sacrificing control precision over data operations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240413985A1Optimized Encryption Key Management By A Group Of Storage Systems
Publication Date: 2024.12.12 PURE STORAGE INC
  • US20240413985A1 patent drawing
  • US20240413985A1 patent drawing
  • US20240413985A1 patent drawing

AI summary

Protecting an encryption key for data stored in a storage system that includes a plurality of storage devices, including: reading, from at least a majority of the storage devices, a portion of an apartment key; reconstructing the apartment key using the portions of the apartment key read by the majority of the storage devices; unlocking the main portion of each of the storage devices utilizing the apartment key; reading, from the main portion of one of the storage devices, a portion of a third-party resource access key; requesting, from the third-party resource utilizing the third-party resource access key, an encryption key; receiving, from the third-party resource, the encryption key; and decrypting the data stored on the storage devices utilizing the encryption key.