Storage Encryption Key Management via Centralized Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional storage systems face inefficiencies in data management and encryption key protection due to redundant operations and lack of centralized control, leading to reliability issues and increased latency.
Innovation Solution
Implementing a storage system with dual storage array controllers that offload device management responsibilities, utilizing non-volatile random access memory (NVRAM) for quick data buffering, and employing erasure coding and mirroring schemes to ensure data redundancy and protection, while allowing the operating system to initiate and control processes directly on flash storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional storage systems perform redundant encryption key management operations, then data security is maintained, but system latency increases and efficiency decreases
Solution Approach 1:
The patent extracts the encryption key management functionality from individual storage devices and consolidates it into a dedicated key management service. This separation allows encryption operations to be performed centrally rather than redundantly on each device, reducing latency while maintaining security through specialized key handling.
Solution Approach 2:
The key management service provides universal encryption key management across multiple storage devices and controllers. Instead of each device implementing its own encryption logic, a single multi-functional service handles key generation, distribution, and management for the entire storage system, improving efficiency without compromising security.
2Reliability
If storage systems implement distributed key management across multiple devices, then redundancy is improved, but control complexity increases
Solution Approach 1:
The patent introduces a key management service as an intermediary between storage controllers and encryption keys. This mediator handles all key-related operations centrally, providing redundancy through service replication while simplifying control by abstracting complex key management logic from individual storage devices and presenting a unified interface to controllers.
3Measurement precision
If storage controllers manage all device operations directly, then control precision is maintained, but processing overhead increases
Solution Approach 1:
The patent segments storage controller functionality into two parts: data management operations remain with storage controllers for precise control, while encryption key management operations are separated and handled by a dedicated key management service. This segmentation reduces processing overhead on controllers by offloading cryptographic operations without sacrificing control precision over data operations.
Data Source
AI summary
Protecting an encryption key for data stored in a storage system that includes a plurality of storage devices, including: reading, from at least a majority of the storage devices, a portion of an apartment key; reconstructing the apartment key using the portions of the apartment key read by the majority of the storage devices; unlocking the main portion of each of the storage devices utilizing the apartment key; reading, from the main portion of one of the storage devices, a portion of a third-party resource access key; requesting, from the third-party resource utilizing the third-party resource access key, an encryption key; receiving, from the third-party resource, the encryption key; and decrypting the data stored on the storage devices utilizing the encryption key.


