Storage System Encryption Key Management via Cache Pinning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems face challenges in securely managing system-wide encryption keys, leading to risks of data compromise due to key loss or corruption, especially when dealing with large amounts of data and complex encryption management across enterprise infrastructure.

Innovation Solution

The system initializes and upgrades data encryption using a system-wide encryption key, employing cache memory to ensure reliable encryption and decryption processes, pinning and unpinning data slices in RAID groups to maintain data integrity during write operations, and utilizing a Key Manager for secure key lifecycle management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption technologies and appliances are deployed to secure data-at-rest, then data security is improved, but device complexity and management complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple encryption functions and key management capabilities into a single integrated storage system. The storage appliance includes both encryption engines and a key manager component, eliminating the need for separate encryption appliances and reducing management complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The storage system is designed to perform multiple functions including data storage, encryption, decryption, and key management within a single platform. This multi-functional approach eliminates the need for separate point solutions and reduces overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple encryption technologies and key managers are deployed to enhance security, then data protection is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The key manager automatically performs key generation, distribution, rotation, and revocation without requiring manual intervention. The system self-manages the entire key lifecycle, reducing operational burden while maintaining strong security controls.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The key manager acts as an intermediary between storage operations and encryption keys, abstracting away the complexity of key management from users and applications. This mediator handles all key-related operations transparently, simplifying the user experience.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If data encryption is implemented across the enterprise infrastructure, then security is improved, but scalability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The encryption system is divided into modular components including multiple encryption engines and a centralized key manager. This segmentation allows the system to scale horizontally by adding more encryption engines while maintaining centralized key management control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical key management structure with different key levels (data encryption keys, key encryption keys, master keys) that can be deployed at different organizational levels. This dimensional approach enables scalable deployment from single-site to enterprise-wide configurations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If encryption technologies are installed to protect data-at-rest, then security is improved, but service levels deteriorate due to network outages and reconfiguration

Engineering Contradiction:
ImprovesecurityVSAvoidservice levels
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Encryption is enabled and configured in advance during system initialization or maintenance windows. Once configured, the encryption functionality operates transparently without requiring network outages or reconfigurations during normal data operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces physical encryption appliances and hardware-based key management with software-based encryption engines and virtual key manager components. This substitution eliminates the need for physical reconfiguration and network outages, allowing encryption to be enabled and modified without service disruption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9910791B1Managing system-wide encryption keys for data storage systems
Publication Date: 2018.03.06 EMC IP HLDG CO LLC
  • US9910791B1 patent drawing
  • US9910791B1 patent drawing
  • US9910791B1 patent drawing

AI summary

The techniques presented herein provide for initializing and upgrading data encryption capability in a data storage system. The data storage system in initialized to encrypt data writes using a system wide encryption key. A request is received to upgrade the encryption functionality in the data storage system. A data slice is identified for encryption, wherein the data slice is stored in a RAID group in the data storage system. The data slice is pinned in a first cache memory of a first storage processor and persisted in a second cache memory of a second storage processor. The data slice encrypted and a write operation is initiated to write the encrypted data slice back to the RAID group. If the write operation was successful, the data slice is unpinned the first and second cache memory associated with the data slice is freed, else if the write operation was unsuccessful, the data slice is unpinned and the first and second cache memory associated with the data slice are flushed.