Intermediary Transform Fleet for Multi-Volume Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing systems face challenges in encrypting data volumes created from unencrypted snapshots, particularly in compliance with changing data protection regulations, as they often require dedicated encryption resources for each new volume, which is inefficient and burdensome.
Innovation Solution
The implementation of intermediary resources, such as a source volume and a transform fleet, that perform encryption using multiple encryption keys, allowing for the creation of encrypted volumes while minimizing exposure of encryption information and isolating encryption contexts from the primary data storage, enabling default encryption for multiple volumes without additional user burden.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated encryption resources are created for each new volume from unencrypted snapshots, then data security and compliance with protection regulations are improved, but device complexity and operational burden increase
Solution Approach 1:
The patent implements a single encryption service resource that can service multiple volume creation requests simultaneously. This encryption service acts as a universal resource that handles encryption for different volumes using different encryption contexts and keys, eliminating the need for dedicated encryption resources for each volume while maintaining security requirements.
Solution Approach 2:
The patent introduces an encryption service as an intermediary component between the snapshot source and the target volumes. This intermediary handles all encryption operations, managing encryption contexts and keys centrally, thereby reducing the complexity burden from users while ensuring data security through controlled access to encryption resources.
2Productivity
If multiple volumes are encrypted in parallel using a shared encryption service, then productivity and efficiency are improved, but ensuring proper isolation of encryption contexts becomes more difficult
Solution Approach 1:
The patent segments encryption contexts into distinct, isolated units that are associated with specific volumes. Each encryption context contains the necessary keys and parameters for encrypting a particular volume, and the system ensures that these segmented contexts remain isolated even when processed in parallel by the shared encryption service, maintaining both productivity and security.
Solution Approach 2:
The patent applies local quality by ensuring that each volume receives the specific encryption context and keys appropriate for its security requirements. The encryption service dynamically assigns the correct encryption context to each volume creation request, allowing parallel processing while maintaining proper isolation through context-specific encryption parameters.
3Ease of operation
If encryption is performed on the primary data storage resources, then ease of operation is improved, but system performance and resource availability deteriorate
Solution Approach 1:
The patent extracts the encryption function from the primary data storage resources and places it in a dedicated encryption service. This separation allows the primary storage resources to focus on data operations while the encryption service handles security transformations, improving overall system performance while maintaining ease of operation through automated encryption management.
Solution Approach 2:
The encryption service acts as an intermediary that handles all encryption operations externally to the primary storage system. This intermediary approach allows storage resources to remain available for data operations while the encryption service processes encryption requests, thereby maintaining system performance and providing transparent encryption to users.
Data Source
AI summary
Generally described, one or more aspects of the present application correspond to techniques for creating multiple encrypted block store volumes of data from an unencrypted source. These encryption techniques can use a transform fleet as an intermediary use between the unencrypted source and the encrypted volumes. The transform fleet can obtain data of the volume from one or both of two sources—an object storage “snapshot” a block storage “source volume”—and can then apply the appropriate encryption key for performing the encryption of a particular volume.


