Intermediary Transform Fleet for Multi-Volume Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing systems face challenges in encrypting data volumes created from unencrypted snapshots, particularly in compliance with changing data protection regulations, as they often require dedicated encryption resources for each new volume, which is inefficient and burdensome.

Innovation Solution

The implementation of intermediary resources, such as a source volume and a transform fleet, that perform encryption using multiple encryption keys, allowing for the creation of encrypted volumes while minimizing exposure of encryption information and isolating encryption contexts from the primary data storage, enabling default encryption for multiple volumes without additional user burden.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated encryption resources are created for each new volume from unencrypted snapshots, then data security and compliance with protection regulations are improved, but device complexity and operational burden increase

Engineering Contradiction:
Improvedata securityVSAvoidencryption resource management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a single encryption service resource that can service multiple volume creation requests simultaneously. This encryption service acts as a universal resource that handles encryption for different volumes using different encryption contexts and keys, eliminating the need for dedicated encryption resources for each volume while maintaining security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an encryption service as an intermediary component between the snapshot source and the target volumes. This intermediary handles all encryption operations, managing encryption contexts and keys centrally, thereby reducing the complexity burden from users while ensuring data security through controlled access to encryption resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple volumes are encrypted in parallel using a shared encryption service, then productivity and efficiency are improved, but ensuring proper isolation of encryption contexts becomes more difficult

Engineering Contradiction:
Improvevolume creation speedVSAvoidencryption context isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments encryption contexts into distinct, isolated units that are associated with specific volumes. Each encryption context contains the necessary keys and parameters for encrypting a particular volume, and the system ensures that these segmented contexts remain isolated even when processed in parallel by the shared encryption service, maintaining both productivity and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by ensuring that each volume receives the specific encryption context and keys appropriate for its security requirements. The encryption service dynamically assigns the correct encryption context to each volume creation request, allowing parallel processing while maintaining proper isolation through context-specific encryption parameters.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If encryption is performed on the primary data storage resources, then ease of operation is improved, but system performance and resource availability deteriorate

Engineering Contradiction:
Improveencryption transparencyVSAvoidsystem performance
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent extracts the encryption function from the primary data storage resources and places it in a dedicated encryption service. This separation allows the primary storage resources to focus on data operations while the encryption service handles security transformations, improving overall system performance while maintaining ease of operation through automated encryption management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The encryption service acts as an intermediary that handles all encryption operations externally to the primary storage system. This intermediary approach allows storage resources to remain available for data operations while the encryption service processes encryption requests, thereby maintaining system performance and providing transparent encryption to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10924275B1Creating multiple encrypted volumes from a single source
Publication Date: 2021.02.16 AMAZON TECH INC
  • US10924275B1 patent drawing
  • US10924275B1 patent drawing
  • US10924275B1 patent drawing

AI summary

Generally described, one or more aspects of the present application correspond to techniques for creating multiple encrypted block store volumes of data from an unencrypted source. These encryption techniques can use a transform fleet as an intermediary use between the unencrypted source and the encrypted volumes. The transform fleet can obtain data of the volume from one or both of two sources—an object storage “snapshot” a block storage “source volume”—and can then apply the appropriate encryption key for performing the encryption of a particular volume.