×

Encryption key recovery in the event of storage management failure

  • US 9,571,278 B1
  • Filed: 10/21/2013
  • Issued: 02/14/2017
  • Est. Priority Date: 12/27/2007
  • Status: Active Grant
First Claim
Patent Images

1. A method of encryption key recovery, said method comprising a hardware processor executing computer instructions in memory to perform the steps of:

  • (a) creating a storage object for containing encrypted data in data storage of a data storage system, assigning an object identifier to the storage object for identifying the storage object in the data storage system, assigning a data encryption key to the storage object, assigning a key identifier to the data encryption key, storing the data encryption key in the data storage system in association with the object identifier, and storing the key identifier in the data storage system in association with the object identifier; and

    (b) when performing an operation upon the storage object using the data encryption key in the data storage system, detecting failure of the data encryption key in the data storage system, and in response to detecting failure of the data encryption key in the data storage system, using the object identifier for fetching the stored key identifier associated with the object identifier, and using the fetched key identifier associated with the object identifier for fetching a copy of the data encryption key from a key server computer, and resuming the operation upon the storage object using the copy of the data encryption key fetched from the key server computer.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×