US2012284531A1PendingUtilityA1
Method and apparatus for cryptographic conversion in a data storage system
Est. expiryMar 11, 2024(expired)· nominal 20-yr term from priority
Inventors:Nobuyuki Osaki
G06F 21/80H04L 9/14H04L 9/0894H04L 9/088
53
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
When data is encrypted and stored for a long time, encryption key(s) and/or algorithm(s) should be updated so as not to be compromised due to malicious attack. To that end, stored encrypted data is converted in the storage system with new set of cryptographic criteria. During this process, read and write requests can be serviced.
Claims
exact text as granted — not AI-modified1 - 15 . (canceled)
16 . A storage system comprising:
at least one storage device; and a controller coupled to the storage device, the controller configured to: encrypt a first data, that was stored in the storage device in un-encrypted form, to produce an encrypted data using an encryption key; store the encrypted data to the storage device in the storage system; and access a second data stored in the storage device, which includes reading the second data, wherein the accessing of the second data is performed during the encrypting of the first data to produce the encrypted data.
17 . The storage system according to claim 16 ,
wherein the controller is further configured to update progress position information based on an encrypted position of the first data.
18 . The storage system according to claim 17 ,
wherein the controller is further configured to: compare the progress position information with I/O (Input/Output) position information indicated in an I/O request; and determine whether to execute data conversion or not for the I/O request based on the comparison.
19 . The storage system according to claim 17 ,
wherein the progress position information indicates at least one of a position that has been encrypted or a position that has not been encrypted.
20 . The storage system according to claim 17 ,
wherein the I/O request is a read request for reading out the second data and the I/O position information is read position information; and wherein the progress position information is compared with the read position information indicated in the read request in order to determine whether the controller will decrypt the second data or not.
21 . The storage system according to claim 17 ,
wherein the I/O request is a read request for reading out the second data and the I/O position information is read position information; and wherein the controller is further configured to decrypt the second data if the read position information is identified as an area that has been an encrypted area by the comparison with the progress position information.
22 . The storage system according to claim 17 ,
wherein the I/O request is a write request for storing a third data and the I/O position information is write position information; and wherein the progress position information is compared with the write position information indicated in the write request in order to determine whether the controller will encrypt the third data or not.
23 . The storage system according to claim 17 ,
wherein the I/O request is a write request for storing a third data and the I/O position information is write position information; and wherein the controller is further configured to encrypt the third data if the write position information is identified as an area that has been an encrypted area by the comparison with the progress position information.
24 . A method for storing data in a storage system, the method comprising:
encrypting a first data, that was stored in the storage device in un-encrypted form, to produce an encrypted data using an encrypting key; storing the encrypted data in the storage device; and accessing a second data stored in the storage device, wherein the accessing of the second data is performed during the encrypting of the first data to produce the encrypted data.
25 . The method according to claim 24 , further comprising:
updating progress position information based on an encrypted position of the first data.
26 . The method according to claim 25 , further comprising:
comparing the progress position information with I/O position information indicated in an I/O request; and determining whether to execute data conversion or not for the I/O request based on the comparison.
27 . The method according to claim 25 ,
wherein the progress position information indicates at least one of a position that has been encrypted or a position that has not been encrypted.
28 . The method according to claim 25 ,
wherein the I/O request is a read request for reading out the second data and the I/O position information is read position information; and wherein the progress position information is compared with the read position information indicated in the read request in order to determine whether the controller will decrypt the second data or not.
29 . The method according to claim 25 ,
wherein the I/O request is a read request for reading out the second data and the I/O position information is read position information; and wherein the method further comprises: decrypting the second data if the read position information is identified as an area that has been an encrypted area by the comparison with the progress position information.
30 . The method according to claim 25 ,
wherein the I/O request is a write request for storing a third data and the I/O position information is write position information; and wherein the progress position information is compared with the write position information indicated in the write request in order to determine whether the controller will encrypt the third data or not.
31 . The method according to claim 25 ,
wherein the I/O request is a write request for storing a third data and the I/O position information is write position information; and wherein the method further comprises: encrypting the third data if the write position information is identified as an area that has been an encrypted area by the comparison with the progress position information.Join the waitlist — get patent alerts
Track US2012284531A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.