US2017373848A1PendingUtilityA1
Method and apparatus for cryptographic conversion in a data storage system
Est. expiryMar 11, 2024(expired)· nominal 20-yr term from priority
Inventors:Nobuyuki Osaki
H04L 9/088H04L 9/0894G06F 21/80H04L 9/14
59
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
When data is encrypted and stored for a long time, encryption key(s) and/or algorithm(s) should be updated so as not to be compromised due to malicious attack. To that end, stored encrypted data is converted in the storage system with new set of cryptographic criteria. During this process, read and write requests can be serviced.
Claims
exact text as granted — not AI-modified1 - 15 . (canceled)
16 . A system comprising:
a storage having at least one physical storage device; and a controller internally coupled to the storage, the controller configured to: encrypt a first data, that was stored in the physical storage device in un-encrypted form, to produce an encrypted data using an encryption key; store the encrypted data to the physical storage device in the storage; and access a second data stored in the physical storage device, which includes reading the second data, wherein the accessing of the second data is performed during the encrypting of the first data to produce the encrypted data.
17 . The computer system according to claim 16 ,
wherein the controller is further configured to update progress position information based on an encrypted position of the first data.
18 . The system according to claim 17 ,
wherein the controller is further configured to: compare the progress position information with I/O (Input/Output) position information indicated in an I/O request; and determine whether to execute data encryption/decryption or not for the I/O request based on the comparison.
19 . The system according to claim 17 ,
wherein the progress position information indicates at least one of a position that has been encrypted or a position that has not been encrypted.
20 . The system according to claim 17 ,
wherein the I/O request is a read request for reading out the second data and the I/O position information is read position information; and wherein the progress position information is compared with the read position information indicated in the read request in order to determine whether the controller will decrypt the second data or not.
21 . The system according to claim 17 ,
wherein the I/O request is a read request for reading out the second data and the I/O position information is read position information; and wherein the controller is further configured to decrypt the second data if the read position information is identified as an area that has been an encrypted area by the comparison with the progress position information.
22 . The system according to claim 17 ,
wherein the I/O request is a write request for storing a third data and the I/O position information is write position information; and wherein the progress position information is compared with the write position information indicated in the write request in order to determine whether the controller will encrypt the third data or not.
23 . The system according to claim 17 ,
wherein the I/O request is a write request for storing a third data and the I/O position information is write position information; and wherein the controller is further configured to encrypt the third data if the write position information is identified as an area that has been an encrypted area by the comparison with the progress position information.
24 . A method for storing data in a storage which includes at least one physical storage device and which is internally coupled to a controller, the method comprising:
encrypting a first data, that was stored in the physical storage device in un-encrypted form, to produce an encrypted data using an encrypting key; storing the encrypted data in the physical storage device; and accessing a second data stored in the physical storage device, wherein the accessing of the second data is performed during the encrypting of the first data to produce the encrypted data; wherein the encrypting, storing, and accessing are performed by the controller.
25 . The method according to claim 24 , further comprising:
updating, by the controller, progress position information based on an encrypted position of the first data.
26 . The method according to claim 25 , further comprising:
comparing, by the controller, the progress position information with I/O position information indicated in an I/O request; and determining, by the controller, whether to execute data encryption/decryption or not for the I/O request based on the comparison.
27 . The method according to claim 25 ,
wherein the progress position information indicates at least one of a position that has been encrypted or a position that has not been encrypted.
28 . The method according to claim 25 ,
wherein the I/O request is a read request for reading out the second data and the I/O position information is read position information; and wherein the progress position information is compared with the read position information indicated in the read request, by the controller, in order to determine whether the controller will decrypt the second data or not.
29 . The method according to claim 25 ,
wherein the I/O request is a read request for reading out the second data and the I/O position information is read position information; and wherein the method further comprises: decrypting, by the controller, the second data if the read position information is identified as an area that has been an encrypted area by the comparison with the progress position information.
30 . The method according to claim 25 ,
wherein the I/O request is a write request for storing a third data and the I/O position information is write position information; and wherein the progress position information is compared with the write position information indicated in the write request in order to determine whether the controller will encrypt the third data or not.
31 . The method according to claim 25 ,
wherein the I/O request is a write request for storing a third data and the I/O position information is write position information; and wherein the method further comprises: encrypting, by the controller, the third data if the write position information is identified as an area that has been an encrypted area by the comparison with the progress position information.Join the waitlist — get patent alerts
Track US2017373848A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.