Secured transfer of data between datacenters
Abstract
In various embodiments, a method of transferring data between datacenters may be performed. The method may include running a first plurality of host programs and a first plurality of encryption units at a first datacenter. The method may further include establishing, between the first datacenter and a second datacenter, secure communication connections between each of the first plurality of encryption units and a corresponding one of a second plurality of encryption units running at the second datacenter. The method may further include transferring, by the first datacenter, data from the first plurality of host programs to a second plurality of host programs running at the second datacenter.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method, comprising:
transferring data from a first host program executing at a first datacenter to a second host program executing at a second datacenter, including by:
selecting, by the first host program, a first encryption unit, from a plurality of encryption units, to encrypt data from the first host program;
encrypting, by the first encryption unit, data from the first host program to generate encrypted data; and
sending the encrypted data from the first encryption unit to a corresponding encryption unit executing at the second datacenter;
monitoring one or more levels of usage of the plurality of encryption units; and modifying a number of encryption units executing at the first datacenter based on the one or more levels of usage, including by sending a request to an orchestration host to instantiate additional encryption units at the first datacenter and the second datacenter.
22 . The method of claim 21 , further comprising:
monitoring one or more performance metrics of the plurality of encryption units executing at the first datacenter; determining, based on the one or more performance metrics, ranking information corresponding to the plurality of encryption units; and providing the ranking information to the first host program.
23 . The method of claim 22 , wherein the selecting the first encryption unit from the plurality of encryption units is performed based on the ranking information.
24 . The method of claim 22 , wherein the one or more performance metrics include at least one of the following metrics:
a processor utilization; a data transmission speed; and a status of a secure communication connection.
25 . The method of claim 21 , further comprising:
periodically refreshing the plurality of encryption units executing at the first datacenter, including by:
decommissioning at least one of the plurality of encryption units after a particular time interval such that the at least one encryption unit is no longer available for use in transferring encrypted data to the second datacenter; and
instantiating a new encryption unit at the first datacenter.
26 . The method of claim 21 , wherein the orchestration host is executing at the first datacenter.
27 . The method of claim 21 , wherein the one or more levels of usage includes at least one of the following:
a processor utilization of one or more of the plurality of encryption units; a data-transfer rate of one or more of the plurality of encryption units; and a Bidirectional Forwarding Detection (BFD) link status.
28 . A non-transitory, computer-readable medium having computer instructions stored thereon that are capable of being executed by one or more computer systems to cause operations comprising:
transferring data from a first host program executing at a first datacenter to a second host program executing at a second datacenter, including by:
selecting, by the first host program, a first encryption unit, from a plurality of encryption units, to encrypt data from the first host program;
encrypting, by the first encryption unit, data from the first host program to generate encrypted data; and
sending the encrypted data from the first encryption unit to a corresponding encryption unit executing at the second datacenter;
monitoring one or more levels of usage of the plurality of encryption units; and modifying a number of encryption units executing at the first datacenter based on the one or more levels of usage, including by sending a request to an orchestration host to instantiate additional encryption units at the first datacenter and the second datacenter.
29 . The non-transitory, computer-readable medium of claim 28 , wherein the operations further comprise:
monitoring one or more performance metrics of the plurality of encryption units executing at the first datacenter; determining, based on the one or more performance metrics, ranking information corresponding to the plurality of encryption units; and providing the ranking information to the first host program.
30 . The non-transitory, computer-readable medium of claim 29 , wherein the selecting the first encryption unit from the plurality of encryption units is performed based on the ranking information.
31 . The non-transitory, computer-readable medium of claim 29 , wherein the one or more performance metrics include at least one of the following metrics:
a processor utilization; a data transmission speed; and a status of a secure communication connection.
32 . The non-transitory, computer-readable medium of claim 28 , wherein the operations further comprise:
periodically refreshing the plurality of encryption units executing at the first datacenter, including by:
decommissioning at least one of the plurality of encryption units after a particular time interval such that the at least one encryption unit is no longer available for use in transferring encrypted data to the second datacenter; and
instantiating a new encryption unit at the first datacenter.
33 . The non-transitory, computer-readable medium of claim 28 , wherein the orchestration host is executing at the second datacenter.
34 . The non-transitory, computer-readable medium of claim 28 , wherein the one or more levels of usage includes at least one of the following:
a processor utilization of one or more of the plurality of encryption units; a data-transfer rate of one or more of the plurality of encryption units; and a Bidirectional Forwarding Detection (BFD) link status.
35 . A method, comprising:
transferring data from a first host program executing at a first datacenter to a second host program executing at a second datacenter, including by:
selecting, by the first host program, a first encryption unit, from a plurality of encryption units, to encrypt data from the first host program;
encrypting, by the first encryption unit, data from the first host program to generate encrypted data; and
sending the encrypted data from the first encryption unit to a corresponding encryption unit executing at the second datacenter;
periodically refreshing the plurality of encryption units executing at the first datacenter, including by:
decommissioning at least one of the plurality of encryption units after a particular time interval such that the at least one encryption unit is no longer available for use in transferring encrypted data to the second datacenter; and
instantiating a new encryption unit at the first datacenter.
36 . The method of claim 35 , further comprising:
monitoring one or more performance metrics of the plurality of encryption units executing at the first datacenter; determining, based on the one or more performance metrics, ranking information corresponding to the plurality of encryption units; and providing the ranking information to the first host program.
37 . The method of claim 36 , wherein the selecting the first encryption unit from the plurality of encryption units is performed based on the ranking information.
38 . The method of claim 35 , wherein the one or more performance metrics include at least one of the following metrics:
a processor utilization; a data transmission speed; and a status of a secure communication connection.
39 . The method of claim 35 , further comprising:
monitoring one or more levels of usage of the plurality of encryption units; and modifying a number of encryption units executing at the first datacenter based on the one or more levels of usage, including by sending a request to an orchestration host to instantiate additional encryption units at the first datacenter and the second datacenter.
40 . The method of claim 39 , wherein the one or more levels of usage includes at least one of the following:
a processor utilization of one or more of the plurality of encryption units; a data-transfer rate of one or more of the plurality of encryption units; and a Bidirectional Forwarding Detection (BFD) link status.Join the waitlist — get patent alerts
Track US2021234843A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.