US2021234843A1PendingUtilityA1

Secured transfer of data between datacenters

Assignee: SALESFORCE COM INCPriority: Jan 30, 2017Filed: Feb 1, 2021Published: Jul 29, 2021
Est. expiryJan 30, 2037(~10.5 yrs left)· nominal 20-yr term from priority
Inventors:Paul Eldridge
H04L 63/0435G06F 11/3409H04L 63/0272H04L 63/0428G06F 2221/2107G06F 21/602G06F 11/3442G06F 11/3433G06F 2201/81G06F 11/3006G06F 11/3452H04L 63/0485
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In various embodiments, a method of transferring data between datacenters may be performed. The method may include running a first plurality of host programs and a first plurality of encryption units at a first datacenter. The method may further include establishing, between the first datacenter and a second datacenter, secure communication connections between each of the first plurality of encryption units and a corresponding one of a second plurality of encryption units running at the second datacenter. The method may further include transferring, by the first datacenter, data from the first plurality of host programs to a second plurality of host programs running at the second datacenter.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method, comprising:
 transferring data from a first host program executing at a first datacenter to a second host program executing at a second datacenter, including by:
 selecting, by the first host program, a first encryption unit, from a plurality of encryption units, to encrypt data from the first host program; 
 encrypting, by the first encryption unit, data from the first host program to generate encrypted data; and 
 sending the encrypted data from the first encryption unit to a corresponding encryption unit executing at the second datacenter; 
   monitoring one or more levels of usage of the plurality of encryption units; and   modifying a number of encryption units executing at the first datacenter based on the one or more levels of usage, including by sending a request to an orchestration host to instantiate additional encryption units at the first datacenter and the second datacenter.   
     
     
         22 . The method of  claim 21 , further comprising:
 monitoring one or more performance metrics of the plurality of encryption units executing at the first datacenter;   determining, based on the one or more performance metrics, ranking information corresponding to the plurality of encryption units; and   providing the ranking information to the first host program.   
     
     
         23 . The method of  claim 22 , wherein the selecting the first encryption unit from the plurality of encryption units is performed based on the ranking information. 
     
     
         24 . The method of  claim 22 , wherein the one or more performance metrics include at least one of the following metrics:
 a processor utilization;   a data transmission speed; and   a status of a secure communication connection.   
     
     
         25 . The method of  claim 21 , further comprising:
 periodically refreshing the plurality of encryption units executing at the first datacenter, including by:
 decommissioning at least one of the plurality of encryption units after a particular time interval such that the at least one encryption unit is no longer available for use in transferring encrypted data to the second datacenter; and 
 instantiating a new encryption unit at the first datacenter. 
   
     
     
         26 . The method of  claim 21 , wherein the orchestration host is executing at the first datacenter. 
     
     
         27 . The method of  claim 21 , wherein the one or more levels of usage includes at least one of the following:
 a processor utilization of one or more of the plurality of encryption units;   a data-transfer rate of one or more of the plurality of encryption units; and   a Bidirectional Forwarding Detection (BFD) link status.   
     
     
         28 . A non-transitory, computer-readable medium having computer instructions stored thereon that are capable of being executed by one or more computer systems to cause operations comprising:
 transferring data from a first host program executing at a first datacenter to a second host program executing at a second datacenter, including by:
 selecting, by the first host program, a first encryption unit, from a plurality of encryption units, to encrypt data from the first host program; 
 encrypting, by the first encryption unit, data from the first host program to generate encrypted data; and 
 sending the encrypted data from the first encryption unit to a corresponding encryption unit executing at the second datacenter; 
   monitoring one or more levels of usage of the plurality of encryption units; and   modifying a number of encryption units executing at the first datacenter based on the one or more levels of usage, including by sending a request to an orchestration host to instantiate additional encryption units at the first datacenter and the second datacenter.   
     
     
         29 . The non-transitory, computer-readable medium of  claim 28 , wherein the operations further comprise:
 monitoring one or more performance metrics of the plurality of encryption units executing at the first datacenter;   determining, based on the one or more performance metrics, ranking information corresponding to the plurality of encryption units; and   providing the ranking information to the first host program.   
     
     
         30 . The non-transitory, computer-readable medium of  claim 29 , wherein the selecting the first encryption unit from the plurality of encryption units is performed based on the ranking information. 
     
     
         31 . The non-transitory, computer-readable medium of  claim 29 , wherein the one or more performance metrics include at least one of the following metrics:
 a processor utilization;   a data transmission speed; and   a status of a secure communication connection.   
     
     
         32 . The non-transitory, computer-readable medium of  claim 28 , wherein the operations further comprise:
 periodically refreshing the plurality of encryption units executing at the first datacenter, including by:
 decommissioning at least one of the plurality of encryption units after a particular time interval such that the at least one encryption unit is no longer available for use in transferring encrypted data to the second datacenter; and 
 instantiating a new encryption unit at the first datacenter. 
   
     
     
         33 . The non-transitory, computer-readable medium of  claim 28 , wherein the orchestration host is executing at the second datacenter. 
     
     
         34 . The non-transitory, computer-readable medium of  claim 28 , wherein the one or more levels of usage includes at least one of the following:
 a processor utilization of one or more of the plurality of encryption units;   a data-transfer rate of one or more of the plurality of encryption units; and   a Bidirectional Forwarding Detection (BFD) link status.   
     
     
         35 . A method, comprising:
 transferring data from a first host program executing at a first datacenter to a second host program executing at a second datacenter, including by:
 selecting, by the first host program, a first encryption unit, from a plurality of encryption units, to encrypt data from the first host program; 
 encrypting, by the first encryption unit, data from the first host program to generate encrypted data; and 
 sending the encrypted data from the first encryption unit to a corresponding encryption unit executing at the second datacenter; 
   periodically refreshing the plurality of encryption units executing at the first datacenter, including by:
 decommissioning at least one of the plurality of encryption units after a particular time interval such that the at least one encryption unit is no longer available for use in transferring encrypted data to the second datacenter; and 
 instantiating a new encryption unit at the first datacenter. 
   
     
     
         36 . The method of  claim 35 , further comprising:
 monitoring one or more performance metrics of the plurality of encryption units executing at the first datacenter;   determining, based on the one or more performance metrics, ranking information corresponding to the plurality of encryption units; and   providing the ranking information to the first host program.   
     
     
         37 . The method of  claim 36 , wherein the selecting the first encryption unit from the plurality of encryption units is performed based on the ranking information. 
     
     
         38 . The method of  claim 35 , wherein the one or more performance metrics include at least one of the following metrics:
 a processor utilization;   a data transmission speed; and   a status of a secure communication connection.   
     
     
         39 . The method of  claim 35 , further comprising:
 monitoring one or more levels of usage of the plurality of encryption units; and   modifying a number of encryption units executing at the first datacenter based on the one or more levels of usage, including by sending a request to an orchestration host to instantiate additional encryption units at the first datacenter and the second datacenter.   
     
     
         40 . The method of  claim 39 , wherein the one or more levels of usage includes at least one of the following:
 a processor utilization of one or more of the plurality of encryption units;   a data-transfer rate of one or more of the plurality of encryption units; and   a Bidirectional Forwarding Detection (BFD) link status.

Join the waitlist — get patent alerts

Track US2021234843A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.