发明名称 DATA PROTECTION IN A STORAGE SYSTEM USING EXTERNAL SECRETS
摘要 A system, method, and computer-readable storage medium for protecting a set of storage devices using a secret sharing scheme in combination with an external secret. An initial master secret is generated and then transformed into a final master secret using an external secret. A plurality of shares are generated from the initial master secret and distributed to the storage devices. The data of each storage device is encrypted with a device-specific key, and this key is encrypted using the final master secret. In order to read the data on a given storage device, the initial master secret reconstructed from a threshold number of shares and the external secret is retrieved. Next, the initial master secret is transformed into the final master secret using the external secret, and then the final master secret is used to decrypt the encrypted key of a given storage device.
申请公布号 EP3066610(A1) 申请公布日期 2016.09.14
申请号 EP20140796637 申请日期 2014.10.27
申请人 PURE STORAGE, INC. 发明人 MILLER, ETHAN;COLGROVE, JOHN;HAYES, JOHN
分类号 G06F21/62;G06F17/30;H04L9/08 主分类号 G06F21/62
代理机构 代理人
主权项
地址