发明名称 LOG STRUCTURED VOLUME ENCRYPTION FOR VIRTUAL MACHINES
摘要 Methods, systems, and apparatus, including a method for providing data. The method comprises receiving a first request from a first virtual machine (VM) to store data, obtaining the data and an access control list (ACL) of authorized users, obtaining a data key that has a data key identifier, encrypting the data key and the ACL using a wrapping key to generate a wrapped blob, encrypting the data, storing the wrapped blob and the encrypted data, and providing the data key identifier to users on the ACL. The method further comprises receiving a second request from a second VM to obtain a data snapshot, obtaining an unwrapped blob, obtaining the data key and the ACL from the unwrapped blob, authenticating a user associated with the second request, authorizing the user against the ACL, decrypting the data using the data key, and providing a snapshot of the data to the second VM.
申请公布号 US2013227303(A1) 申请公布日期 2013.08.29
申请号 US201213405036 申请日期 2012.02.24
申请人 KADATCH ANDREW;HALCROW MICHAEL A.;GOOGLE INC. 发明人 KADATCH ANDREW;HALCROW MICHAEL A.
分类号 G06F9/455 主分类号 G06F9/455
代理机构 代理人
主权项
地址