发明名称 Encryption solution for protecting file systems in multi-host clusters
摘要 A method of managing file security in a cluster environment is provided. The method includes passing a request for a file from a secure file system layer to a secure volume manager layer and locking at least a portion of the file as affected by the request, at a cluster file system layer. The method includes passing one or more keys from the secure file system layer to the secure volume manager layer. The method includes decrypting the file as received, in response to the request for the file including a read request for the file, prior to sending the decrypted file to the secure file system layer. The method includes encrypting the file as received, in response to the request for the file including a write request for the file, prior to sending the encrypted file to the input/output layer.
申请公布号 US9202077(B2) 申请公布日期 2015.12.01
申请号 US201314015954 申请日期 2013.08.30
申请人 Vormetric, Inc. 发明人 Sadrolashrafi Masoud
分类号 H04L29/06;G06F21/62 主分类号 H04L29/06
代理机构 Womble Carlyle Sandridge & Rice LLP 代理人 Womble Carlyle Sandridge & Rice LLP
主权项 1. A method of managing file security in a multi-host cluster environment, comprising: passing a request for a file from a secure file system layer process local to one of a plurality of hosts in the multi-host cluster environment through a cluster file system layer process local to the one of the plurality of hosts to a secure volume manager layer process local to the one of the plurality of hosts, wherein the file is to be written to or read from a network shared storage coupled to the plurality of hosts; locking at least a portion of the file as affected by the request, at the cluster file system layer process, the locking preventing access by other requests; passing one or more keys from the secure file system layer process to the secure volume manager layer process; decrypting, via application of the one or more keys at the secure volume manager layer process, the file as received, in response to the request for the file including a read request for the file, prior to sending the decrypted file to the secure file system layer process; and encrypting, via application of the one or more keys at the secure volume manager layer process, the file as received, in response to the request for the file including a write request for the file, prior to sending the encrypted file to an input/output layer process, wherein at least one method operation is executed through a processor.
地址 San Jose CA US