发明名称 Key information consistency checking in encrypting data storage system
摘要 A data storage system employs data encryption to increase data security, and techniques for ensuring consistency of key information maintained and used throughout the system to reduce the likelihood that data will become non-recoverable due to the use of an incorrect encryption key. In one aspect, a verification process is performed between a key table at a central storage processor and key tables containing decrypted copies of the same information that are stored and utilized at separate input/output (I/O) modules. The verification process includes computing respective hash values at the I/O modules and at the storage processor and comparing the hash values to determine whether they match, a match indicating that the tables are consistent and a non-match indicating that the tables are not consistent. In another aspect, an I/O module performs a check prior to performing an encryption/decryption operation as part of processing an I/O command to ensure that the correct key will be utilized. This check involves comparing address information from the I/O command to address information stored in association with the data encryption key. If the address information is consistent, it indicates that the specified data encryption key is the correct key to be used for the encryption/decryption operation.
申请公布号 US8005227(B1) 申请公布日期 2011.08.23
申请号 US20070964789 申请日期 2007.12.27
申请人 EMC CORPORATION 发明人 LINNELL THOMAS;HARWOOD JACK;FITZGERALD JOHN T.
分类号 H04L9/08 主分类号 H04L9/08
代理机构 代理人
主权项
地址