Master key generation and distribution for storage area network devices

    公开(公告)号:US10148431B2

    公开(公告)日:2018-12-04

    申请号:US14472358

    申请日:2014-08-28

    Abstract: Mechanisms are provided for generating a master key used to secure key objects associated with data blocks in a data center. A cryptographic node creation request is received. It is determined that a master key can not be obtained from another cryptographic node in the data center. A master key is generated. The master key is included in a key hierarchy used to encrypt a data center key object, the data center key object corresponding to a data block maintained in a storage area network (SAN), where the data center key object includes a unique identifier, an encrypted key, and a wrapper unique identifier. The master key is split into N shares, with M shares required to recreate the master key, wherein M is less than N. The N shares are distributed to different entities.

    MASTER KEY GENERATION AND DISTRIBUTION FOR STORAGE AREA NETWORK DEVICES
    2.
    发明申请
    MASTER KEY GENERATION AND DISTRIBUTION FOR STORAGE AREA NETWORK DEVICES 审中-公开
    存储区域网络设备的主要生成和分配

    公开(公告)号:US20150019870A1

    公开(公告)日:2015-01-15

    申请号:US14472358

    申请日:2014-08-28

    Abstract: Mechanisms are provided for generating a master key used to secure key objects associated with data blocks in a data center. A cryptographic node creation request is received. It is determined that a master key can not be obtained from another cryptographic node in the data center. A master key is generated. The master key is included in a key hierarchy used to encrypt a data center key object, the data center key object corresponding to a data block maintained in a storage area network (SAN), where the data center key object includes a unique identifier, an encrypted key, and a wrapper unique identifier. The master key is split into N shares, with M shares required to recreate the master key, wherein M is less than N. The N shares are distributed to different entities.

    Abstract translation: 提供了用于生成用于保护与数据中心中的数据块相关联的密钥对象的主密钥的机制。 接收加密节点创建请求。 确定不能从数据中心中的另一密码节点获得主密钥。 生成主密钥。 主密钥被包括在用于加密数据中心密钥对象的密钥层级中,数据中心密钥对象对应于维护在存储区域网络(SAN)中的数据块,其中数据中心密钥对象包括唯一标识符, 加密密钥和封装唯一标识符。 主密钥分为N股,M股需要重新创建主密钥,其中M小于N。N股分配给不同的实体。

Patent Agency Ranking