EP1388061A2

Encryption based security system for network storage

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 14 May 2022, 4.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

54 claims: 5 independent, 49 dependent

  1. 1
    Claims of equivalent WO 02093314 A2 CLAIMS 1. An encryption based security apparatus for network storage, comprising:one or more storage devices;one or more client devices;and an encryption device for separating access to said one or more storage devices via said one or more client devices from access to client data stored on said one or more storage devices;wherein said encryption device encrypts all client data that is stored on said one or more storage devices.
  2. 2
    The apparatus of Claim 1 , said encryption device comprising:at least two network interfaces, comprising: a clear text network interface that is connected to said one or more clients;and a secure network interface that is connected to said one or more storage devices;wherein each network interface supports multiple network nodes.
  3. 3
    The apparatus of Claim 1 , wherein said encryption device is located in a network, on a path between said one or more client devices and said one or more storage devices.
  4. 4
    The apparatus of Claim 1 , wherein said encryption device intercepts all packets that flow between said one or more client devices and said one or more storage devices.
  5. 5
    The apparatus of Claim 1 , wherein said encryption device distinguishes between data, command, and status information.
  6. 6
    The apparatus of Claim , wherein said encryption device encrypts said client data sent from said one or more client devices to said one or more storage devices using an encryption method;wherein said encryption device decrypts said client data sent from said one or more client storage to said one or more client devices using said encryption method;and wherein said encryption device passes command and status information through without modification.
  7. 7
    The apparatus of Claim 1 , said encryption device comprising:a plurality of keys for encrypting and decrypting said client data;and a selection module for selecting a particular one of said plurality of keys based upon at least one of client identification, data location on said one or more storage devices, file name, permission structure, and other factors.
  8. 8
    The apparatus of Claim 7, wherein a plurality of encryption devices share keys and selection modules between them, wherein client data encrypted by one encryption device can be decrypted by another encryption device.
  9. 9
    The apparatus of Claim 1 , wherein said encryption device operates in a transparent fashion to both of said one or more client devices and said one or more storage systems;wherein no modification is required to either of said one or more client devices and said one or more storage devices to enable storage of encrypted client data on said one or more storage devices, and to enable subsequent retrieval and decryption of said client data.
  10. 10
    The apparatus of Claim 1 , wherein said encryption device performs any of decoding device storage related traffic, extracting of a payload, and transparent encryption of said payload.
  11. 11
    The apparatus of Claim 1 , wherein said encryption device operates in any of SAN, NAS (NFS/CIFS), and HTML environments.
  12. 12
    The apparatus of Claim 7, wherein said encryption keys are generated inside said encryption device and are not transmitted therefrom in cleartext form.
  13. 13
    The apparatus of Claim 7, wherein said encryption keys are encrypted with a master key that is generated inside said encryption device.
  14. 14
    The apparatus of Claim 13, wherein said master key is never transmitted from said encryption device.
  15. 15
    The apparatus of Claim 13, wherein said master key is transmitted from said encryption device using a shared key, wherein said key is broken into a plurality of key parts, wherein possession of some subset of said plurality of key parts is sufficient to reconstruct said master key.
  16. 16
    The apparatus of Claim 7, wherein a user is allowed to have an additional key, wherein said user key, a Cryptainer key, and a master key are required to encrypt said client data.
  17. 17
    The apparatus of Claim 7, wherein keys are assigned to any of a region and a directory.
  18. 18
    The apparatus of Claim 1 , further comprising:a client application;and a server comprising a server application;wherein user passwords are propagated to said encryption device;and wherein said server can not access client data except as permitted by said user.
  19. 19
    The apparatus of Claim 1 , wherein said encryption device comprises:a module for initially encrypting and re-encrypting said client data without interrupting access to said one or more storage devices by said one or more client devices.
  20. 20
    The apparatus of Claim 1 , wherein said encryption device comprises:a module for administrator management of said client data;wherein said client data are not readable by said administrator.
  21. 21
    The apparatus of Claim 1 , wherein said encryption device comprises:a module for allowing a first user to control which other users may access said first user's client data without explicitly sharing a first user's key with said other users.
  22. 22
    The apparatus of Claim 1 , wherein said encryption device combines encryption with mirroring.
  23. 23
    The apparatus of Claim 1 , wherein said encryption device permits any of private and shared mirror configurations.
  24. 24
    The apparatus of Claim 1 , wherein said encryption device permits selective remote client data access.
  25. 25
    The apparatus of Claim 1 , wherein said encryption device permits a failover configuration in connection with encryption and decryption of storage device related traffic.
  26. 26
    The apparatus of Claim 1 , wherein said encryption device transparently forwards traffic that is not storage related.
  27. 27
    An encryption based security apparatus for network storage, comprising:an encryption device, located in a network, on a path between one or more client devices and one or more storage devices, for separating access to said one or more storage devices via said one or more client devices from access to client data stored on said one or more storage devices;said encryption device comprising at least two network interfaces, comprising a clear text network interface that is connected to said one or more clients;and a secure network interface that is connected to said one or more storage devices;wherein each network interface supports multiple network nodes;wherein said encryption device encrypts all client data that is stored on said one or more storage devices.
  28. 28
    An encryption based security method for network storage, comprising the steps of:providing one or more storage devices;providing one or more client devices;and separating access to said one or more storage devices via said one or more client devices from access to client data stored on said one or more storage devices with an encryption device;wherein said encryption device encrypts all client data that is stored on said one or more storage devices.
  29. 29
    The method of Claim 28, said encryption device comprising:at least two network interfaces, comprising: a clear text network interface that is connected to said one or more clients;and a secure network interface that is connected to said one or more storage devices;wherein each network interface supports multiple network nodes.
  30. 30
    The method of Claim 28, wherein said encryption device is located in a network, on a path between said one or more client devices and said one or more storage devices.
  31. 31
    The method of Claim 28, wherein said encryption device intercepts all packets that flow between said one or more client devices and said one or more storage devices.
  32. 32
    The method of Claim 28, wherein said encryption device distinguishes between data, command, and status information.
  33. 33
    The method of Claim 28, wherein said encryption device encrypts said client data sent from said one or more client devices to said one or more storage devices using an encryption method;wherein said encryption device decrypts said client data sent from said one or more client storage to said one or more client devices using said encryption method;and wherein said encryption device passes command and status information through without modification.
  34. 34
    The method of Claim 28, further comprising the steps of:providing a plurality of keys for encrypting and decrypting said client data;and providing a selection module for selecting a particular one of said plurality of keys based upon at least one of client identification, data location on said one or more storage devices, file name, permission structure, and other factors.
  35. 35
    The method of Claim 34, wherein a plurality of encryption devices share keys and selection modules between them, wherein client data encrypted by one encryption device can be decrypted by another encryption device.
  36. 36
    The method of Claim 28, wherein said encryption device operates in a transparent fashion to both of said one or more client devices and said one or more storage systems;wherein no modification is required to either of said one or more client devices and said one or more storage devices to enable storage of encrypted client data on said one or more storage devices, and to enable subsequent retrieval and decryption of said client data.
  37. 37
    The method of Claim 28, wherein said encryption device performs any of decoding device storage related traffic, extracting of a payload, and transparent encryption of said payload.
  38. 38
    The method of Claim 28, wherein said encryption device operates in any of SAN, NAS (NFS/CIFS), and HTML environments.
  39. 39
    The method of Claim 34, wherein said encryption keys are generated inside said encryption device and are not transmitted therefrom in cleartext form.
  40. 40
    The method of Claim 34, wherein said encryption keys are encrypted with a master key that is generated inside said encryption device.
  41. 41
    The method of Claim 40, wherein said master key is never transmitted from said encryption device.
  42. 42
    The method of Claim 40, wherein said master key is transmitted from said encryption device using a shared key, wherein said key is broken into a plurality of key parts, wherein possession of some subset of said plurality of key parts is sufficient to reconstruct said master key.
  43. 43
    The method of Claim 34, wherein a user is allowed to have an additional key, wherein said user key, a Cryptainer key, and a master key are required to encrypt said client data.
  44. 44
    The method of Claim 34, wherein keys are assigned to any of a region and a directory.
  45. 45
    The method of Claim 1 , further comprising the steps of:providing a client application;and providing a server comprising a server application;wherein user passwords are propagated to said encryption device;and wherein said server can not access client data except as permitted by said user.
  46. 46
    The method of Claim 28, further comprising the step of:initially encrypting and re-encrypting said client data without interrupting access to said one or more storage devices by said one or more client devices.
  47. 47
    The method of Claim 28, further comprising the step of:providing a module for administrator management of said client data;wherein said client data are not readable by said administrator.
  48. 48
    The method of Claim 28, further comprising the step of:allowing a first user to control which other users may access said first user's client data without explicitly sharing a first user's key with said other users.
  49. 49
    The method of Claim 28, wherein said encryption device combines encryption with mirroring.
  50. 50
    The method of Claim 28, wherein said encryption device permits any of private and shared mirror configurations.
  51. 51
    The method of Claim 28, wherein said encryption device permits selective remote client data access.
  52. 52
    The method of Claim 28, wherein said encryption device permits a failover configuration in connection with encryption and decryption of storage device related traffic.
  53. 53
    The method of Claim 28, wherein said encryption device transparently forwards traffic that is not storage related.
  54. 54
    An encryption based security method for network storage, comprising the steps of:providing an encryption device, located in a network, on a path between one or more client devices and one or more storage devices;separating access to said one or more storage devices via said one or more client devices from access to client data stored on said one or more storage devices;said encryption device comprising at least two network interfaces, comprising a clear text network interface that is connected to said one or more clients;and a secure network interface that is connected to said one or more storage devices;wherein each network interface supports multiple network nodes;wherein said encryption device encrypts all client data that is stored on said one or more storage devices.
Independent claims54