Nova Patents
EP2645673A2

Storage device and its control method

Abstract

Provided is a storage device which partitions data from a host into multiple partitioned data and distributes, encrypts and stores them together with a parity to and in multiple memory mediums. This storage device executes processing of restoring the partitioned data or the parity stored in a memory medium to be subject to encryption re-key based on decrypted data of the partitioned data or the parity stored in each memory medium other than the memory medium to be subject to encryption re-key among the multiple memory mediums, storing the restored partitioned data or the parity in a backup memory medium while encrypting the restored partitioned data or the parity with a new encryption key, and thereafter interchanging the backup memory medium and the memory medium to be subject to encryption re-key so that the backup memory medium will be a memory medium configuring the parity group and the memory medium to be subject to encryption re-key will be the backup memory medium.

EP2645673A2, drawing sheet 1
Sheet 1 of 18

Term

Projected expiry 25 May 2029.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

12 claims: 2 independent, 10 dependent

  1. 1
    A storage device coupled to one or more host computers and a management computer, the storage device comprising a plurality of memory mediums including a backup memory medium, and a control unit arranged to encrypt data supplied from any of the one or more host computers by using a first encryption key and to store the encrypted data in a memory medium of the plurality of memory mediums; wherein the control unit is arranged to perform re-key processing by being configured:to determine whether the backup memory medium is usable or not, in accordance with an encryption key exchange command received from the management computer;to select a first memory medium to be an encryption key exchange target, from among the plurality of memory mediums other than the backup memory medium, according to a designation contained in the received encryption key exchange command;to decrypt data stored in the first memory medium by using the first encryption key;to encrypt the decrypted data with a second encryption key designated by the received encryption key exchange command;andto store the data encrypted with the second encryption key in the backup memory medium;andto swap the selected first memory medium and the backup memory medium, by setting the backup memory medium storing the data encrypted with the second encryption key as a memory medium of the memory mediums other than the backup memory medium, and setting the selected first medium as a new backup memory medium;wherein if the control unit determines that the new backup memory medium is not usable, then the control unit is configured to wait a predetermined period of time before repeating the determination, andif it is subsequently determined, after a predetermined number of repeats, that the new backup memory medium is not usable, then the control unit is configured to notify the management computer, from which the encryption key exchange command was received, that the encryption key exchange cannot be performed.
  2. 7
    A control method for a storage device coupled to one or more host computers and a management computer, the storage device comprising a plurality of memory mediums including a backup memory medium, and a control unit arranged to encrypt data supplied from any of the one or more host computers by using a first encryption key and to store the encrypted data in a memory medium of the plurality of memory mediums; wherein the control unit performs re-key processing including the steps of:determining whether the backup memory medium is usable or not, in accordance with an encryption key exchange command received from the management computer;selecting a first memory medium to be an encryption key exchange target, from among the plurality of memory mediums other than the backup memory medium, according to a designation contained in the received encryption key exchange command;decrypting data stored in the first memory medium by using the first encryption key;encrypting the decrypted data with a second encryption key designated by the received encryption key exchange command;andstoring the data encrypted with the second encryption key in the backup memory medium;andswapping the selected first memory medium and the backup memory medium, by setting the backup memory medium storing the data encrypted with the second encryption key as a memory medium of the memory mediums other than the backup memory medium, and setting the selected first medium as a new backup memory medium;wherein if the control unit determines that the new backup memory medium is not usable, then the control unit waits a predetermined period of time before repeating the determination, andif it is subsequently determined, after a predetermined number of repeats, that the new backup memory medium is not usable, then the control unit notifies the management computer, from which the encryption key exchange command was received, that the encryption key exchange cannot be performed.