JP5117748B2

Storage virtualization apparatus comprising encryption functions

Abstract

This record has no abstract on file.

JP5117748B2, drawing sheet 1
Sheet 1 of 5

Term

Projected expiry 29 March 2027.

  1. Priority and filed
  2. Granted
  3. Today
  4. Projected expiry

7 claims: 3 independent, 4 dependent

  1. 1
    A device connected to a first external storage subsystem, which is an external first storage subsystem, and a second external storage subsystem, which is a second external storage subsystem. A storage virtualization unit that provides the first external logical volume of the first external storage subsystem as its own logical volume to a higher-level device, an encryption processing unit that encrypts data, and the encryption processing unit encrypts data. An encryption key registration unit that registers an encryption key, which is an electronic key used for conversion, in a storage area, a cache area, and an upper interface unit that is an interface to a higher-level device and receives a data write request from the higher-level device. The external interface unit, which is an interface to the external storage subsystem, the cache unit that stores the data received by the upper interface unit and / or the external interface unit in the cache area, and the received write request are specified. A determination unit that first determines whether or not the first external storage subsystem having the first external logical volume has the first encryption function, If the result of the first determination is affirmative, a write request for writing the data to the first external logical volume without having the encryption processing unit encrypt the data on the cache area is requested. By transmitting to the first external storage subsystem through the external interface unit, while the result of the first determination is negative, the data on the cache area is encrypted by the encryption processing unit. An I / O processing unit and the first external storage subsystem that generate encrypted data and transmit a write request for writing the encrypted data to the first external logical volume to the first external storage subsystem through the external interface unit. A migration processing unit that executes a migration process for migrating the data stored in the external logical volume of the second external storage subsystem to the second external logical volume of the second external storage subsystem is provided.At the time of the migration process, the first encryption function acquires an encryption key used for encrypting data from the first external storage subsystem, and the acquired encryption key is obtained by the encryption key registration unit. Register in storage area In the migration process, the determination unit makes a second determination as to whether or not the second external storage subsystem has a second encryption function. The migration processing unit may:(A) if the result of the second determination is affirmative, (a1) if the first external storage subsystem has the first encryption function, the first The data obtained by decrypting the encrypted data stored in the external logical volume of the first external logical volume by the first encryption function is received from the first external storage subsystem, while the first external When the storage subsystem does not have the first encryption function, the encrypted data stored in the first external logical volume is received from the first external storage subsystem, and the encryption key of the storage area is received. To decrypt the encrypted data using the above, (a2) transmit the encryption key of the storage area to the second external storage subsystem, and of the first external logical volume. The data obtained by decrypting the encrypted data in (a1) is transmitted to the second external storage subsystem without being encrypted by the encryption processing unit, whereby the second encryption is performed. The decrypted data is encrypted by the encryption function using the transmitted encryption key, and (B) if the result of the second determination is negative, (b1) the first external storage. When the subsystem has the first encryption function, the data obtained by decrypting the encrypted data stored in the first external logical volume by the first encryption function is used. Encrypted data received from the first external storage subsystem, while stored in the first external logical volume if the first external storage subsystem does not have the first encryption function. Is received from the first external storage subsystem, and the encryption processing unit is made to decrypt the encrypted data using the encryption key of the storage area, and (b2) of the first external logical volume. The data obtained by decrypting the encrypted data in (b1) is encrypted by the encryption processing unit using the encryption key of the storage area, and the encrypted data obtained by the encryption is used as described above. Second outsideA storage virtualization device that transmits to a unit storage subsystem, and the storage virtualization unit provides the second external logical volume as its own logical volume to a higher-level device after at least the migration process is completed. 外部に存在する第一のストレージサブシステムである第一の外部ストレージサブシステムと外部に存在する第二のストレージサブシステムである第二の外部ストレージサブシステムとに接続された装置であって、 前記第一の外部ストレージサブシステムが有する第一の外部論理ボリュームを自分の論理ボリュームとして上位装置に提供するストレージ仮想化部と、 データを暗号化する暗号処理部と、 前記暗号処理部がデータの暗号化に使用した電子的な鍵である暗号鍵を記憶領域に登録する暗号鍵登録部と、 キャッシュ領域と、 上位装置に対するインタフェースであって、前記上位装置からデータのライト要求を受信する上位インタフェース部と、 外部ストレージサブシステムに対するインタフェースである外部インタフェース部と、 前記上位インタフェース部及び/又は前記外部インタフェース部で受信したデータを前記キャッシュ領域に記憶させるキャッシュ部と、 前記受信したライト要求で指定されている第一の外部論理ボリュームを有する第一の外部ストレージサブシステムに第一の暗号化機能が有るか否かの第一の判定を行う判定部と、 前記第一の判定の結果が肯定的であれば、前記キャッシュ領域上のデータを前記暗号処理部に暗号化させることなく、そのデータを前記第一の外部論理ボリュームに書込むことのライト要求を前記外部インタフェース部を通じて前記第一の外部ストレージサブシステムに送信し、一方、前記第一の判定の結果が否定的であれば、前記キャッシュ領域上のデータを前記暗号処理部に暗号化させることで暗号データを生成させ、その暗号データを前記第一の外部論理ボリュームに書込むことのライト要求を前記外部インタフェース部を通じて前記第一の外部ストレージサブシステムに送信するI/O処理部と 前記第一の外部論理ボリュームに記憶されているデータを前記第二の外部ストレージサブシステムが有する第二の外部論理ボリュームに移行する移行処理を実行する移行処理部とを備え、前記移行処理の際、前記第一の暗号化機能は、データの暗号化に使用した暗号鍵を前記第一の外部ストレージサブシステムから取得し、その取得した暗号鍵を前記暗号鍵登録部により前記記憶領域に登録し、 前記判定部は、前記移行処理において、前記第二の外部ストレージサブシステムが第二の暗号化機能を有するか否かの第二の判定を行い、 前記移行処理部は、(A)前記第二の判定の結果が肯定的の場合、(a1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化することを前記暗号処理部に実行させ、(a2)前記記憶領域の暗号鍵を前記第二の外部ストレージサブシステムに送信し、前記第一の外部論理ボリュームの暗号データが前記(a1)において復号化されることにより得られたデータを、前記暗号処理部に暗号化させることなく前記第二の外部ストレージサブシステムに送信し、それにより、前記第二の暗号化機能に、前記送信された暗号鍵を用いて、前記復号化されたデータを暗号化させ、(B)前記第二の判定の結果が否定的の場合、(b1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化することを前記暗号処理部に実行させ、(b2)前記第一の外部論理ボリュームの暗号データが前記(b1)において復号化されることにより得られたデータを、前記記憶領域の暗号鍵を用いて前記暗号処理部に暗号化させ、該暗号化により得られた暗号データを、前記第二の外部ストレージサブシステムに送信し、 前記ストレージ仮想化部は、少なくとも前記移行処理の完了した後、前記第二の外部論理ボリュームを自分の論理ボリュームとして上位装置に提供するストレージ仮想化装置。
  2. 6
    The storage virtualization device includes a storage virtualization device, a first external storage subsystem having a first external logical volume, and a second external storage subsystem having a second external logical volume. A storage virtualization unit that provides the first external logical volume as its own logical volume to a higher-level device, an encryption processing unit that encrypts data, and an electronic key used by the encryption processing unit to encrypt data. An encryption key registration unit that registers a certain encryption key in a storage area, a cache area, an interface to a higher-level device, a higher-level interface unit that receives a data write request from the higher-level device, and an interface to an external storage subsystem. It has an external interface unit, a cache unit that stores data received by the upper interface unit and / or the external interface unit in the cache area, and a first external logical volume specified by the received write request. A determination unit that first determines whether or not the first external storage subsystem has the first encryption function, If the result of the first determination is affirmative, a write request for writing the data to the first external logical volume without having the encryption processing unit encrypt the data on the cache area is requested. By transmitting to the first external storage subsystem through the external interface unit, while the result of the first determination is negative, the data on the cache area is encrypted by the encryption processing unit. An I / O processing unit and the first external storage subsystem that generate encrypted data and transmit a write request for writing the encrypted data to the first external logical volume to the first external storage subsystem through the external interface unit. It is equipped with a migration processing unit that executes migration processing to migrate the data stored in the external logical volume ofAt the time of the migration process, the first encryption function acquires an encryption key used for encrypting data from the first external storage subsystem, and the acquired encryption key is obtained by the encryption key registration unit. Register in storage area The determination unit makes a second determination as to whether or not the second external storage subsystem has a second encryption function, and the migration processing unit makes a positive result of the second determination. Control the migration process based on whether it is present or negative The migration processing unit may:(A) if the result of the second determination is affirmative, (a1) if the first external storage subsystem has the first encryption function, the first The data obtained by decrypting the encrypted data stored in the external logical volume of the first external logical volume by the first encryption function is received from the first external storage subsystem, while the first external When the storage subsystem does not have the first encryption function, the encrypted data stored in the first external logical volume is received from the first external storage subsystem, and the encryption key of the storage area is received. To decrypt the encrypted data using the above, (a2) transmit the encryption key of the storage area to the second external storage subsystem, and of the first external logical volume. The data obtained by decrypting the encrypted data in (a1) is transmitted to the second external storage subsystem without being encrypted by the encryption processing unit, whereby the second encryption is performed. The decrypted data is encrypted by the encryption function using the transmitted encryption key, and (B) if the result of the second determination is negative, (b1) the first external storage. When the subsystem has the first encryption function, the data obtained by decrypting the encrypted data stored in the first external logical volume by the first encryption function is used. Encrypted data received from the first external storage subsystem, while stored in the first external logical volume if the first external storage subsystem does not have the first encryption function. Is received from the first external storage subsystem, and the encryption processing unit is made to decrypt the encrypted data using the encryption key of the storage area, and (b2) of the first external logical volume. The data obtained by decrypting the encrypted data in (b1) is encrypted by the encryption processing unit using the encryption key of the storage area, and the encrypted data obtained by the encryption is used as described above. Second outsideA storage system that transmits to a storage subsystem, and the storage virtualization unit provides the second external logical volume as its own logical volume to a higher-level device after at least the migration process is completed. ストレージ仮想化装置と、 第一の外部論理ボリュームを有する第一の外部ストレージサブシステムと、 第二の外部論理ボリュームを有する第二の外部ストレージサブシステムとを備え、 前記ストレージ仮想化装置が、前記第一の外部論理ボリュームを自分の論理ボリュームとして上位装置に提供するストレージ仮想化部と、 データを暗号化する暗号処理部と、 前記暗号処理部がデータの暗号化に使用した電子的な鍵である暗号鍵を記憶領域に登録する暗号鍵登録部と、 キャッシュ領域と、 上位装置に対するインタフェースであって、前記上位装置からデータのライト要求を受信する上位インタフェース部と、 外部ストレージサブシステムに対するインタフェースである外部インタフェース部と、 前記上位インタフェース部及び/又は前記外部インタフェース部で受信したデータを前記キャッシュ領域に記憶させるキャッシュ部と、 前記受信したライト要求で指定されている第一の外部論理ボリュームを有する第一の外部ストレージサブシステムに第一の暗号化機能が有るか否かの第一の判定を行う判定部と、 前記第一の判定の結果が肯定的であれば、前記キャッシュ領域上のデータを前記暗号処理部に暗号化させることなく、そのデータを前記第一の外部論理ボリュームに書込むことのライト要求を前記外部インタフェース部を通じて前記第一の外部ストレージサブシステムに送信し、一方、前記第一の判定の結果が否定的であれば、前記キャッシュ領域上のデータを前記暗号処理部に暗号化させることで暗号データを生成させ、その暗号データを前記第一の外部論理ボリュームに書込むことのライト要求を前記外部インタフェース部を通じて前記第一の外部ストレージサブシステムに送信するI/O処理部と 前記第一の外部論理ボリュームに記憶されているデータを第二の外部論理ボリュームに移行する移行処理を実行する移行処理部とを備え、前記移行処理の際、前記第一の暗号化機能は、データの暗号化に使用した暗号鍵を前記第一の外部ストレージサブシステムから取得し、その取得した暗号鍵を前記暗号鍵登録部により前記記憶領域に登録し、 前記判定部は、前記第二の外部ストレージサブシステムが第二の暗号化機能を有するか否かの第二の判定を行い、 前記移行処理部は、前記第二の判定の結果が肯定的であるか否定的であるかに基づいて、前記移行処理を制御し、 前記移行処理部は、(A)前記第二の判定の結果が肯定的の場合、(a1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化することを前記暗号処理部に実行させ、(a2)前記記憶領域の暗号鍵を前記第二の外部ストレージサブシステムに送信し、前記第一の外部論理ボリュームの暗号データが前記(a1)において復号化されることにより得られたデータを、前記暗号処理部に暗号化させることなく前記第二の外部ストレージサブシステムに送信し、それにより、前記第二の暗号化機能に、前記送信された暗号鍵を用いて、前記復号化されたデータを暗号化させ、(B)前記第二の判定の結果が否定的の場合、(b1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化することを前記暗号処理部に実行させ、(b2)前記第一の外部論理ボリュームの暗号データが前記(b1)において復号化されることにより得られたデータを、前記記憶領域の暗号鍵を用いて前記暗号処理部に暗号化させ、該暗号化により得られた暗号データを、前記第二の外部ストレージサブシステムに送信し、 前記ストレージ仮想化部は、少なくとも前記移行処理の完了した後、前記第二の外部論理ボリュームを自分の論理ボリュームとして上位装置に提供するストレージシステム。
  3. 7
    Control of storage virtualization devices connected to the first external storage subsystem, which is the first external storage subsystem, and the second external storage subsystem, which is the second external storage subsystem. The first method is to store the data according to the write request received from the host device in the cache area and to the first external storage subsystem having the first external logical volume specified by the received write request. The first determination as to whether or not there is an encryption function is performed, and if the result of the first determination is affirmative, the data on the cache area is encrypted by the encryption function of the storage virtualization device. If the data on the cache area is transmitted from the storage virtualization device to the first external storage subsystem and the result of the first determination is negative, the data on the cache area is used by the encryption key of the storage area. And the encrypted data obtained by the encryption is transmitted to the first external storage subsystem.When executing the migration process of migrating the data stored in the first external logical volume to the second external logical volume,The encryption key used by the first encryption function to encrypt the data is acquired from the first external storage subsystem, and the acquired encryption key is registered. A second determination is made as to whether or not the second external storage subsystem has a second encryption function, and (A) if the result of the second determination is affirmative, (a1) the first determination. When the external storage subsystem of the above has the first encryption function, it is obtained by decrypting the encrypted data stored in the first external logical volume by the first encryption function. Data is received from the first external storage subsystem, while if the first external storage subsystem does not have the first encryption function, it is stored in the first external logical volume. The encrypted data is received from the first external storage subsystem, the encrypted data is decrypted using the encryption key of the storage area, and (a2) the encryption key of the storage area is used by the second external storage subsystem. And the data obtained by decrypting the encrypted data of the first external logical volume in (a1) is transmitted to the second external storage subsystem without encryption. The second encryption function is used to encrypt the decrypted data by using the transmitted encryption key. (B) If the result of the second determination is negative, (b1) If the first external storage subsystem has the first encryption function, it is stored in the first external logical volume. The data obtained by decrypting the encrypted data by the first encryption function is received from the first external storage subsystem, while the first external storage subsystem receives the first. When there is no one encryption function, the encrypted data stored in the first external logical volume is received from the first external storage subsystem, and the encrypted data is received by using the encryption key of the storage area. (B2) The data obtained by decrypting the encrypted data of the first external logical volume in (b1) is encrypted using the encryption key of the storage area, and the encryption is performed. The encrypted data obtained by the above-mentioned second external storage subsystem is transmitted to the second external storage subsystem, and after at least the migration processing of (A) and (B) is completed, the second external logical volume is transferred to the storage virtualization device. A storage control method that is provided to the host device as a logical volume of. 外部に存在する第一のストレージサブシステムである第一の外部ストレージサブシステムと外部に存在する第二のストレージサブシステムである第二の外部ストレージサブシステムとに接続されたストレージ仮想化装置の制御方法であって、 上位装置から受信したライト要求に従うデータをキャッシュ領域に記憶させ、 前記受信したライト要求で指定されている第一の外部論理ボリュームを有する第一の外部ストレージサブシステムに第一の暗号化機能が有るか否かの第一の判定を行い、 前記第一の判定の結果が肯定的であれば、前記キャッシュ領域上のデータを前記ストレージ仮想化装置の暗号化機能で暗号化すること無く前記ストレージ仮想化装置から前記前記第一の外部ストレージサブシステムに送信し、 前記第一の判定の結果が否定的であれば、前記キャッシュ領域上のデータを前記記憶領域の暗号鍵を用いて暗号化し、その暗号化により得られた暗号データを、前記第一の外部ストレージサブシステムに送信し、前記第一の外部論理ボリュームに記憶されているデータを第二の外部論理ボリュームに移行する移行処理を実行する際に、前記第一の暗号化機能がそのデータの暗号化に使用した暗号鍵を前記第一の外部ストレージサブシステムから取得し、その取得した暗号鍵を登録し、 前記第二の外部ストレージサブシステムが第二の暗号化機能を有するか否かの第二の判定を行い、 (A)前記第二の判定の結果が肯定的の場合、(a1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化し、(a2)前記記憶領域の暗号鍵を前記第二の外部ストレージサブシステムに送信し、前記第一の外部論理ボリュームの暗号データが前記(a1)において復号化されることにより得られたデータを、暗号化することなく前記第二の外部ストレージサブシステムに送信し、それにより、前記第二の暗号化機能に、前記送信された暗号鍵を用いて、前記復号化されたデータを暗号化させ、 (B)前記第二の判定の結果が否定的の場合、(b1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化し、(b2)前記第一の外部論理ボリュームの暗号データが前記(b1)において復号化されることにより得られたデータを、前記記憶領域の暗号鍵を用いて暗号化し、該暗号化により得られた暗号データを、前記第二の外部ストレージサブシステムに送信し、 少なくとも前記(A)及び(B)の移行処理の完了した後、前記第二の外部論理ボリュームを前記ストレージ仮想化装置の論理ボリュームとして上位装置に提供する記憶制御方法。