US20200342117A1

Backups of file system instances with root object encrypted by metadata encryption key

Claim Score by NHIP

Read claim 9, the broadest

Abstract

Example implementations relate to encrypting data objects. In an example, data objects of a file system instance contained by a security domain are encrypted using a Data Encryption Key that is specific to the security domain and is wrapped by a Key Encryption Key shared exclusively within a cluster. A root object of the file system instance is encrypted using a Metadata Encryption Key. A backup of the file system instance is created on a backup node. The Data Encryption Key and the Metadata Encryption Key are sent to the backup node.

US20200342117A1, drawing sheet 1
Sheet 1 of 13

Term

13.4 yearsto projected expiry

Projected expiry 26 February 2040, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

20 claims: 3 independent, 17 dependent

  1. 1
    A system belonging to a cluster, the system comprising:a processing resource;and a machine readable medium storing instructions that, when executed by the processing resource, cause the processing resource to: encrypt data objects of a file system instance to generate encrypted data objects using a data encryption key (DEK) specific to a security domain containing the file system instance, the DEK being wrapped by a key encryption key (KEK) shared exclusively within the cluster, and the file system instance hierarchically relating the encrypted data objects located at a leaf level to a first root object through references to signatures of the encrypted data objects, encrypt the first root object using a first metadata encryption key (MEK), create on a node a backup of the file system instance comprising at least some of the encrypted data objects, and send the DEK and the first MEK to the node with the backup.
  2. 9
    Broadest claimClaim Score 49, average(NHIP)A method comprising:encrypting, by a processing resource of a node in a cluster, data objects of a file system instance to generate encrypted data objects using a data encryption key (DEK) specific to a security domain containing the file system instance, the DEK being wrapped by a key encryption key (KEK) shared exclusively within the cluster, and the file system instance hierarchically relating the encrypted data objects located at a leaf level to a first root object through references to signatures of the encrypted data objects;encrypting, by the processing resource, the first root object using a first metadata encryption key (MEK) that is wrapped by the DEK and is specific to the first root object to generate an encrypted first root object;creating, by the processing resource, a backup of the file system instance on another node comprising at least some of the encrypted data objects;and sending the DEK and the first MEK to the other node with the backup.
  3. 15
    A non-transitory machine readable medium storing instructions executable by processing resource of a computing system, the non-transitory machine readable medium comprising:instructions to encrypt data objects of a file system instance to generate encrypted data objects using a data encryption key (DEK) specific to a security domain containing the file system instance, the DEK being wrapped by a key encryption key (KEK) shared exclusively within a cluster to which the computing system belongs, and the file system instance hierarchically relating the encrypted data objects located at a leaf level to a first root object through references to signatures of the encrypted data objects;instructions to encrypt the first root object using a first metadata encryption key (MEK) that is wrapped by the DEK and is specific to the first root object;instructions to create a backup of the file system instance on another computing system comprising at least some of the encrypted data objects;and instructions to send the DEK and the first MEK to the other computing system with the backup.