The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 31, 2022

Filed:

Nov. 09, 2018
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Eyal Rahamim, Tel Aviv, IL;

Alexander Snast, Rishon LeZion, IL;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/60 (2013.01); H04L 9/08 (2006.01); G06F 13/16 (2006.01); G06F 13/42 (2006.01); G06F 3/06 (2006.01); H04L 9/32 (2006.01); G06F 3/00 (2006.01); G06F 13/00 (2006.01);
U.S. Cl.
CPC ...
H04L 9/0822 (2013.01); G06F 3/00 (2013.01); G06F 3/0623 (2013.01); G06F 3/0659 (2013.01); G06F 3/0674 (2013.01); G06F 3/0679 (2013.01); G06F 13/00 (2013.01); G06F 13/1668 (2013.01); G06F 13/4282 (2013.01); G06F 21/602 (2013.01); H04L 9/0869 (2013.01); H04L 9/3242 (2013.01); G06F 2213/0042 (2013.01);
Abstract

A data security technique for a data storage system includes in response to connection of an external storage device to a port of the data storage system, retrieving an authentication key encryption key (AKEK) for the data storage system from the external storage device to the data storage system. A random wrapper key (RWK) is generated based on the AKEK and an encrypted random wrapper key (ERWK) for the data storage system (retrieved from a first key repository of the data storage system). The ERWK is retrieved from a first key repository of the data storage system. A master key (retrieved from a second key repository of the data storage system) is decrypted for the data storage system using the RWK. A device access key (DAK) is derived based on the master key. The DAK is used to encrypt/decrypt data for a drive associated with the DAK.


Find Patent Forward Citations

Loading…