Outer Rim Archives
Archives · 2024 · 20240291808

Application (pre-grant publication)

CENTRALLY MANAGED REMOTE STORAGE ENCRYPTION AND DECRYPTION

Number
20240291808
Published
2024-08-29
Filed
2023-02-23
Assignee
Lucasfilm Entertainment Company Ltd. LLC
Inventors
Aitken; Francis et al.
CPC
H04L63/0435; H04L63/0428; H04L67/1097; H04L63/0272
Verdict
Set aside storage encryption, IT security
Source
Google Patents · FreePatentsOnline

Abstract

Techniques are disclosed for centrally managing remote storage encryption and decryption. In some embodiments, to access an encrypted volume on a storage device connected to a computing device, a virtual private network (VPN) client authenticates a user of the computing device to a VPN. After authenticating the user and establishing a VPN connection, the VPN client launches a key management system (KMS) client that authenticates the user and requests an encryption key from a KMS server based on the user, a volume identifier (ID) of the encrypted volume, and a storage device ID of the storage device. The KMS server verifies that the user is allowed to access the encrypted volume having the volume ID, and that the encrypted volume is stored on the storage device having the storage device ID. Upon verification, the KMS server transmits the encryption key to the KMS client for decrypting the encrypted volume.

Background

Embodiments of the present disclosure relate generally to computer storage and encryption and, more specifically, to centrally managed remote storage encryption and decryption. DESCRIPTION OF THE RELATED ART

Users are increasingly working from remote computing devices that are located outside the traditional premises of firms. Oftentimes, high performance access to the same data that is available at the traditional premises is required to retain efficiency when working from a remote computing device.

One conventional approach for providing high performance and secure access to data is to store the data within an encrypted volume on a storage device. The storage device is given to a user, who can connect the storage device to a remote computing device and decrypt the encrypted volume using an encryption key or associated password. Once decrypted, data on the decrypted volume can be accessed and modified by the user.

One drawback of the above approach to providing high performance and secure access to data is anyone having knowledge of the encryption key or associated password can decrypt the encrypted volume and access data stored therein, which presents a security risk. Another drawback of the above approach is that access to data stored within the encrypted volume cannot be easily revoked when a user having knowledge of the encryption key or associated password should no longer be allowed to access such data.

As the foregoing illustrates, w

Claims

1. A computer-implemented method for decrypting an encrypted volume, the method comprising: identifying an encrypted volume stored on a storage device; requesting, from a server, an encryption key based on a user, an identifier (ID) associated with the encrypted volume, and an ID associated with the storage device; and decrypting the encrypted volume based on the encryption key. || 10. One or more non-transitory computer-readable storage media including instructions that, when executed by at least one processor, cause the at least one processor to perform steps for decrypting an encrypted volume, the steps comprising: identifying an encrypted volume stored on a storage device; requesting, from a server, an encryption key based on a user, an identifier (ID) associated with the encrypted volume, and an ID associated with the storage device; and decrypting the encrypted volume based on the encryption key. || 19. A system, comprising: one or more memories storing instructions; and one or more processors that are coupled to the one or more memories and, when executing the instructions, are configured to: identify an encrypted volume stored on a storage device, request, from a server, an encryption key based on a user, an identifier (ID) associated with the encrypted volume, and an ID associated with the storage device, and decrypt the encrypted volume based on the encryption key.