Application (pre-grant publication)
CENTRALLY MANAGED REMOTE STORAGE ENCRYPTION AND DECRYPTION
- Number
- 20240291808
- Published
- 2024-08-29
- Filed
- 2023-02-23
- Assignee
- Lucasfilm Entertainment Company Ltd. LLC
- Inventors
- Aitken; Francis et al.
- CPC
- H04L63/0435; H04L63/0428; H04L67/1097; H04L63/0272
- Verdict
- Set aside storage encryption, IT security
- Source
- Google Patents · FreePatentsOnline
Abstract
Techniques are disclosed for centrally managing remote storage encryption and decryption. In some embodiments, to access an encrypted volume on a storage device connected to a computing device, a virtual private network (VPN) client authenticates a user of the computing device to a VPN. After authenticating the user and establishing a VPN connection, the VPN client launches a key management system (KMS) client that authenticates the user and requests an encryption key from a KMS server based on the user, a volume identifier (ID) of the encrypted volume, and a storage device ID of the storage device. The KMS server verifies that the user is allowed to access the encrypted volume having the volume ID, and that the encrypted volume is stored on the storage device having the storage device ID. Upon verification, the KMS server transmits the encryption key to the KMS client for decrypting the encrypted volume.
Background
Embodiments of the present disclosure relate generally to computer storage and encryption and, more specifically, to centrally managed remote storage encryption and decryption. DESCRIPTION OF THE RELATED ART
Users are increasingly working from remote computing devices that are located outside the traditional premises of firms. Oftentimes, high performance access to the same data that is available at the traditional premises is required to retain efficiency when working from a remote computing device.
One conventional approach for providing high performance and secure access to data is to store the data within an encrypted volume on a storage device. The storage device is given to a user, who can connect the storage device to a remote computing device and decrypt the encrypted volume using an encryption key or associated password. Once decrypted, data on the decrypted volume can be accessed and modified by the user.
One drawback of the above approach to providing high performance and secure access to data is anyone having knowledge of the encryption key or associated password can decrypt the encrypted volume and access data stored therein, which presents a security risk. Another drawback of the above approach is that access to data stored within the encrypted volume cannot be easily revoked when a user having knowledge of the encryption key or associated password should no longer be allowed to access such data.
As the foregoing illustrates, w