发明授权
- 专利标题: Selective encryption system and method for I/O operations
- 专利标题(中): 选择性加密系统和I / O操作方法
-
申请号: US10448825申请日: 2003-05-30
-
公开(公告)号: US07428636B1公开(公告)日: 2008-09-23
- 发明人: Carl A. Waldspurger , Matthew Eccleston
- 申请人: Carl A. Waldspurger , Matthew Eccleston
- 申请人地址: US CA Palo Alto
- 专利权人: VMware, Inc.
- 当前专利权人: VMware, Inc.
- 当前专利权人地址: US CA Palo Alto
- 代理商 Jeffrey Pearce
- 主分类号: H04L9/00
- IPC分类号: H04L9/00
摘要:
Upon occurrence of a trigger condition, writes of allocation units of data (including code) to a device, such as writes of blocks to a disk, are first encrypted. Each allocation unit is preferably a predetermined integral multiple number of minimum I/O units. A data structure is marked to indicate which units are encrypted. Upon reads from the device, only those allocation units marked as encrypted are decrypted. The disk protected by selective encryption is preferably the virtual disk of a virtual machine (VM). The trigger condition is preferably either that the virtual disk has been initialized or that the VM has been powered on. Mechanisms are also provided for selectively declassifying (storing in unencrypted form) already-encrypted, stored data, and for determining which data units represent public, general-use data units that do not need to be encrypted. The “encrypt-on-write” feature of the invention may be used in conjunction with a “copy-on-write” technique.
信息查询