Invention Grant
- Patent Title: Authenticated device-based storage operations
-
Application No.: US14569038Application Date: 2014-12-12
-
Publication No.: US09729524B1Publication Date: 2017-08-08
- Inventor: Eric Jason Brandwine , Gregory Branchek Roth
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US WA Seattle
- Assignee: AMAZON TECHNOLOGIES, INC.
- Current Assignee: AMAZON TECHNOLOGIES, INC.
- Current Assignee Address: US WA Seattle
- Agency: Hogan Lovells US LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; H04L29/06 ; H04L9/32

Abstract:
Data storage operation commands are digitally signed to enhance data security in a distributed system. A data storage client and a compute-enabled data storage device may share access to a cryptographic key. The data storage client uses the cryptographic key to digitally sign commands transmitted to the data storage device, which can use its copy to verify a digital signature of a command before fulfilling the command. The storage device can also determine whether to perform a transformation, such that requests authenticated to a first identity might receive cleartext while a request authenticated to a second identity might receive ciphertext. The compute-enabled storage device can also receive unauthenticated calls and attempt to retrieve the appropriate key from a key management service or other such source.
Information query