Blockchain-implemented data migration audit trail
By introducing blockchain technology into the data migration system, a secure ledger was solved, and the problem of lack of security tracking and verification mechanisms in the existing technology was solved, and a credible audit trajectory was realized to ensure that the progress and completion of data migration tasks could be safely tracked and verified.
Patent Information
- Application Number
- CN202111162643.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-10-08
- Filing Date
- 2021-09-30
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-09-30
AI Technical Summary
In existing data migration programs, there is a lack of a secure and tamper-proof mechanism to track and verify the execution progress and completion of end-to-end data migration tasks, especially when multiple stakeholders participate, trust problems and errors are prone to occur.
By leveraging blockchain technology, create a secure, tamper-proof ledger for storing and recording audit trajectories related to data migration events. The system includes generating a task list, assigning tasks, performing tasks, recording task details and recording them to digital assets, and ultimately recording these digital assets as blocks of the blockchain and distributing them to all nodes of the blockchain network.
A secure and trustworthy audit trajectory is realized, which can effectively track and verify the execution progress and completion of data migration tasks, solve the risks of trust problems and errors, and provide a tamper-proof record.
Smart Images

Figure CN114297174B_ABST
Abstract
Description
Background Art
[0001] The present disclosure relates generally to the field of blockchain storage, and more particularly to implementing a blockchain to securely store an audit trail describing data migration between data centers, computer networks, and / or cloud-based networks.
[0002] Data migration can refer to the process of moving data from one location to another, from one format to another, or from one application to another. The migration of data is usually the result of introducing a new system and / or location for data, while application migration or consolidation may be driven by a business decision to replace or expand a legacy system with a new application that can share the same data set. Currently, trends in data migration suggest that enterprises begin to migrate data from on-premiss infrastructure, data centers, and applications to cloud-based storage, services, and application delivery mechanisms. Some types of migration may include application migration, cloud migration, and storage migration. Application migration may refer to moving an application from one environment to another, from a local IT center to the cloud, between clouds (private, public, and / or hybrid), or moving the underlying data of an application to a new form of application hosted by a software provider. Similarly, cloud migration may refer to the process of moving data, applications, or other business elements from a local data center to the cloud or from one cloud to another. Finally, storage migration may include moving data from an existing storage array to a new storage array. Summary of the invention
[0003] Embodiments of the present disclosure relate to a computer-implemented method, associated computer system, and computer program product for implementing a blockchain for controlling access to a ledger including an audit trail, the audit trail comprising a digital asset describing tasks associated with the execution of a data migration event. The computer-implemented method includes: creating, by a processor, a task list configured to delegate one or more tasks for migrating data from a data migration source to a data migration target; assigning, by the processor, the one or more tasks to at least one party responsible for the execution of the assigned tasks to complete the migration of the data from the data migration source to the data migration target; executing, by the processor, the assigned tasks; recording, by the processor, details corresponding to the execution of the assigned tasks to a digital asset based on the execution of the assigned tasks; recording, by the processor, the digital asset as a block of a blockchain; and distributing, by the processor, a block of a blockchain describing the execution of the assigned tasks for migrating from a data migration source to a data migration target to all nodes of a blockchain network, wherein the block recorded to the blockchain updates the data migration audit trail implemented by the blockchain. BRIEF DESCRIPTION OF THE DRAWINGS
[0004] The accompanying drawings included in the present disclosure are incorporated into the specification and form a part of the specification. They illustrate embodiments of the present disclosure and together with the description explain the principles of the present disclosure. The accompanying drawings illustrate only certain embodiments and do not limit the present disclosure.
[0005] Figure 1 Depicted is an embodiment of a block diagram of internal and external components of a data processing system in which embodiments described herein may be implemented in accordance with the present disclosure.
[0006] Figure 2A A block diagram of an embodiment of a computing environment for executing a blockchain-implemented data migration audit trail in accordance with the present disclosure is depicted.
[0007] Figure 2B A block diagram of an alternative embodiment of a computing environment for implementing a blockchain-implemented data migration audit trail in accordance with the present disclosure is depicted.
[0008] Figure 3 An embodiment of a cloud computing environment in which the embodiments described herein may be implemented is depicted in accordance with the present disclosure.
[0009] Figure 4 Embodiments of abstract model layers of a cloud computing environment according to the present disclosure are depicted.
[0010] Figure 5A An example blockchain architecture according to an embodiment of the present disclosure is shown.
[0011] Figure 5B A blockchain transaction flow according to an embodiment of the present disclosure is shown.
[0012] Figure 6 An example of a peer node of a blockchain network and one or more contents thereof according to an embodiment of the present disclosure is shown.
[0013] Figure 7 A block diagram of an embodiment of a method for performing a blockchain-enabled data migration audit trail according to the present disclosure is depicted. DETAILED DESCRIPTION
[0014] The terms used herein are only used for the purpose of describing specific embodiments and are not intended to be limiting of the present disclosure. As used herein, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that the terms "include" and / or "comprise" when used in this specification specify the presence of stated features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or groups thereof.
[0015] All parts or steps in the attached claims plus the corresponding structures, materials, actions and equivalents of the functional elements are intended to include any structure, material or action for performing functions in combination with other claimed elements as specifically claimed. The description of the present disclosure has been presented for the purpose of illustration and description, but it is not intended to be exhaustive or limited to the disclosure of the disclosed form. Without departing from the scope and spirit of the present disclosure, many modifications and variations will be apparent to those of ordinary skill in the art. The selected and described embodiments are intended to best explain the principles of the present disclosure, practical applications, and to enable other persons of ordinary skill in the art to understand the present disclosure of various embodiments with various modifications, which are suitable for the particular use under consideration.
[0016] Overview
[0017] A data migration program may involve hundreds of tasks (or more) to be performed by multiple stakeholders, which may migrate hundreds of applications and workloads between traditional data centers and / or cloud networks (public or private). These stakeholders may be part of different entities, groups, organizations, businesses, or companies, and may often need to work together to complete the end-to-end tasks associated with a data migration event. The stakeholders may be part of an application team, which may be a customer and / or service provider, a third-party migration team that performs one or more migration services between a data migration source (such as a data center or cloud network) and a data migration target, as well as an infrastructure team associated with managing the data migration target and an administrative team for the customer and / or service provider.
[0018] Embodiments of the present disclosure recognize that current data migration procedures may involve manually tracking and updating timelines for completing one or more migration tasks, allowing one or more stakeholders to review the executed tasks within the planned timeline, verifying the completion of the tasks, and manually updating the timeline. However, when the process is manually performed by multiple stakeholders involved in the end-to-end data migration task, embodiments of the present disclosure also recognize key security challenges associated with stakeholders auditing the execution of the data migration task. As a result of multiple stakeholders who may be part of different entities, companies, organizations, etc., there may not be a single source of trust available for all stakeholders that can help each party involved in the data migration understand the progress and timeline of the completion of all end-to-end migration tasks. In the case where multiple stakeholders from multiple different affiliations input data into the planned migration timeline, one or more files that track the execution of the end-to-end data migration tasks may be prone to trust issues, manipulation, and errors. As a result, an auditor tracking the progress of the end-to-end migration of data may be left with an inadequately prepared audit trail without a single credible source of tracking information that can be used to monitor or understand the completion of the end-to-end migration task.
[0019] Embodiments of the present disclosure recognize the need for a secure, tamper-proof audit trail that stakeholders can use and trust when reviewing the end-to-end migration of data and for monitoring the progress of data migration tasks. Embodiments of the present disclosure utilize the use of blockchain to create a securely stored, tamper-proof ledger that includes an audit trail, wherein the audit trail created and updated describes the completion of the end-to-end migration task. The audit trail can be accessed by stakeholders responsible for auditing the completion of the data migration in order to track the tasks completed in a scheduled manner and ensure that the execution requirements of the data migration are met. Each of the event logs, records, and alarms from the server of the data migration source or target, including network device logs, operating system logs, user access logs, etc. associated with the end-to-end migration task and the output from the data migration tool, can be used as part of the audit trail and stored in the blocks of the blockchain network. Examples of blockchain networks can include peer-to-peer (P2p) networks. Across all nodes of the blockchain network, all event logs, alarms, or other assets recorded as blocks of the blockchain can be timestamped, hashed, and stored. Since entries are added to the blockchain as blocks, the entries are verified as valid by every node of the blockchain network, and blocks added to the blockchain network cannot be modified or tampered with.
[0020] One or more digital assets that may comprise an audit trail may be forwarded from respective monitoring servers, recording servers and / or output from the migration tool to a node of a blockchain network utilized by a blockchain platform that uses an application programming interface (API) function to execute application code to implement one or more blockchain transactions. Managers and / or auditors responsible for tracking the progress of the task may access and audit the blocks of the audit trail via the blockchain platform, query the (multiple) ledgers containing the audit trail, perform further analysis and / or use one or more blockchain applications and / or generate user-friendly reports from the ledger information. The generated reports may be viewed by clients connected to the blockchain platform, clients connected to a data migration source or a data migration target and / or other stakeholders to display the progress of the task to all teams or groups involved in the end-to-end data migration task. Thus, all participants and auditors of the end-to-end migration are allowed to observe a single, untampered source that describes the complete flow of end-to-end migration events.
[0021] Data processing system
[0022] The present invention may be a system, method and / or computer program product at any possible integrated technical detail level. The computer program product may include one or more computer-readable storage media (or media) having computer-readable program instructions thereon for causing a processor to implement various aspects of the present invention.
[0023] A computer-readable storage medium may be a tangible device capable of holding and storing instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a device such as a mechanical encoding of a convex structure in a punch card or a groove with instructions recorded thereon, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be interpreted as a temporary signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagated through a waveguide or other transmission medium (e.g., a light pulse passing through an optical fiber cable), or an electrical signal sent through a wire.
[0024] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a respective computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in a computer-readable storage medium within the respective computing / processing device.
[0025] The computer-readable program instructions for implementing the operation of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for an integrated circuit, or source code or object code written in any combination of one or more programming languages (including object-oriented programming languages, such as Smalltalk, C++, etc.) and procedural programming languages (such as "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or completely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider via the Internet). In some embodiments, in order to perform various aspects of the present invention, an electronic circuit including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may execute a computer-readable program instruction by utilizing the state information of the computer-readable program instructions to personalize the electronic circuit.
[0026] Various aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, devices (systems) and computer program products according to embodiments of the present invention. It will be understood that each block of the flowchart illustration and / or block diagram and the combination of blocks in the flowchart illustration and / or block diagram can be implemented by computer-readable program instructions.
[0027] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine, such that instructions such as those executed by a processor of a computer or other programmable data processing device create components for implementing the functions / actions specified in one or more boxes of a flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium, which can direct a computer, a programmable data processing device, and / or other equipment to work in a particular manner, such that the computer-readable storage medium having the instructions stored therein includes an article of manufacture, which includes instructions for implementing aspects of the functions / actions specified in one or more boxes of a flowchart and / or block diagram.
[0028] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device, so that a series of operating steps are performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, so that the instructions executed on the computer, other programmable apparatus, or other device implement the functions / actions specified in one or more boxes of the flowchart and / or block diagram.
[0029] The flow chart and block diagram in the accompanying drawings show the architecture, function and operation of the possible implementation of the system, method and computer program product according to various embodiments of the present invention.In this regard, each frame in the flow chart or block diagram can represent a module, segment or part of an instruction, which includes one or more executable instructions for realizing the logical function of (multiple) specifications.In some alternative embodiments, the function noted in the frame may not occur in the order noted in the figure.For example, the two frames shown in succession can actually be performed substantially simultaneously, or, depending on the function involved, these frames can sometimes be performed in reverse order.It will also be noted that the combination of each frame of the block diagram and / or flow chart illustration and the frame in the block diagram and / or flow chart illustration can be realized by a dedicated hardware-based system that performs a specified function or action or implements a combination of special hardware and computer instructions.
[0030] The description of various embodiments of the present invention has been given for the purpose of illustration, but it is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the present invention. The terms used herein are selected to best explain the principles of the embodiments, practical applications, or technical improvements to the technology found on the market, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.
[0031] Figure 1 1 shows a block diagram of a data processing system 10, which may be a simplified example of a computing system capable of performing one or more computing operations described herein. Data processing system 10 may represent Figure 2A-6 One or more computing systems or devices depicted in computing environments 200, 240, 300, 500, 550 according to embodiments of the present disclosure described herein. It should be understood that Figure 1 This is only an illustration of one implementation of data processing system 10 and does not imply any limitations with respect to the environments in which different embodiments may be implemented. Figure 1 The components shown in may represent any electronic device capable of executing machine-readable program instructions.
[0032] Although Figure 1An example of data processing system 10 is shown, but data processing system 10 may take many different forms, including real, virtual, and containerized forms. For example, data processing system 10 may take the form of a personal desktop computer system, a laptop computer, a notebook, a tablet computer, a server, a client, a network device, a terminal, a thin client, a fat client, a kiosk, a mobile communication device (e.g., a smart phone), an augmented reality (AR) device, a virtual reality (VR) headset, a multiprocessor system, a microprocessor-based system, a small computer system, a large computer system, a smart device (i.e., smart glasses, smart watches, etc.), an Internet of Things (IoT) device, etc. Data processing system 10 may operate in a network computing environment, a virtual computing environment, a containerized computing environment, a distributed cloud computing environment, a serverless computing environment, and / or a combination of environments thereof, which may include any of the systems or devices described herein and / or additional computing devices or systems known or used by those of ordinary skill in the art.
[0033] Data processing system 10 may include communications fabric 22 that may provide electronic communications between one or more processors 13, memory 15, persistent storage 16, cache 17, communications unit 21, and one or more input / output (I / O) interfaces 25. Communications fabric 22 may be implemented using any architecture designed to pass data and / or control information between processor 13, memory 15, cache 17, external devices 27, and any other hardware components within data processing system 10.
[0034] Memory 15 and permanent storage 16 may be computer-readable storage media. Embodiments of memory 15 may include random access memory (RAM) and cache 17 memory. In general, memory 15 may include any suitable volatile or non-volatile computer-readable storage media, and may include firmware or other software programmed into memory 15. Software program(s) 24, applications 107a, 107b (generally referred to herein as "applications 107"), workloads 109a, 109b (generally referred to herein as "workloads 109"), and services described herein may be stored in memory 15, cache 17, and / or permanent storage 16 for execution and / or access by one or more of the respective processors 13 of data processing system 10.
[0035] Persistent storage 16 may include a plurality of magnetic hard disk drives. Alternatively, or in addition to magnetic hard disk drives, permanent storage 16 may include one or more solid-state hard disk drives, semiconductor storage devices, read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, or any other computer-readable storage medium capable of storing program instructions or digital information. Embodiments of the media used by permanent storage 16 may also be removable. For example, a removable hard disk drive may be used for permanent storage 16. Other examples include optical and magnetic disks, thumb drives, and smart cards that are inserted into a drive for transfer to another computer-readable storage medium that is also part of permanent storage 16.
[0036] The communication unit 21 provides the convenience of electronic communication between the data processing systems 10. For example, electronic communication between one or more computer systems or devices via a communication network. In an exemplary embodiment, the communication unit 21 may include a network adapter or interface, such as a TCP / IP adapter card, a wireless Wi-Fi interface card or antenna, a 3G, 4G or 5G cellular network interface card or other wired or wireless communication link. The communication network may include, for example, copper wires, optical fibers, wireless transmissions, routers, firewalls, switches, gateway computers, edge servers and / or other network hardware that may be part of a node of a device, system, host, terminal or other network computer system of a communication network or connect the node. Software and data for practicing embodiments of the present invention may be downloaded to a computer system operating in a network environment via the communication unit 21 (e.g., via the Internet, a local area network or other wide area network). Data and software for (multiple) programs 24, applications 107, workloads 109 or services may be loaded from the communication unit 21 into the permanent storage 16, stored in the memory 15 and / or the cache memory 17.
[0037] One or more I / O interfaces 25 may allow input of data and output of data to other devices that may be connected to data processing system 10. For example, I / O interface 25 may provide a connection to one or more external devices 27, such as one or more IoT devices, a recording device such as an audio recording device, a microphone, a camera, one or more sensors, an input device such as a keyboard, a computer mouse, a touch screen, a virtual keyboard, a touch pad, a pointing device, or other human-computer interface devices. External device 27 may also include portable computer-readable storage media such as thumb drives, portable optical or magnetic disks, and memory cards. I / O interface 25 may be connected to a human-readable display device 28. Display device 28 provides a mechanism for displaying data to a user, and may be, for example, a computer monitor, a screen, a television, a projector, a display panel, etc. Display device 28 may also be a combined display, and may be used as a touch screen as part of a built-in display of a tablet computer or mobile computing device.
[0038] A system for executing a blockchain-enabled audit trail of data migration
[0039] Aspects of the present disclosure generally relate to the field of blockchain storage, and more specifically to implementing a blockchain to securely transmit evidence describing the completion of one or more tasks associated with an end-to-end data migration to a blockchain network's block, the evidence including evidence provided by application logs, operating system logs, user access logs, network device logs, and / or migration tools or other event records (collectively referred to herein as "assets" or "digital assets"), creating a secure ledger including an audit trail 129 that is trusted by each stakeholder performing one or more tasks of the end-to-end migration process. As the end-to-end migration process continues and eventually completes the transfer of data between networks, data centers, private clouds, and / or public clouds, managers and / or auditors responsible for overseeing and / or reviewing the completion of the end-to-end migration task 111 can access the audit data of the audit trail 129 stored on the blockchain network 130 by querying the ledger stored by the peer nodes 104-110 of the blockchain network 130. Auditors and managers can review the progress of the data migration, track the progress of one or more responsible parties assigned one or more tasks, analyze any errors, and securely verify that the transfer of data was successfully performed.
[0040] It is readily understood that the instant components, as generally described and illustrated in the figures herein, may be arranged and designed in a variety of different configurations. Therefore, the following detailed description of embodiments of at least one of the methods, apparatus, non-transitory computer-readable media, and systems, as represented in the figures, is not intended to limit the scope of the claimed application, but merely represents selected embodiments.
[0041] In one or more embodiments, the instant features, structures or characteristics described throughout this specification may be combined or removed in any appropriate manner. For example, throughout this specification, the use of the phrases "exemplary embodiments", "some embodiments" or other similar language refers to the fact that specific features, structures or characteristics described in conjunction with the embodiments may be included in at least one embodiment. Therefore, the phrases "exemplary embodiments", "in some embodiments", "in other embodiments" or other similar language appearing throughout this specification do not necessarily all refer to the same set of embodiments, and the described features, structures or characteristics may be combined or removed in any appropriate manner in one or more embodiments. In addition, in the accompanying drawings, any connection between elements may allow unidirectional and / or bidirectional communication, even if the described connection is a unidirectional arrow or a bidirectional arrow. Moreover, any device depicted in the figure may be a different device. For example, if a mobile device is shown as sending information, a wired device may also be used to send information.
[0042] In addition, although the term "message" can be used in the description of the embodiment, the application can be applied to many types of networks and data. In addition, although certain types of connections, messages and signaling can be described in exemplary embodiments, the application is not limited to certain types of connections, messages and signaling.
[0043] Described herein in detail are methods, systems, and computer program products for utilizing a blockchain / hyperledger fabric to securely create an audit trail 129 describing the progress and / or completion of one or more end-to-end data migration tasks 111 performed during a data migration between a data migration target, such as a target data center 125 or cloud network 250, and one or more migration data sources, such as a source data center 101 or cloud network 250 (public or private). Referring to the accompanying drawings, Figure 2A-6 Methods that can be performed using one or more data processing systems 10 operating within computing environments 200, 240, 300, 500, 550 and variations thereof to implement systems, methods, and computer program products for implementing a blockchain-implemented data migration audit trail 129 are depicted. Embodiments of computing environments 200, 240, 300, 500, 550 may include one or more data processing systems 10 interconnected as part of a computing network. The interconnected data processing systems 10 communicating on the computing network may be dedicated systems or devices, which may include, but are not limited to, interconnection of one or more data centers 101, 125 including a recording server 103 and / or a monitoring server 105; interconnection of client devices 119, 123, 127 and / or a blockchain platform 112 hosting a blockchain node 102 of a blockchain network 130.
[0044] Figure 2A-6The dedicated data processing system 10 shown in FIG. 1 may include not only Figure 2A-6 The elements of the systems and devices depicted in the drawings, and Figure 2A-6 The dedicated data processing system depicted in the Figure 1 One or more elements of the data processing system 10 shown in and described above. Although not shown in the figure, one or more elements of the data processing system 10 may be integrated into embodiments of the data center 101, 125, the recording server 103a, 103b, the monitoring server 105a, 105b, the client device 119, 123, 127, and the system hosting the blockchain platform 112 and / or the blockchain node 102 constituting the blockchain network 130, including (but not limited to) one or more processors 13, (multiple) programs 24, memory 15, permanent storage 16, cache memory 17, communication unit 21, input / output (I / O) interface 25, external device 27 and / or display device 28.
[0045] With reference to the accompanying drawings, Figure 2A-2B An example of a computing environment 200, 240 is depicted that is capable of executing a blockchain-implemented audit trail 129 to securely store and track the progress of an end-to-end migration task 111 (also referred to herein as task 111) as the task 111 is executed and completed, a deadline for completing the task 111 is missed or results in errors and / or alarms being output. Figure 2A-2B As shown, the end-to-end migration tasks 111 may include tasks that can be performed as part of a data migration procedure before data migration occurs (pre-migration tasks 113), tasks that are part of migrating data from a data migration source to a data migration target (migration tasks 115), and tasks that can be performed after completing the data migration to the data migration target (post-migration tasks 117).
[0046] like Figure 2A-2B As shown in the embodiment of the present invention, an example of data migration including migration of one or more applications 107 and / or workloads 109 can be performed as part of: from a data migration source (i.e., source data center 101) to a data migration target (i.e., Figure 2A The migration of the source data center 101 to the private or public cloud network 250 (such as Figure 2B and / or in some embodiments, migration from a first private or public cloud network 250 to a second private or public cloud network 250.
[0047] Cloud network 250 is a service delivery model for enabling convenient on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be quickly provisioned and released with minimal management effort or minimal interaction with the provider of the service. A cloud model may include at least five characteristics, at least three service models, and at least four deployment models.
[0048] Features are as follows:
[0049] On-demand self-service: Cloud consumers can unilaterally and automatically provision computing capabilities, such as server time and network storage, as needed without requiring manual interaction with the service provider.
[0050] Wide Area Network Access: Capabilities are available over the network and accessed through standard mechanisms that facilitate use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, smart devices, IoT devices, virtual assistant hubs, etc.).
[0051] Resource pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, where different physical and virtual resources are dynamically assigned and reassigned based on demand. There is a sense of location independence, as consumers typically do not control or know the exact location of the resources provided, but are able to specify the location at a higher level of abstraction (e.g., country, state, or data center).
[0052] Rapid Elasticity: Capacity can be provisioned quickly and elastically, in some cases automatically, to scale up quickly and release quickly to scale down quickly. To the consumer, the capacity available for provisioning often appears to be unlimited and can be purchased in any quantity at any time.
[0053] Metered Services: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both providers and consumers of the utilized services.
[0054] The service model is as follows:
[0055] Software as a Service (SaaS): The capability provided to consumers is to use the provider's applications running on a cloud infrastructure. The applications are accessible from a variety of client devices through a thin client interface such as a web browser (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure including the network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.
[0056] Platform as a Service (PaaS): The capability provided to consumers is to deploy applications created or acquired by consumers onto cloud infrastructure, where the applications are created using programming languages and tools supported by the provider. Consumers do not manage or control the underlying cloud infrastructure including networks, servers, operating systems, or storage, but have control over the deployed applications and possible configuration of the application hosting environment.
[0057] Infrastructure as a Service (IaaS): The capabilities provided to consumers are processing, storage, networking, and other basic computing resources on which consumers can deploy and run arbitrary software, which may include operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but have control over the operating system, storage, deployed applications, and control over possible restrictions on select networking components (e.g., host firewalls).
[0058] The deployment model is as follows:
[0059] Private Cloud: The cloud infrastructure is operated only for the organization. It can be managed by the organization or a third party and can exist on-premises or off-premises.
[0060] Community cloud: The cloud infrastructure is shared by several organizations and supports a specific community with shared concerns (e.g., mission, security requirements, policies, and compliance considerations). It can be managed by the organization or a third party and can exist on-premises or off-premises.
[0061] Public cloud: Cloud infrastructure is available to the general public or large industrial groups and is owned by an organization that sells cloud services.
[0062] Hybrid cloud: A cloud infrastructure is a combination of two or more clouds (private, community or public) that remain distinct(s) entities but are bound together by standardized or privatized technologies that enable data and application portability (e.g., cloud bursting for load balancing between clouds).
[0063] The cloud computing environment 300 is service-oriented with a focus on statelessness, low coupling, modularity, and semantic interoperability. At the core of cloud computing is the infrastructure of the cloud network 250 comprising interconnected nodes 310 .
[0064] With reference to the accompanying drawings, Figure 3 318a-318n that are connected or communicated with the nodes 310 of the cloud network 250. It should be understood that the types of client devices 318a-318n connected to the cloud computing environment 300 are intended to be illustrative only, and the computing nodes 310 of the cloud computing environment 300 can communicate with any type of computerized device on any type of network and / or network addressable connection (e.g., using a web browser).
[0065] Reference now Figure 4 , shows a set of functional abstraction layers provided by the cloud computing environment 300. It should be understood in advance that Figure 4 The components, layers, and functions shown in are intended to be illustrative only, and embodiments of the present invention are not limited thereto. As depicted, the following layers and corresponding functions are provided:
[0066] The hardware and software layer 460 includes hardware and software components. Examples of hardware components include mainframes 461; servers 462 based on RISC (Reduced Instruction Set Computer) architecture; servers 463, including recording servers 103 and monitoring servers; blade servers 464; storage devices 465; and network and networking components 466. In some embodiments, software components include network application server software 467 and database software 468.
[0067] Virtualization layer 470 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual servers 471 ; virtual storage 472 ; virtual networks 473 , including virtual private networks; virtual applications and operating systems 474 ; and virtual clients 475 .
[0068] In one example, the management layer 480 may provide the functionality described below. Resource provisioning 481 provides dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment 300. Metering and pricing 482 provides cost tracking when resources are utilized within the cloud computing environment 300, as well as billing or invoicing for the consumption of these resources. In one example, these resources may include application software licenses. Security provides authentication for cloud consumers and tasks, as well as protection for data and other resources. User portal 483 provides access to the cloud computing environment 300 for consumers and system administrators. Service level management 484 provides cloud computing resource allocation and management so that the required service levels are met. Service level agreement (SLA) planning and fulfillment 485 provides pre-scheduling and procurement of cloud computing resources for its expected future needs according to the SLA.
[0069] The workload layer 490 provides examples of functionality for which a cloud computing environment may be utilized. Examples of workloads 109 and functionality that may be provided from this layer include software development and lifecycle management 491, data analytics processing 492, virtual classroom education delivery 493, transaction processing 494, blockchain applications 124, and / or APIs 122 for accessing and communicating with peer nodes 104-110 of a blockchain platform 112. For example, the applications 124 and / or APIs 122 are used to invoke chaincodes / smart contracts (discussed in detail below) to propose updated blocks to be added to the blockchain and / or query ledgers stored by peer nodes 104-110 including an audit trail 129.
[0070] With reference to the accompanying drawings, Figure 2A-2B A block diagram of an example of a computing environment 200, 240 capable of creating, storing, and / or updating a ledger on a blockchain including an audit trail 129 using a blockchain network 130 is depicted. An embodiment of the audit trail 129 may be generated for the purpose of tracking and monitoring the progress of a task 111 associated with migrating data from a data migration source to a data migration target. As shown in the example of the computing environment 200, the computing environment 200 may include a data migration source (i.e., a source data center 101) that may store and maintain data selected to be transferred or copied to another location within the computing environment and / or network. For example, the transfer of one or more applications 107a, workloads 109a, and virtual devices and systems hosted by the data migration source, including servers 103a, 105a, virtual devices, storage, containers, etc.
[0071] The stakeholders who are selecting to perform a data migration event and the complexity of the data migration event may vary depending on the type of data migration that may be occurring. For example, in some embodiments, an owner or service provider of an application 107a hosted by a source data center 101 may be selecting to migrate the application 107a or workload 109a and associated data hosted by the source data center 101 to a new location, such as a target data center 125 or cloud network 250. In other embodiments, an owner or manager of a migration data source, such as the owner of a source data center 101, may decide to upgrade a data center, migrate from a legacy system to a public or private cloud network 250, and / or migrate from a private cloud to a public cloud (or vice versa). As a result of the owner or manager of a data center 101, 125, and / or cloud network 250 deciding to migrate to a new infrastructure or a new location, the resulting migration may migrate all applications 107a, workloads 109a, servers, virtual clients, and hosted data to a new target location.
[0072] Stakeholders requesting and / or coordinating the migration of data from a data migration source to a data migration target may develop a schedule for completing one or more of the end-to-end migration tasks 111 so that the migration event is properly completed within a specific specification. For example, within a promised time frame or in compliance with a promised contractual obligation or service level. In some embodiments, the entity coordinating the data migration and / or scheduling the tasks 111 may be the owner, manager, or operator of the data being transferred and / or the owner, operator, or manager of the data migration source. For example, the owner, operator, or manager of the source data center 101 and / or the service provider of one or more applications 107a and / or the workload 109a hosted by the source data center 101. In other embodiments, the entity that may be coordinating and scheduling the completion of one or more tasks 111 may be one or more migration teams (internal or a third party hired to perform the end-to-end migration process). An embodiment of the tasks 111 that may be scheduled for completion may include a series of pre-migration tasks 113, migration tasks 115, and post-migration tasks 117, a scheduled time frame (including a deadline) for completing the tasks, and stakeholders assigned to complete each task. Examples of pre-migration tasks may include rebooting servers, preparing backups of storage devices of the source data center 101, terminating services of one or more running applications 107a and / or workloads 109a. Embodiments of migration tasks 115 may include one or more tasks that may involve the actual transfer of data, applications 107a, workloads 109a, and libraries, as well as processes that may convert and / or format data to meet the requirements of storage and operation at the data migration target. For example, data stored by a database in the source data center 101 is converted to a newly upgraded format understood by the database engine of the target data center 125 that receives the database data set during the migration of the data. In addition, examples of post-migration tasks 117 may include tasks such as verifying the completion of the migrated data received by the data migration target, updating permissions, updating fields to correspond to the destination on the new data migration target, updating server names, updating dependencies, and finally testing the data migration target to ensure that no errors are generated during the data migration, including post-migration tasks 117 for testing of the transferred applications 107b and / or workloads 109b to ensure that they are launched and operated without errors.
[0073] Embodiments of the computing environment 200, 240 may include a plurality of systems, components, modules, services, and / or programs that perform and log the execution and / or completion of tasks 111 assigned to one or more specific stakeholders to complete as part of an end-to-end data migration event. The execution, completion, and even failure (i.e., due to missed deadlines or errors) of performing one or more tasks 111 may be captured and logged by one or more systems, components, programs, etc. within the computing environment 200, 240. For example, the tasks 111 may be monitored, executed, and / or logged in coordination with one or more recording servers 103a, 103b, monitoring servers 105a, 105b, applications 107a, 107b, workloads 109a, 109b, and migration tools 121 of a data migration source and / or a data migration target and / or a client device 119, 123, 127 executing one or more blockchain applications 124, APIs 122, or application code 120.
[0074] As a function of performing one or more tasks 111 that are scheduled or assigned to a particular entity, embodiments of systems, components, modules, services, and / or programs that implement the execution of one or more tasks 111 may create detailed digital assets that describe the implementation (or attempted implementation) of tasks 111. The term "digital asset" may refer to an electronic record owned, licensed, or controlled by an owner or manager of the data being created. For example, a log, alert, or event record created by a source data center 101 may, in some instances, be a digital asset owned by the owner of the source data center 101, or the owner / licensee of the application 107a or workload 109a that created the log or record. Embodiments of resources that create logs, alerts, event records, error reports, or other types of files may provide details describing the characteristics of the event within the file data (or metadata). For example, the record, log, error report, or alert may include the name of the task, the date and time the task was performed, the date and time the task completed, the result of the task (i.e., whether it completed successfully or failed), a list and description of any errors that occurred, and any error codes or warnings, systems, applications 107, workloads 109, programs, migration tools 121, or other computing resources used to perform the tasks 111. Digital assets may be output and / or stored by one or more systems, components, modules, services, applications 107, workloads 109, programs (generally referred to as "resources") that perform the execution of one or more tasks 111. Embodiments of resources that perform the execution of one or more tasks 111 may automatically and / or periodically establish a connection with the blockchain platform 112 via the API 122 and / or (multiple) blockchain applications 124 and request an update to one or more peer nodes 104-110 of the blockchain platform 112 including an audit trail 129 having one or more files including digital assets describing the implementation and execution of the end-to-end migration task 111. Each of the (multiple) embodiments of the peer nodes 104-110 hosts one or more blockchain ledgers and may include a chaincode (also referred to as a smart contract and described in detail below) that can access the blockchain's ledger (i.e., the audit trail 129). The interface with the chaincode occurs via the API 122 to execute the application code 120. For example, an auditor of the end-to-end migration task 111 can run the chaincode via the API 122 to query the ledger and / or the migration tool 121, or can execute the chaincode via the API 122 to update the ledger of the peer node. In some embodiments, each resource can also back up and store digital assets that detail and describe the implementation of one or more tasks 111 to a localized repository or database and / or a network-accessible repository or database that can be accessed outside the blockchain platform 112.
[0075] As described above, one of the resources that can create digital assets when implementing and executing one or more tasks 111 can be a logging server 103a, 103b. An embodiment of the logging server 103 can refer to a computer (real or virtual) or a computer program that can manage and provide log data and event records related to the state of the computer system from which the log data is collected. For example, the logging server 103a manages and provides log data and event records describing the state of the source data center 101, including logs and event records describing the actions of one or more applications 107a and workloads 109a of the source data center 101. An embodiment of the logging server 103a can additionally selectively store and archive records of events and logs tracked by the logging server 103a, ensure the security and confidentiality of the stored logs, control the quality of log and event records by analyzing and / or adding missing information to the logs and contextualizing the events recorded by the logs, including recording information about the IP address that generated the log or event record, user information, one or more characteristics of the system being accessed, and any error details or alarms that may be triggered as part of the log or event occurrence.
[0076] Another type of resource that can create digital assets that contribute to the audit trail 129 of the end-to-end migration task 111 in response to the implementation or execution of the end-to-end migration task 111 can include monitoring servers 105a, 105b. An embodiment of the monitoring server 105 can be a computer system (real or virtual) or computer program responsible for supervising the application 107 and workload 109, and providing a global view of the application 107 and workload 109 at a given moment and a history of the past state of the application 107 or workload 109, including: the execution and / or response time of the resources of the application or workload; the integrity of the application 107 or workload 109; and the availability of the application 107 or workload 109. The monitoring server 105 can detect the lack of execution, the number of connections entering the service, application 107 or workload 109, and anomalies. The monitoring server 105 can monitor multiple elements of the service, application 107 and workload 109, generally referred to as "metrics". Metrics that may be monitored may include (but are not limited to) CPU load, number of simultaneous connections, errors, simulated interactions with applications 107 or workloads 109, network load (i.e., quality of service, latency, ping, etc.), and attempted connections blocked by firewalls. Supervision of metrics by monitoring server 105 allows for the creation of alerts that may reference or indicate significant state changes, which may be, in some instances, a result of executing one or more tasks 111. Examples of alerts that may be created in response to the performance of one or more tasks 111 may include high CPU load, repository pushes, build errors, and too many simultaneous connections.
[0077] In some embodiments, the migration tool 121 may be used to perform one or more end-to-end migration tasks 111. The migration tool 121 may be operated by one or more stakeholders via a migration client device 119, and may often be used by more than one different team to which the task 111 may be assigned, such as a data migration team, a management team, and / or an infrastructure team. Embodiments of the data migration tool 121 may be used to move applications 107a, services, libraries, servers 103a, 105a, and / or workloads 109a (collectively referred to as "migrated data") from one storage system to another storage system, and more specifically from one or more storage systems of a data migration source to (multiple) storage systems of a data migration target. The data migration tool 121 may perform one or more end-to-end migration tasks 111, including migration tasks 115 of selecting, preparing, extracting, and / or transforming data of a data migration source through a process to ensure that the form of the migrated data is compatible with the new storage location of the storage system of the data migration target. Embodiments of the migration tool 121 may include a tool set capable of performing data integration, and may include extract, load, and transform (ETL) tools.
[0078] The ETL tool that may be part of an embodiment of the migration tool 121 is capable of handling the complex requirements of the end-to-end migration task 111, including the complex migration task 115 of the data migration process. The ETL functionality of the migration tool 121 may include tools for handling large data sets, deep data profiling, and integration of migration data between multiple platforms. In some embodiments, the ETL functionality of the migration tool 121 may automate standard ETL tasks, such as obtaining data from an operating system, converting the obtained data into a unified format, and loading the converted data into a destination database or storage system of the data migration target.
[0079] In some embodiments of the migration tool 121, the output of the migration tool that performs one or more end-to-end migration tasks may include outputting one or more logs, alerts, errors, records, and / or another type of digital asset detailing the task 111 performed by the migration tool 121, one or more actions performed, the results of performing the task 111 (the results including indications of success, failure, error, etc.), the date and time the task was initiated and completed, and information describing the user performing the task, the IP address of the migration client device 119 running the migration tool 121, the data migration source, and the data migration target.
[0080] Embodiments of digital assets recorded and / or generated as a result of one or more assigned end-to-end migration tasks 111 being performed by one or more systems, components, program applications 107, workloads, servers 103, 105, and / or migration tools 121, such as logs, records, errors, alarms, and events, which may be stored as part of an audit trail 129 as one or more blocks within a data layer 128 of a blockchain or another type of distributed database. In some embodiments, the methods, systems, and / or computer program products described herein utilize a decentralized database (such as a blockchain) that is a distributed storage system, which includes multiple nodes 102 (including peer nodes 104-110) on a blockchain network 130 that communicate with each other to create and update data describing an audit trail 129 of end-to-end migration of data between (multiple) data migration sources and (multiple) data migration targets. The decentralized database may include an append-only immutable data structure similar to a distributed ledger capable of maintaining records between mutually untrusted parties. The untrusted parties are referred to herein as peer nodes 104-110 or simply peers. Each peer 104-110 maintains a copy of the distributed ledger describing the audit trail 129, and no single peer can modify the records of the ledger without consensus among the distributed peers 104-110. For example, the peer nodes 104-110 can implement a consensus protocol to verify blockchain storage transactions that store digital assets as blocks written to the audit trail 129, group storage transactions into blocks, and build hash chains on blocks. If necessary, the process forms the ledger by sorting the storage transactions to maintain consistency.
[0081] In various embodiments, permissioned and / or permissionless blockchains may be used. In a public or permissionless blockchain, anyone can participate without a specific identity (e.g., remaining anonymous). Public blockchains may involve native cryptocurrencies and use consensus based on various protocols such as proof of work. On the other hand, permissioned blockchain databases provide secure interactions between a group of entities that share a common goal (i.e., the migration of data) but do not fully trust each other, such as businesses, entities, and / or stakeholders that exchange funds, goods, (private) information, etc. to accomplish their goals.
[0082] In addition, in some embodiments, the method, system and / or computer program product may utilize a blockchain that operates arbitrary, programmable logic, tailored for decentralized storage solutions and is referred to as a "smart contract" or "chain code". The peers 104-110 may host an instance of an API 122 that may be connected to an application 124 and / or may execute application code to implement chain code instructions or commands. For example, instructions to access or query the ledger of a particular peer node or update the ledger (i.e., audit trail 129) with the consensus of the peer nodes 104-110. In some cases, there may be a dedicated chain code for managing functions and parameters, which is referred to as a system chain code (such as managing access to off-chain data stores / databases). In some embodiments, the method, system and / or computer program product may also utilize a smart contract that is a trusted distributed application that utilizes the tamper-proof nature of the blockchain database and the underlying protocol between the nodes 102, which is referred to as an endorsement or endorsement policy. Blockchain transactions associated with the application may be endorsed before being deployed to the blockchain, while unendorsed transactions are ignored.
[0083] The endorsement policy allows the chaincode to specify the signers of the transaction in the form of a set of peer nodes 104-110 required for endorsement. When a client node of the blockchain network 130 sends a transaction to the peers 104-110 specified in the endorsement policy, the transaction is executed to verify the transaction. After verification, the transaction enters the sorting phase, in which a consensus protocol is used to produce an ordered sequence of signed transactions grouped into blocks.
[0084] In some embodiments, methods, systems, and / or computer program products may utilize nodes 102 that are communication entities of a blockchain system. A "node" may perform a logical function in the sense that multiple nodes of different types may run on the same physical server or blockchain platform 112. Blockchain nodes 102 are grouped in trust domains and are associated with logical entities that control them in various ways. Blockchain nodes 102 may include different types, such as client nodes 560 or submitting client nodes that submit transaction calls to signatories (e.g., peers) and broadcast transaction proposals to subscription services (e.g., subscription nodes).
[0085] Another type of node 102 is a peer node 104-110, which can receive transactions submitted by clients, coordinate transactions, and maintain the state and copy of the ledger of blockchain transactions. Peers 104-110 can also have the role of signator, although this is not required. Subscription service nodes or subscribers are nodes that run communication services for all blockchain nodes 102, and they implement delivery guarantees, such as broadcasts to each of the peer nodes 104-110 when coordinating / confirming transactions (including documenting the transfer of digital assets received from data migration sources, data migration targets, migration tools 121, and one or more client devices 119, 123, 127) and modifying the world state of the blockchain, which is another name for the initial blockchain transaction and can generally include control and setup information.
[0086] In some embodiments, methods, systems, and / or computer program products may utilize a ledger that is an ordered, tamper-proof record of all state transitions of a blockchain. State transitions may result from chaincode invocations (e.g., transactions) submitted by parties (e.g., client nodes, ordering nodes, signer nodes, peer nodes, etc.). Each party (such as peer nodes 104-110) may maintain a copy of the ledger. Transactions may result in a set of asset key-value pairs being submitted to the ledger as one or more operands, such as create, update, delete, etc. The ledger includes a blockchain (also referred to as a chain) for storing immutable ordered records in blocks. The ledger also includes a state database that maintains the current state of the blockchain.
[0087] In some embodiments, the methods, systems, and / or computer program products described herein may utilize a chain as a transaction log structured as hash-linked blocks (e.g., Figure 6 ), and each block contains a sequence of N transactions, where N is equal to or greater than one. The block header includes hashes 605a-605n of the block transactions, and hashes 607a-n of the previous block transactions. In the example of a genesis block, the hash of the header of the previous block may be zeroed because the previous block may not exist. Given the hash-linked blocks, all transactions on the ledger can be ordered and cryptographically linked together. Therefore, it is impossible to tamper with the ledger data without breaking the hash link. The hash 605 of the most recently added blockchain block represents every transaction that came before it on the chain, making it possible to ensure that all peer nodes 104-110 are in a consistent and trusted state. The blockchain can be stored in the peer node 104-110 file system (e.g., local, attached storage, cloud, etc.), effectively supporting the append-only nature of the blockchain workload. Figure 6 An example of a transaction log structured as hash-linked blocks stored by peer nodes 104-110 is depicted. Figure 6 As shown, each of the peer nodes 104 and 110 of the blockchain network 130 includes not only a hash 605a-605n of the link, a previous hash 607a-607n of the previous block, and a payload 609a-609n (i.e., a digital asset or file added to the audit trail 129), but also a timestamp 603a-603n of the receipt identifying the time when the block was created and / or added to the blockchain, and an index 601a-601n. In some embodiments, a nonce 608a-608n may be added to the block stored by each peer node 104-110. A "nonce" may refer to a "number used only once" during encrypted communications. An embodiment of a nonce 608 may be a random or pseudo-random number issued in an authentication protocol when a block is hashed or encrypted to ensure that old communications cannot be reused in a replay attack, and if a block in the blockchain is rehashed, the rehash of the block satisfies certain difficulty level restrictions on the rehashing by being assigned a new nonce associated with the rehashed block value.
[0088] The current state of the immutable ledger represents the latest values of all keys included in the chain transaction log. Because the current state represents the latest key values known to the channel on the blockchain network 130, it is sometimes referred to as the world state. Embodiments of the channel allow a specific set of peers, applications 124, and APIs 122 to communicate with each other within the blockchain network 130. Chain code calls execute transactions against the current state data of the ledger. In order to make these chain code interactions efficient, the latest values of the keys can be stored in the state database. The state database can simply be a view of the indexes in the chain's transaction log, so it can be regenerated from the chain at any time. The state database can be automatically restored (or generated) when the peer node starts and before the transaction is accepted.
[0089] Some benefits of the instant solution described and depicted herein include methods, systems, and computer program products for implementing a blockchain to securely create an audit trail 129 of end-to-end migration events using one or more digital assets describing the execution of one or more end-to-end migration tasks 111. Exemplary embodiments solve the problems of time and trust by extending the features of the database, such as immutability, digital signatures, and being a single source of trust for auditing the execution of data migration between a data migration source and a data migration target. Exemplary embodiments provide a solution for generating a secure ledger containing an audit trail 129 on a blockchain accessible via a blockchain platform 112. Embodiments of a blockchain network 130 can be isomorphic based on the type of information stored (e.g., private information, public information, application or workload specifications, etc.) and the rules for managing assets based on smart contracts executed via applications 124 and / or APIs 122. In some embodiments, due to the nature of the different types of digital assets that can be collected from various servers 103, 105, migration tools 121, applications 107, workloads 109, and client devices 119, 123, the blockchain network 130 can be based on the asset type stored to the audit trail 129, or based on the migration project added to the audit trail 129 and the cross-blockchain communication protocol can be used for each blockchain network to synchronously communicate with each other. In other embodiments, each chain in the blockchain network 130 can be associated with an asset type, and the rules governing the asset type can be combined via chains communicating through the cross-chain communication protocol.
[0090] Note that blockchain differs from traditional databases in that blockchain is not a central storage, but rather a decentralized, immutable, and secure storage where nodes 102 can share changes to records in the storage. Some properties inherent in blockchain and which help to achieve blockchain include, but are not limited to, immutable ledger, smart contracts, security, privacy, decentralization, consensus, endorsement, accessibility, etc., which are further described herein. According to various aspects, the system described herein is achieved due to the immutable accountability, security, privacy, allowed decentralization, availability of smart contracts, endorsement, and accessibility inherent and unique to blockchain.
[0091] Specifically, the blockchain ledger data including the audit trail 129 is immutable, which provides an effective method for securely auditing the execution of one or more end-to-end tasks 111 while performing an end-to-end migration of data between a data migration source and a data migration target. In addition, the use of encryption in the blockchain provides security and establishes trust. Smart contracts manage the status of digital assets added to the audit trail 129. The exemplary blockchain is decentralized. Therefore, each end user, manager and / or auditor of the end-to-end data migration project can access its own copy of the ledger. Multiple stakeholders including different organizations, entities (and peers) responsible for auditing or executing a part of the task 111 can be loaded onto the blockchain network 130. Key organizations can be used as signing peers to verify smart contract execution results, read sets, and write sets. In other words, the inherent characteristics of the blockchain provide an effective implementation method for stakeholders to use the blockchain platform 112 to audit the end-to-end migration of data between the source and the target to track the progress and execution of the end-to-end migration task 111.
[0092] One of the benefits of the exemplary embodiments described herein is that blockchain improves the functionality of one or more data processing systems 10 that implement a data migration audit trail 129 using a blockchain network 130 (e.g., by deferring to validators / nodes in the blockchain network 130 to implement the transfer, which can facilitate the collection and endorsement of multiple signatures required to confirm acceptance of the execution of one or more end-to-end migration tasks 111 to the audit trail 129). Through the blockchain system described herein, the data processing systems of the computing environments 200, 240, 300, 500, 550 (or the processors of (one or more) data processing systems 10) can perform functions for tracking the progress of end-to-end data migration between source and target systems and / or cloud networks 250 utilizing the blockchain network 130 by providing access to the capabilities of the blockchain platform 112 (such as distributed ledgers, peers, cryptographic techniques, event processing, etc.). In addition, the blockchain platform 112 enables the creation of a business network and enables any stakeholder (including users, entities, or organizations of the end-to-end migration event) to become onboard participants (e.g., merged with an immutable ledger, become a validating / trusting party, etc.). As such, blockchain is more than just a database; blockchain has the ability to create a network of users, entities, onboard / offboard organizations, and other stakeholders that can collaborate and execute service processes in the form of smart contracts that execute transactions with a ledger that is queried and updated with an audit trail 129 of digital assets that describe end-to-end migration tasks. In addition, querying transactions allows the ledger to be viewed by an auditor in order to monitor the progress and execution of one or more end-to-end data migration tasks.
[0093] Embodiments of conventional databases cannot be used to implement the embodiments described herein because conventional databases cannot bring all stakeholders involved in the end-to-end migration onto the blockchain network 130, conventional databases do not create trusted collaboration, and do not provide tamper-proof storage and preservation of logs, alerts, records, and other digital assets recorded to the blockchain ledger. Therefore, the proposed embodiments described herein utilizing the blockchain network 130 cannot be implemented by conventional databases. Furthermore, if conventional databases are used to implement the example embodiments, the example embodiments described herein will suffer from unnecessary disadvantages, such as lack of security, and lack of a single unified consensus of the ledger including the audit trail 129 describing the status of the end-to-end migration task 111. Therefore, the example embodiments provide a specific solution to problems in the field / domain of auditing data migration between a data migration source and a data migration target.
[0094] Now turn to Figure 2A-2B Blockchain platform 112 and Figure 5A In the blockchain architecture 500 of the present invention, an embodiment of the blockchain platform 112 may include certain blockchain elements, for example, a set of blockchain nodes 102. The blockchain node 102 may include one or more peers 104-110 (these four nodes are described by way of example only). These nodes 102 participate in several activities, such as blockchain transaction addition and verification processes (consensus). One or more of the peers 104 and 110 may endorse and / or recommend transactions (such as recording one or more digital assets as blocks to the blockchain) based on an endorsement policy, and may provide subscription services for all blockchain nodes 102 in the blockchain architecture 500. The blockchain node 102 may initiate blockchain authentication and seek to write to the blockchain immutable ledger stored in the blockchain layer 116, a copy of which may also be stored on the and / or data layer 128, or supporting the physical infrastructure 114. The blockchain configuration may include one or more blockchain applications 124, which may be linked to an application programming interface (API) 122 to access and execute stored program / application code 120 (e.g., chain code, smart contracts, etc.), which may be created according to the customized configuration sought by the participants, and may maintain its own state, control its own assets, and receive external information. The application code 120 may be deployed as a transaction and installed on all blockchain nodes 102 and their peers 104 and 110 by attaching to the distributed ledger. For example, the application code 120 may run a chain code that queries the audit trail 129 in its current state based on the ledger of the queried peer, and / or runs the application code 120 that updates the audit trail 129 with one or more new records, logs, events, alerts, etc., using the consensus of the peers on a particular channel of the blockchain network 130.
[0095] Embodiments of the blockchain platform 112 may include various layers, such as a blockchain data layer 128, a service layer 118 (e.g., cryptographic trust services, virtual execution environments, etc.), and an underlying physical computer infrastructure 114 layer, which may be used to receive new transactions that constitute an audit trail 129 and store them on the blockchain, and provide access to auditors seeking to query the data of the audit trail 129 (e.g., via an audit client device 127). The blockchain layer 116 may expose an interface that provides access to the virtual execution environment necessary to process application code 120 and use the physical infrastructure 114. Cryptographic trust services may be used to verify transactions such as asset exchange transactions and keep transaction information private.
[0096] The blockchain architecture 500 can process and execute application code 120 through API 122 via one or more interfaces exposed in the blockchain layer 116, as well as services provided by the blockchain platform 112 in the service layer 118. The application code 120 can control blockchain assets. For example, the application code 120 can store and transmit data, and can be executed by the peer 104 in the form of a smart contract and an associated chain code with conditions or other code elements. As a non-limiting example, a smart contract can be created to perform the transfer of resources and / or the generation of resources. The smart contract itself can be used to identify rules associated with authorization (e.g., asset delivery rules, storage, restrictions, etc.), access requirements (e.g., data storage, off-chain data storage, etc.), and / or the use of the ledger to create or attach an audit trail 129. For example, the audit trail asset data 529 can be processed by one or more processing entities (e.g., virtual machines) included in the blockchain layer 116. The output results 531 may include a plurality of linked shared documents (e.g., each linked shared document records the issuance of a smart contract regarding audit trail asset data 529 that was identified as approved or rejected for addition to the blockchain), including documents and files that may contain logs, records, alerts, error reports, and other digital assets transmitted to the blockchain platform 112 via the API 122. In some embodiments, the physical infrastructure 114 may be used to obtain any data or information described herein.
[0097] Smart contracts can be created via high-level applications and programming languages, and then written to blocks in a blockchain. Smart contracts can include executable code that is registered, stored, and / or replicated using a blockchain (e.g., a distributed network of blockchain peers). A transaction is the execution of smart contract code, which can be executed in response to a condition associated with the smart contract being satisfied. The execution of a smart contract can trigger (one or more) trusted modifications to the state of the blockchain's ledger. (One or more) modifications to the blockchain ledger caused by the execution of the smart contract can be automatically replicated throughout the distributed network of blockchain peers 104-110 through one or more consensus protocols.
[0098] Smart contracts can write data to the blockchain in the format of key-value pairs. In addition, the smart contract code can read the values stored in the blockchain and use them in application operations, such as to generate a user-friendly report on the audit trail 129 and deliver the report to the blockchain application 124 installed on the user client device 124. An embodiment of the smart contract code can write the output of various logical operations to the blockchain. The code can be used to create temporary data structures in a virtual machine or other computing platform. The data written to the blockchain can be public and / or can be encrypted and maintained as private data. The temporary data used / generated by the smart contract is kept in memory by the provided execution environment, and then deleted once the data required for the blockchain is identified.
[0099] The chaincode may include a code interpretation of a smart contract with additional features. As described herein, a chaincode may be an application code 120 deployed on a computing network where it is executed and verified by chain validators together during a consensus process. The chaincode receives a hash 605 and retrieves from the blockchain a hash associated with a data template created by using a previously stored feature extractor. If the hash of the hashed identifier matches the hash created from the stored identifier template data, the chaincode sends an authorization key to the requested service. The chaincode may write data associated with cryptographic details to the blockchain (e.g., thereby confirming the transfer of a digital asset, such as for an audit trail 129 log, record, alert, or event; or identifying a difference from a perspective transfer of a digital asset, etc.).
[0100] Figure 5BAn example of a blockchain transaction flow 550 between nodes 102 of a blockchain network 130, such as nodes 102 of a peer-to-peer (p2p) network, is shown. The transaction flow 550 may include a transaction proposal 591 sent by an application client node 560 to a signatory peer node 581 (e.g., in some embodiments, the transaction proposal 591 may be a request including an identifier associated with an off-chain data store or database). The endorsing peer node 581 may verify the client signature and execute the chaincode function to initiate the proposed transaction. For example, the proposed transaction to record a log from the migration tool 121 to a block and input the block into the audit trail 129 blockchain. The output may include a chaincode result, a set of key / value versions read in the chaincode (read set), and a set of key / values written in the chaincode (write set). The proposal response 592 is sent back to the client node 560 along with the endorsement signature (if approved). The client node 560 assembles the endorsement into a transaction payload 593 and broadcasts the payload 593 to the ordering service node 584. The ordering service node 584 then delivers the ordered transaction as a block to all peers 581-583 on the channel. Before being deployed to the blockchain, each peer 581-583 can check the endorsement policy to ensure the correct assignment of the specific peer that has signed the result and verify the signature against the transaction payload 593 (e.g., all peers or a threshold number of peers, verifying that the request includes an identifier and / or symmetric key that allows the data store connection object to be found and / or access to the off-chain database storing the digital asset)
[0101] An embodiment of a client node 560 initiates a transaction proposal 591 by constructing and sending a request to a peer node 581 acting as an endorser. The client node 560 may include an application utilizing a supporting software development kit (SDK) that utilizes an available API 122 to connect to a peer and invoke a chaincode to generate a transaction proposal 591. Through the peer connection, the application 124 and / or the API 122 may execute the chaincode to query or update the ledger. The results of a ledger query transaction are returned immediately, while a ledger update involves more complex interactions between the application, peer, and subscriber (described in detail herein). A transaction proposal 591 is a request to invoke a chaincode function so that data can be read and / or written to the ledger (e.g., writing a new key-value pair for an asset to be added to the audit trail 129). The SDK may simplify the package of the transaction proposal 591 into an appropriately structured format (e.g., protocol buffers over remote procedure calls (RPCs)) and take the cryptographic credentials of the client node 560 to generate a unique signature for the transaction proposal 591.
[0102] In response, the endorsement peer node 581 may verify that (a) the transaction proposal 591 to add the digital asset to the block including the audit trail 129 is well-formed, (b) the transaction has not been submitted in the past (replay attack protection), (c) the signature is valid, and (d) the submitter (in this example, the client node 560) is properly authorized to perform the proposed operation on the channel of the blockchain network 130. The endorsement peer node 581 may input the transaction proposal 591 as an argument to the invoked chaincode function. The chaincode is then executed against the current state database to produce a transaction result including a response value, a read set, and a write set. However, the ledger of the node 102 of the blockchain is not updated at this time. In some embodiments, the value set is transmitted back to the SDK of the client node 560 along with the signature of the endorsement peer node 581 as a proposal response 592, which parses the payload 593 for consumption and display by the application 124 and / or API 122.
[0103] In response, the application of the client node 560 views / verifies the signature of the endorsement peer and compares the proposed response to determine whether the proposed response is the same. If the chain code only queries the ledger, the application views the query response and typically does not submit the transaction to the sorting node 584 service. If the client node 560 intends to submit a transaction to the sorting node 584 service to update the ledger, the client node 560 determines whether the specified endorsement policy has been satisfied (e.g., the request has been accepted) before submission. Here, the client node 560 may only include one of the multiple parties or stakeholders in the transaction to add the digital asset to the block of the audit trail 129. In this case, each individual client node 560 can have their own endorsement peer, and each endorsement peer will need to endorse the transaction. The architecture is such that even if the client node 560 chooses not to view the response or otherwise forward the unendorsed transaction, the endorsement policy will still be enforced by the peer and supported in the submission verification phase.
[0104] After a successful review, the client node 560 assembles the endorsement into the transaction and broadcasts the transaction proposal 591 and response to the ordering node 584 within the transaction message in the transaction payload 593 step. The transaction may contain read / write sets, signatures of the endorsing peers, and channel IDs. The ordering node 584 does not need to see the entire contents of the transaction in order to perform its operations, but instead the ordering node 584 can simply receive transactions from all channels of the network, sort them chronologically by channel, and create blocks of transactions per channel.
[0105] The transaction block is sent from the sorting node ( Figure 5B4 peer node 584 in the example of , referred to herein as "ordering node 584") is delivered to all peer nodes 581-583. Transactions 594 within the block are verified to ensure that any endorsement policies are satisfied and that the state of the ledger for the read set variables has not changed since the read set was generated by the transaction execution. The transactions in the block are marked as valid or invalid. In addition, in step 595, each peer node 581-583 appends the block to the channel's chain, and for each valid transaction, the write set is deployed to the current state database. An event is emitted to notify the application of the client node 560 that the transaction (call) has been immutably appended to the chain, and to notify whether the transaction is verified or not (e.g., whether an update request to the audit trail 129 is allowed or denied, which may include the addition of new digital assets sent from one or more servers 103, 105, migration tools 121 and / or client devices 119, 123, 127 to the blockchain platform 112).
[0106] Method for performing a blockchain-implemented audit trail of data
[0107] Figure 7 FIG. 700 shows an embodiment of an algorithm 700 for executing a computer-implemented method for executing a blockchain-implemented data migration audit trail 129 that can securely track the progress of an end-to-end migration task 111. Figure 7 The algorithm 700 shown and described may be used with one or more computer systems and is generally composed of Figure 1 The data processing system 10 is defined by, and more specifically by Figure 2A-6 The embodiment definition of the special-purpose data processing system of the computing environment 200, 240, 300, 500, 550 depicted in and described in the text. It should be recognized by those skilled in the art that Figure 7 The steps of the algorithm 700 described in the embodiment of the present invention may be performed in a different order than that presented. The algorithm 700 may not necessarily require the execution of all the steps described herein. Instead, some embodiments of the algorithm 700 may change the method by performing a subset of the steps using one or more of the steps discussed below.
[0108] An embodiment of the algorithm 700 may begin at step 701. In step 701, a user, owner, manager, entity, or other stakeholder with authority to authorize data migration of data stored by one or more data migration sources may create and / or authorize a new data migration project. The user authorizing and / or creating a data migration project may identify a data migration source, such as a source data center 101 or a cloud network 250, responsible for transferring data and a target data source, such as a target data center 125 or a second cloud network, designated to receive data migrated from the data migration source.
[0109] In step 703 of the algorithm 700, a task list 111 may be generated and / or distributed to each stakeholder and / or participant who may participate in or contribute to the data migration project created in step 701. The generated task list 111 may include one or more end-to-end migration tasks for preparing, delivering, and verifying the successful migration of data between a data migration source and a data migration target. An embodiment of the end-to-end migration task list 111 may include one or more pre-migration tasks 113, migration tasks 115, and / or post-migration tasks 117. In step 705, one or more tasks 111 of the task list generated in step 703 may be assigned to one or more stakeholders, such as a specific team of participants responsible for performing the assigned tasks of the task list 111. Furthermore, in addition to the assigned tasks, the task list 111 may also include a schedule for completing the tasks before a deadline and a designation of one or more subordinate tasks that may require completion of the assigned tasks before the subordinate tasks can be completed.
[0110] In step 707 of the algorithm 700, a determination is made whether one or more of the assigned tasks of the data migration project is overdue by comparing the due date scheduled for completion of the task to the current date on which the determination is made. If the assigned task has not been executed and exceeds the assigned due date scheduled by the task list generated in step 703, the algorithm may proceed to step 709, where the non-execution of the task that exceeds the due date is recorded to a digital asset, such as a log file, event record, alert, etc. The component, program, server 103, 105, migration tool 121, or other resource that records the non-execution of the assigned task may initiate a transaction to add a digital asset indicating the non-execution of the task to the audit trail 129 maintained by the blockchain platform 112. For example, the resource that generates the digital asset indicating the non-execution of the task may execute the application code 120 via the API 122 and / or application 124 that requests that the ledger maintaining the audit trail 129 be updated to include the non-executed asset. Specifically, a client node that receives a request to update the ledger may execute a chaincode that propagates the execution of the update request to the peers 104 - 110 of the blockchain network 130 .
[0111] Conversely, if in step 707, it is determined whether the assigned tasks 111 are expired, a second determination may be made as to whether one or more tasks 111 have been executed within the computing environment 200, 250 as part of the end-to-end migration project created in step 701. If in step 711, the tasks 111 have not been executed, the algorithm 700 may return to step 707. Likewise, if in step 711, execution of one or more tasks 111 has occurred, the algorithm 700 may proceed to step 713. In step 713, as the task is executed by one or more resources of the computing environment 200, 250 (such as by application(s) 107, workload 109, migration tool 121, server 103, 105, and / or client device 119, 124, 127), one or more resources of the computing environment may generate and / or update digital assets, such as logs, alerts, error reports, event records, etc., detailing the execution of the task 111, the results, and one or more additional details that may provide context for the execution of the task 111 (i.e., identifying when the task was executed, which resource executed the task, when the task was executed, username, network, IP address, etc.). For example, the digital asset recording the execution of the task may be an application log, an operating system log, output from one or more migration tools 121, a user access log from a client 119, 123, 127 or server 103, 105, and / or a network device log.
[0112] In step 715 of the algorithm 700, the digital asset generated by one or more resources of the computing environment 200, 240 may send the asset along with a transaction proposal to update the ledger of the audit trail 129 so as to accurately reflect the execution of one or more tasks 111 on the blockchain that maintains the audit trail 129. For example, the one or more resources of the computer environment 200, 240 that generated the asset may forward the request to the blockchain platform 112 via the application 124 and / or the API 122. In response to receiving the transaction proposal to update the ledger of the blockchain including the audit trail 129, the application 124 and / or the API 122 may execute the application code 120 to process the request with one or more peer nodes 104-110. For example, through API 122, a resource seeking to update a blockchain establishes a peer connection with one or more peer nodes 104-110 of blockchain network 130 and application code 120 invokes a chaincode to facilitate peer nodes 104-110 to update a blockchain including an audit trail 129 that is provisioned with digital assets detailing the execution of task 111. The invoked chaincode may generate an update proposal response that may be returned to the application 124 or API 122 that sent the initial update request.
[0113] In step 717 of the algorithm 700, a record of the digital asset indicating the execution of the one or more tasks may be entered onto a blockchain, which includes an audit trail 129 as a block in the blockchain. For example, upon receiving a proposal response from a peer node via the application 124 or the API 122, the application 124 and / or the API may order the executed update transactions by sending a transaction request to an ordering node of the blockchain network 130. The ordering node may collect transactions from the blockchain network 130 into blocks, which may include an index 601, a timestamp 603, a hash 605, a previous hash of a previous block 607, a nonce 608, and / or a payload 609 including a digital asset detailing the execution (or non-execution of an end-to-end migration task). An embodiment of the ordering node of the blockchain network 130 may distribute the block for the requested transaction to all peers on the blockchain network 130 (or a specific channel of the blockchain network), including the peer node that received the original update request to invoke the chaincode to update the ledger including the audit trail 129. The peer nodes 104-110 may validate the block received from the ordering node and if the update request is deemed valid, each peer node that receives the block from the ordering node may update their copy of the ledger of the audit trail 129 maintained by each peer node 104-110 (if the peer nodes 104-110 reach a consensus to perform the update transaction). In some embodiments, after the verified update of the ledger including the audit trail 129, the peer nodes 104-110 may generate an event to identify the completion of the update transaction and send the event to the application 124 or API 122 that generated the initial transaction request.
[0114] In step 719 of algorithm 700, a determination may be made as to whether each end-to-end migration task 111 has been completed. If all of the end-to-end migration tasks 111 generated in step 703 have been completed, algorithm 700 may end. Conversely, if there are still additional unexecuted end-to-end migration tasks 111 of the data migration project, algorithm 700 may return from step 719 to step 707.
[0115] In some embodiments, an auditor of the end-to-end migration task 111 may attempt to view the ledger including the audit trail 129 at any point in time that the execution of the task 111 has been scheduled or completed, including when all end-to-end migration tasks 111 are completed. The auditor may access the ledger including the audit trail, for example, via the audit client device 127 by establishing a peer connection with the peer nodes 104-110 using the application 124 and / or via the API 122 and submitting a query request to receive a copy of the ledger maintained by the peer node with the established peer connection. The query request submitted via the application 124 and / or the API 122 may execute the application code 120, calling the chain code of the peer node to execute the query request. The chain code generates a query result of the ledger and returns a copy of the ledger including the audit trail 129 to the auditor's client device 127 for review and analysis by the auditor. In some embodiments, an auditor may utilize a copy of the ledger including the audit trail 129 to prepare one or more reports detailing the status and execution of the end-to-end migration task, and may send the generated reports to one or more client devices 119 , 123 , 127 .
[0116] The description of various embodiments of the present disclosure has been presented for illustrative purposes, but it is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the present invention. The terms used herein are selected to best explain the principles of the embodiments, practical applications, or technical improvements to technologies found on the market, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A computer-implemented method for generating a blockchain-enabled data migration audit trail, include: receiving, by a processor of a first participant of a plurality of participants in a data migration project, a task list configured to delegate tasks for migrating data from a data migration source to a data migration target; automatically receiving, by a processor of the first participant, via an application programming interface (API), from a resource that performs execution of one of the tasks of the data migration project, an update request for a digital asset to be added to a blockchain audit trail of the data migration project, the digital asset comprising log data regarding execution of one of the tasks of the data migration project; receiving, by a processor of the first participant, a first block of a plurality of blocks from an ordering node, wherein the first block includes the digital asset, and the ordering node distributing the plurality of blocks to corresponding nodes in a blockchain network; updating, by the processor of the first participant, the blockchain audit trail of the data migration project with the first block; as well as An event is generated, by a processor of the first participant, indicating completion of updating the blockchain audit trail and sent via the API.
2. A computer-implemented method according to claim 1, wherein the log content of the digital asset is selected from the group consisting of event logs, application logs, operating system logs, user access logs, system alerts, network device logs, and output from a data migration tool.
3. The computer-implemented method of claim 1 , further comprising: include: establishing, by a processor of the first participant, a peer connection with one of the nodes in the blockchain network using the API in communication with a blockchain platform hosting the blockchain network; as well as The processor of the first participant calls the chain code of the one of the nodes in the blockchain network to update the blockchain audit trail with the first block, wherein the first block is generated by at least one of the recording server or the monitoring server or the data migration tool of the data migration source or the data migration target.
4. The computer-implemented method according to claim 3, in, The first block also includes a timestamp of the digital asset, a hash of the transaction of the first block, and a previous hash describing the immediately previously recorded block in the blockchain network. 5 . The computer-implemented method of claim 1 , wherein the data migration source and the data migration target are each selected from the group consisting of a data center, a public cloud network, and a private cloud network.
6. The computer-implemented method of claim 1, further comprising: include: establishing, by a processor of the first participant, a peer connection to one of the nodes in the blockchain network using the API in communication with a blockchain platform hosting the blockchain network; querying, by a processor of the first participant, the one of the nodes in the blockchain network for a copy of the blockchain audit trail; generating, by a processor of the first participant, a report describing progress of at least one of the tasks for migrating data from the data migration source to the data migration target based on the blockchain audit trail; as well as The report is distributed, by a processor of the first participant, to one or more client devices of the data migration source or the data migration target.
7. The computer-implemented method of claim 1, in, The blockchain network is a peer-to-peer (p2p) network, and each of the nodes of the p2p network that receives one of the multiple blocks from the sorting node verifies that the one of the multiple blocks has not been tampered with and adds the one of the multiple blocks to an existing blockchain of the blockchain network.
8. A computer system for generating an audit trail of data migration implemented by a blockchain, include: a processor of a first participant among a plurality of participants in a data migration project; as well as A computer-readable storage medium coupled to a processor of the first participant, wherein the computer-readable storage medium comprises program instructions for executing the computer-implemented method of any one of claims 1 to 7.
9. A computer program product, include: A computer-readable storage medium having program instructions embodied therewith, the program instructions being executable by a processor of a first participant of a plurality of participants in a data migration project to cause the processor of the first participant to perform the computer-implemented method of any one of claims 1 to 7.
Citation Information
Patent Citations
Data migration management apparatus and information processing system
US20100293412A1
Migration of a legacy system
US20200142965A1