Secure Data Replication in Distributed Data Storage Environments
The method addresses the challenge of secure data replication in distributed database systems by encrypting updated data elements in the replication process, ensuring the security and integrity of data across multiple locations.
Patent Information
- Application Number
- JP2022563060
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-05-07
- Filing Date
- 2021-04-27
- Publication Date
- 2025-05-12
- Estimated Expiration
- 2041-04-27
AI Technical Summary
Existing database management systems in distributed environments face challenges in securely replicating data across multiple locations, particularly in ensuring the security of updated data elements during replication.
The method involves creating a first entry in a change table for a first copy of a table and a second entry in a change table for a second copy of the table. If the data element is secured, the updated value is encrypted using a security algorithm and stored as ciphertext in the second entry, while unsecured data elements have their updated values stored directly.
This approach ensures secure data replication by encrypting sensitive data elements during the replication process, thereby enhancing the security and integrity of data across multiple database copies.
Smart Images

Figure 0007674796000001 
Figure 0007674796000002 
Figure 0007674796000003
Abstract
Description
[Technical field]
[0001] The present invention relates generally to computing technologies, and more specifically to a database management system that manages the storage of electronic data in a distributed database system in a secure manner. [Background technology]
[0002] Data replication is the electronic copying of data records stored in a source data store, often to a replicated data store, for data recovery or to allow users on multiple computing devices to access data relevant to their tasks without interfering with other work. In data storage systems, it is often desirable to store replicated data in multiple locations so that the data is locally available at each location. Each location has a local data storage device that can satisfy a request to read its own data without having to query other data storage devices in the data storage system. Summary of the Invention
[0003] According to one or more embodiments of the present invention, a computer-implemented method for secure data replication in a data storage environment includes receiving, by a database system, an instruction to modify a first data element in a table in a database. The database includes a first copy of the table and a second copy of the table. The method further includes, in response to receiving the instruction, creating a first entry in the first modification table. The first entry includes a data element including an update value for the first data element. The update value is provided by the instruction. The method further includes creating a second entry in a second modification table. Creating the second entry includes, in response to determining that the first data element is a secured data element, modifying the update value to a ciphertext using a security algorithm and storing the ciphertext in the second entry as content of the first data element in the second modification table. Further, in response to determining that the first data element is a non-secured data element, the update value is stored in the second entry as content of the first data element in the second modification table. The method further includes altering, by the database system, a second copy of the table in accordance with the instructions received using a second alteration table, where the second table is used to respond to subsequent queries.
[0004] According to one or more embodiments of the present invention, a database system includes a memory device and one or more processors coupled to the memory device. The one or more processors implement a method for secure data replication in a database, where the database includes a first copy of a table and a second copy of the table. The method includes receiving an instruction to modify a first data element in the table. The method further includes creating a first entry in a first modification table in response to receiving the instruction. The first entry includes a data element including an update value for the first data element. The update value is provided by the instruction. The method further includes creating a second entry in a second modification table. Creating the second entry includes modifying the update value to a ciphertext using a security algorithm in response to determining that the first data element is a secured data element, and storing the ciphertext in the second entry as content of the first data element in the second modification table. Further, in response to determining that the first data element is a non-secured data element, the update value is stored in the second entry as content of the first data element in the second modification table. The method further includes altering, by the database system, a second copy of the table in accordance with the instructions received using a second alteration table, where the second table is used to respond to subsequent queries.
[0005] According to one or more embodiments of the present invention, a computer program product includes a storage medium readable by one or more processing circuits. The storage medium includes instructions executable by the one or more processing circuits to perform a method for secure data replication in a database, where the database includes a first copy of a table and a second copy of the table. The method includes receiving instructions to modify a first data element in the table. The method further includes creating a first entry in a first modification table in response to receiving the instructions. The first entry includes a data element including an update value for the first data element. The update value is provided by the instructions. The method further includes creating a second entry in a second modification table. Creating the second entry includes modifying the update value to a ciphertext using a security algorithm in response to determining that the first data element is a secured data element, and storing the ciphertext in the second entry as content of the first data element in the second modification table. Further, in response to determining that the first data element is an unsecured data element, the updated value is stored in a second entry as content of the first data element in a second mutation table. The method further includes altering, by the database system, a second copy of the table in accordance with the received instructions using the second mutation table, where the second table is used to respond to subsequent queries.
[0006] Additional technical features and advantages will be realized through the practice of the present invention. Embodiments and aspects of the present invention are described in detail herein and are considered to be a part of the claimed subject matter. For a better understanding, reference should be made to the detailed description and drawings. [Brief description of the drawings]
[0007] [Figure 1] 1 is a schematic diagram of a data storage system according to an illustrative embodiment of the present invention. [Diagram 2]FIG. 1 illustrates a block diagram and operational flow for modifying a data element in a data storage device. [Diagram 3] FIG. 2 is a block diagram of data elements in a data storage device system that securely replicates data changes in accordance with one or more embodiments of the present invention. [Figure 4] 1 is a flowchart of a method for ensuring security of data replication in a distributed data storage environment in accordance with one or more embodiments of the present invention. [Diagram 5] 1 is a flowchart of a method for ensuring security of a data element when copied from a first entry to a second entry in accordance with one or more embodiments of the present invention. [Figure 6] 1 is a schematic diagram of an exemplary computing device configured to implement one or more exemplary embodiments of the present invention. [Figure 7] FIG. 1 illustrates a cloud computing environment in accordance with one or more embodiments of the present invention. [Figure 8] FIG. 2 illustrates abstraction model layers in accordance with one or more embodiments of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0008] The diagrams depicted herein are exemplary. There are many variations in the diagrams and the operations described therein without departing from the invention. For example, actions can be performed in a different order, or actions can be added, removed, or modified. Also, the term "coupled" and variations thereof describe having a communication path between two elements and do not imply a direct connection between the elements without an intervening element / connection between the elements. All of these variations are considered to be part of this specification.
[0009] Exemplary embodiments of the present invention relate to, among other things, devices, systems, methods, computer readable media, techniques, and methods for improving database systems. To keep database systems synchronized with low latency, change data capture techniques are used. For such change data capture, the database system replicates instructions to modify one or more data elements in the database. For example, such instructions to modify data elements may include instructions to INSERT, UPDATE, and DELETE data elements. In database systems implementing change data capture, such instructions modify data elements between target and replica databases. An embodiment of the present invention further improves such distributed database systems having replication of stored data by facilitating secure updates to the stored data when using change data capture. One or more embodiments of the present invention facilitate converting the fields being updated to secure data, which can then be transparently applied via existing replication processes. During application of the changes, the source change table and the target change table are synchronized to ensure that secure data is stored in the database.
[0010] Change data capture involves capturing data from a database update log and capturing the update records in change tables that contain the updated records as well as metadata. The change tables are then used to apply only the updated records to a replica of the original database.
[0011] 1 illustrates a database system implementing change data capture in accordance with one or more embodiments of the present invention. The database system 100 includes a site A, a first data storage device 102, and host devices 130A, 130B, etc., in communication with the first data storage device 102. The host devices 130A, 130B, etc., request data to be read from and written to the first data storage device 102. The database system 100 further includes a second data storage device 104, and host devices 150A, 150B, etc., in communication with the second data storage device 104, at site B. Similarly, the host devices 150A, 150B, etc., request data to be read from and written to the second data storage device 104.
[0012] The first data storage device 102 and the second data storage device 104 are in communication with each other such that the data they store is replicated at each of sites A and B, including any updates to the data that are requested to be written.
[0013] The database system 100 further includes a third data storage device 106 at Site C and a fourth data storage device 107 at Site D. Unlike the first data storage device 102 at Site A and the second data storage device 104 at Site B, the third data storage device 106 and the fourth data storage device 107 are not in communication with any host device. As a result, the third data storage device 106 and the fourth data storage device 107 do not receive requests to read or write data. Such a site, which comprises a data storage device that does not itself receive write requests from a host device and therefore merely acts as a copy of data stored elsewhere, is described herein as an inactive site.
[0014] However, the third data storage device 106 and the fourth data storage device 107 are in communication with the first data storage device 102 and the second data storage device 104, respectively, and replicate the data stored at each of sites A and B, respectively. In use, the third data storage device 106 and the fourth data storage device 107 may be maintained for active use at site A, for example, while a migration occurs from one site to another (e.g., from site A to site C), or may be maintained to provide a backup for use in the event that one of the first data storage device 102 or the second data storage device 104 fails.
[0015] 1, the third data storage device 106 and the fourth data storage device 107 are located at a different site than the first data storage device 102 and the second data storage device 104, although in alternative embodiments, they may be located at the same site as the first data storage device 102 or the second data storage device 104. Additionally, in the embodiment illustrated in FIG. 1, Site A and Site B each include only a single data storage device in communication with a host device, although in other alternative embodiments, they may include multiple data storage devices in communication with one or more host devices.
[0016] The first data storage device 102 and the second data storage device 104 may replicate data between themselves.
[0017] It will be understood that the illustrated data storage devices and sites are only one example of an exemplary embodiment of the invention, and that in other embodiments of the invention, the number of sites, storage devices, and their organization may vary from the illustrated example.
[0018] FIG. 2 shows a block diagram and operational flow for modifying a data element in a data storage device. In the illustrated example, a first data storage device 102 is shown, but it is understood that any other storage device can operate in the same manner. Additionally, in the example described herein, the data storage device stores data using a table data structure, but it is understood that the data storage device can store data using other types of data structures that can also be updated in substantially the same manner as a table. A data element can be a particular data field, i.e., a cell represented by a particular row-column combination. Alternatively, or in addition, a data element can be an entire row or column in a table.
[0019] It should be noted that the figures herein illustrate the target tables that are modified per the exemplary request. It is understood that the modifications are also made in the source tables. Although the target tables are shown with the modifications, the modifications are not shown in the source tables to illustrate to the reader two states of the data: before the request is completed (in the source tables) and after the request is completed (in the target tables). The database system 100 implements the modifications in the target tables when the request is first established in the source tables. Thus, while the figures herein illustrate the mechanism of updates to the source tables that cause replication in the target tables, it should be understood that the modifications to the source tables themselves are not illustrated herein and that such modifications may be made by the database system without affecting the technical solutions provided by one or more embodiments of the present invention.
[0020] In the exemplary scenario of FIG. 2, consider that source table 202 includes data elements, and that one or more data elements are to be updated by instruction 210. In the exemplary scenario herein, the data element 201 being modified is the field represented by row 1, column 2, such that an existing value "yyy" is being changed to "ppp." It should be further noted that the data values may differ in other embodiments of the invention. Also, the number of rows and columns in table 202 is exemplary, and in one or more embodiments of the invention, table 202 may include a different number of rows and columns. Additionally, the exemplary scenario illustrates an "update" operation that modifies an existing value, in one or more embodiments of the invention, the modification may include inserting a new value.
[0021] With reference to an exemplary scenario, instructions 210 modify source table 202 to target table 204. Using change data capture techniques to modify data per instructions 210, database system 100 creates change table 220 in response to instructions 210. Change table 220 is an intermediate data structure that stores update records. The update records stored in change table 220 include values to be applied to target table 204. Database system 100 subsequently uses an apply process to transform the data element to be updated, in this case data element 201. In one or more embodiments of the invention, the data element to be updated is described in metadata portion 222 of change table 220. In one or more embodiments of the invention, metadata portion 222 may further indicate operations to be performed for the changes to be applied. Change table 220 may store several such changes to be applied to target table 204. Database system 100 executes one or more computer-executable instructions to apply these changes at a later point in time. The changes may be applied sequentially in one or more embodiments of the invention. Alternatively, in one or more embodiments of the present invention, the database system 100 applies the changes in a more efficient out-of-order manner by analyzing the changes made and skipping redundant changes.
[0022] However, technical challenges exist when such change capture techniques are applied to distributed database systems 100 where security is ensured, such as by encryption, masking, or other techniques to ensure the security of values stored in the distributed database system 100. For example, when a data element is updated, the change table 220 may contain the values of the data element that are applied to the target table 204. These values are not secured in existing systems and are therefore vulnerable. Here, the "value" of a data element may also be referred to as the "content" of the data element.
[0023] Such technical challenges are addressed by one or more embodiments of the present invention. Embodiments of the present invention facilitate securing each data element in a change table that is applied to a target table 204. In one or more embodiments of the present invention, the data elements are transformed into secured data, and such secured data is then applied to the target table 204 using existing replication techniques. Replication can apply changes to multiple sites within database system 100.
[0024] 3 illustrates a block diagram and operational flow for modifying a data element in a data storage device in a secure manner in accordance with one or more embodiments of the present invention. Implementing the techniques described in FIG. 3 improves the security of data stored in database system 100. Consider again the same exemplary scenario, but now data element 201 is a field being updated by change instruction 210 from "yyy" to "ppp."
[0025] An embodiment of the invention creates a copy of change table 220, which is referred to as a "secondary change table" 320. However, the copy may be referred to by any other terminology in other embodiments of the invention. Secondary change table 320 contains only update records from first change table 220 that have not yet been applied. In one or more embodiments of the invention, secondary change table 320 is created periodically, at a predetermined frequency, for example every 10 seconds, every 2 minutes, or some other frequency.
[0026] Creating secondary change table 320 may include deleting an existing instance of secondary change table 320 and creating a new instance of secondary change table 320. In one or more embodiments of the invention, when creating an instance of secondary change table 320, database system 100 checks the timestamp of the update records in first change table 220. The timestamp in the update record indicates the time when the update record was created. Using the timestamp, only update records created within a predefined duration from the current time when the instance is being created are copied to the instance of secondary change table 320.
[0027] When an instance of the secondary change table 320 is being created, the data element identifiers, e.g., column names, are examined to determine whether the data in the first change table 220 should be secured. A user / administrator can specify which data elements should be secured. For example, such specifications can be stored in the user settings of the database system 100. Thus, the database system 100 checks the settings to determine whether any data elements in the first change table 220 are secured. If there is a data element to be secured, e.g., data element 201, the identified data element is secured while a copy of the data element is created in the secondary change table 320, and the secured data is stored in the data element 301 in the secondary change table 320. The secondary change table 320 is then used to apply changes to the data elements in the target table 204.
[0028] There may be several approaches to generating secure data when copying values of data elements from update records in the first change table 220 to update records in the secondary change table 320. For example, secure data may be created with a reversible security operation. In this case, the data values may be encrypted and the resulting ciphertext may include security metadata that facilitates converting the ciphertext back to the original data value. The security metadata is stored in metadata 322 of the secondary change table 320. Alternatively, or in addition, the database system 100 stores the security metadata elsewhere on the server. The database system 100 tracks such related information with the secondary change table 320 so that the data values can be decrypted at a later time and restored from the ciphertext generated by the security function. To facilitate the storage of the ciphertext, in one or more embodiments of the present invention, the database system 100 modifies the schema of the data elements between the first change table 220 and the secondary change table 320. The schema modification is necessary because the secure operation changes the format of the data values stored in the original fields to the type of the data values in the ciphertext. The "format" of the data may be the field type associated with the data element, such as text, number, date, etc. The format is selected from a list of data types provided by the database system 100.
[0029] Other examples of securing data values include format preserving methods such as masking, redaction, randomization, etc. In these cases, the schema of the secured data elements remains unchanged between the first mutation table 220 and the secondary mutation table 320. These stability techniques do not change the value of the data stored using a particular encryption formula, but rather the format of the data value. Decrypting the original data from the secured data may include applying the inverse of the encryption formula.
[0030] After such securing, the secondary change table 320 has the possibly modified schema and the secured data rather than the original, clear, i.e., unsecured data. Updating data in the database involves performing an "apply process" that pulls the changes from the secondary change table 320 (rather than the first change table 220) and applies the changes to the target table 204. The target table 204 now contains the secured data from the secondary change table 320. When a user requests to read from the target table 204, the secured data is retrieved and then processed by decrypting the retrieved data. The decryption can be performed by a central system, such as the database system 100 or a separate security server (not shown). Alternatively, the decryption can be performed locally at the user end by a client device (not shown).
[0031] 4 is a flowchart of a method 400 for ensuring security of data replication in a distributed data storage environment according to one or more embodiments of the present invention. The method 400 may be performed by one or more processing units that are part of the database system 100. The method 400 includes, at block 402, receiving instructions 210 to modify a data element in the first data storage device 102. The instructions 210 may be in the form of computer-executable instructions, for example, using Structured Query Language (SQL) or other such programming language. A further explanation of the flowchart is provided using an example scenario described herein with respect to the modification instructions 210 of FIGS. 2 and 3.
[0032] Entries in the first change table 220 are created in response to the received instructions 210, at block 404. The entries in the first change table 220 contain update records that are applied to a source table 202. Each entry contains a data element that is updated from the source table 202. The database also includes a target table 204 to which the changes from the first change table 220 are applied. The target table 204 is then used to respond to subsequent queries.
[0033] The method 400 further includes creating copies of entries from the first mutation table 220 in the secondary mutation table 320 at block 406. Copies are created only for new entries, i.e., only for entries having a timestamp indicating that the entry was created after the last iteration of copying the entries from the first mutation table 220. As previously mentioned, entries from the first mutation table 220 are copied into the secondary mutation table 320 at a predetermined frequency. In one or more embodiments of the present invention, such copying may be manually initiated by an administrator / user.
[0034] Creating the copy includes, in block 414, determining whether the data element 201 being modified is a secured data element. For example, the data element 201, such as a row or field or column, may be secured by using an encryption key, an edit (e.g., a mask), a randomization algorithm, or any other secured algorithm. Alternatively, the data element 201 may not be secured. A user setting associated with the first data storage device 102 may include information regarding whether the data element 201 is secured or not. Alternatively, or in addition, the user setting may be associated with a database stored in the first data storage device 102, the database including the source table 202 of which the data element 201 is a part. The database system 100 may check whether the data element 201 is secured or not based on the user setting. Alternatively, or in addition, the database system (100) may determine the security of the data element 201 based on the metadata of the data element 201.
[0035] When data element 201 is not secured, a copy of data element 301 is made as is in an entry in secondary mutation table 320 in block 416, i.e., without securing the contents of the data element. Alternatively, when data element 201 is secured, the contents of data element 301 are secured in block 418 using a secured algorithm, which results in a ciphertext. In block 420, the ciphertext is then stored in an entry in secondary mutation table 320. A copy of data element 301 in secondary mutation table 320 is thus made in block 412 by checking and copying the contents of each data element in a first entry from first mutation table 220.
[0036] 5 is a flow chart of a method for securing a data element when copying from a first entry to a second entry in accordance with one or more embodiments of the present invention. The method 500 includes, at block 502, reading the content of the data element from the first entry from the first mutation table 220. If it is determined that the content is to be secured, the method 500 further includes, at block 504, determining whether the securing includes a schema / format modification of the content.
[0037] When format-preserving security is applied, in block 506, the content of the data element from the first entry is converted to ciphertext using a schema-preserving security algorithm. Examples of format-preserving security algorithms can include masking, redaction, randomization of characters / elements of the content, or other such algorithms. In this case, the schema remains unchanged between the content of the data element from the first entry and the ciphertext stored in the secondary mutation table 320. Furthermore, the schema of the first mutation table 220 and the schema of the secondary mutation table 320 remain unchanged.
[0038] If format-preserving security is not applied, the content of the data element from the first entry is converted to ciphertext using a non-format-preserving security algorithm at block 508. Thus, the ciphertext created in this case has a different, or separate, schema than the content in the data element from the first entry. For example, the security algorithm in this case may be an encryption algorithm that generates ciphertext that may include character types that may not be included in the original content of the first entry.
[0039] In one or more embodiments of the invention, a ciphertext may be created in which the operation is reversible. In this case, the original content is encrypted and the resulting ciphertext may include security metadata. Alternatively, the database system 100 tracks the security metadata so that the ciphertext can be interpreted at a later time to recover the original content. In turn, the database system 100 changes the schema between the first mutation table 220 and the secondary mutation table 320 when a security operation changes the type of a data element field.
[0040] An embodiment of the present invention facilitates creating secure data in a replicated table based on a policy and a database schema by having a secondary change capture table containing the secured data. Additionally, an embodiment of the present invention facilitates creating a secondary change capture table based on an original change capture table. A copy method is performed that includes checking data elements, such as column names, to identify fields for which secured elements are to be created in the secondary change table. Additionally, an embodiment of the present invention facilitates applying changes from the secondary change capture table to a new table with secured data, where queries to a database system are performed against the new table and then against the secured data.
[0041] Referring now to FIG. 6, a computer system 600 is generally shown according to one embodiment. The computer system 600 is a part of the database system 100 and facilitates the execution of the methods described herein. The computer system 600 is responsible for handling / providing various functionalities of the database system 100 or the database system 100. The computer system 600 can be an electronic computer framework that includes and / or employs any number and combination of computing devices and networks, utilizing various communication technologies, as described herein. The computer system 600 is easily scalable, extensible, modular, and can be modified for different services or reconfigured some features independently of other features. The computer system 600 can be, for example, a server, a desktop computer, a laptop computer, a tablet computer, or a smartphone. In some examples, the computer system 600 can be a cloud computing node. Computer system 600 may be described in the general context of computer system executable instructions, such as program modules, being executed by a computer system. Generally, program modules include routines, programs, objects, components, logic, data structures, etc. that perform particular tasks or implement particular abstract data types. Computer system 600 may also be practiced in a distributed cloud computing environment where tasks are performed by remote processing devices that are linked through a communications network. In a distributed cloud computing environment, program modules may be located in both local and remote computer system storage media, including memory storage devices.
[0042] As shown in FIG. 6, computer system 600 has one or more central processing units (CPUs) 601a, 601b, 601c, etc. (collectively or generically referred to as processors 601). Processor 601 can be a single core processor, a multi-core processor, a computing cluster, or any number of other configurations. Processor 601, also referred to as a processing circuit, is coupled to a system memory (603) and various other components via a system bus 602. System memory 603 can include read only memory (ROM) 604 and random access memory (RAM) 605. ROM 604 is coupled to system bus 602 and includes a basic input / output system (BIOS) that controls certain basic functions of computer system 600. RAM is a read-write memory coupled to system bus 602 for use by processor 601. System memory 603 provides temporary memory space for the operation of said instructions during operation. The system memory 603 may include random access memory (RAM), read-only memory, flash memory, or other suitable memory system.
[0043] Computer system 600 includes an input / output (I / O) adapter 606 and a communications adapter 607 coupled to a system bus 602. I / O adapter 606 may be a small computer system interface (SCSI) adapter that communicates with a hard disk 608 and / or other similar components. I / O adapter 606 and hard disk 608 are collectively referred to herein as mass storage 610.
[0044] Software 611 for execution on computer system 600 is stored in mass storage 610. Mass storage 610 is an example of a tangible storage medium readable by processor 601, where software 611 is stored as instructions for execution by processor 601 to cause computer system 600 to operate as described herein below with respect to various figures. Examples of computer program products and the execution of such instructions are discussed in more detail herein. Communications adapter 607 interconnects system bus 602 with network 612, which may be an external network, enabling computer system 600 to communicate with other such systems. In one embodiment, a portion of system memory 603 and mass storage 610 collectively store an operating system that coordinates the functioning of the various components depicted in FIG. 6, which may be any suitable operating system, such as the z / OS or AIX operating systems from IBM.
[0045] Additional input / output devices are shown connected to the system bus 602 via a display adapter 615 and an interface adapter 616. In one embodiment, adapters 606, 607, 615, and 616 may be connected to one or more I / O buses connected to the system bus 602 via an intermediate bus bridge (not shown). A display 619 (e.g., a screen or display monitor) is connected to the system bus 602 by a display adapter 615, which may include a graphics controller to improve performance of graphics-intensive applications and a video controller. A keyboard 621, a mouse 622, speakers 623, etc. may be connected to the system bus 602 via an interface adapter 616, which may include, for example, a super I / O chip that integrates multiple device adapters into a single integrated circuit. Suitable I / O buses for connecting peripheral devices such as hard disk controllers, network adapters, and graphics adapters typically include a common protocol such as the Peripheral Component Interconnect (PCI). Thus, as configured in FIG. 6, computer system 600 comprises processing capability in the form of a processor 601, storage capabilities including system memory 603 and mass storage 610, input means such as a keyboard 621 and a mouse 622, and output capabilities including speakers 623 and a display 619.
[0046] In some embodiments, the communications adapter 607 may transmit data using any suitable interface or protocol, such as an Internet small computer system interface, among others. The network 612 may be a cellular network, a wireless network, a wide area network (WAN), a local area network (LAN), or the Internet. An external computing device may connect to the computer system 600 via the network 612. In some examples, the external computing device may be an external web server or a cloud computing node.
[0047] It should be understood that the block diagram of Figure 6 is not intended to indicate that computer system 600 includes all of the components depicted in Figure 6. Rather, computer system 600 may include suitable fewer or additional components not depicted in Figure 6 (e.g., additional memory components, embedded controllers, modules, additional network interfaces, etc.). Additionally, the embodiments described herein with respect to computer system 600 may be implemented with any suitable logic, where logic, as referred to herein in various embodiments, may comprise any suitable hardware (e.g., a processor, an embedded controller, or an application specific integrated circuit, among others), software (e.g., an application, among others), firmware, or any suitable combination of hardware, software, and firmware.
[0048] Although this disclosure includes a detailed description of cloud computing, it should be understood that implementation of the teachings described herein is not limited to a cloud computing environment. Rather, embodiments of the invention may be implemented in connection with any other type of computing environment now known or later developed.
[0049] Cloud computing is a service delivery model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with a service provider. This cloud model may include at least five characteristics, at least three service models, and at least four deployment models.
[0050] The characteristics are as follows:
[0051] On-Demand Self-Service: Cloud consumers may unilaterally provision computing capacity, such as server time or network storage, automatically as needed without the need for human interaction with the provider of the service.
[0052] Broad network access: Capabilities are available over the network and accessed through standard mechanisms that facilitate use by heterogeneous thin- or thick-client platforms (e.g., cell phones, laptops, and PDAs).
[0053] Resource Pooling: Provider computing resources are pooled to serve multiple consumers using a multi-tenant model, where different physical and virtual resources are dynamically allocated and reallocated according to demand. Consumers generally have no control or knowledge of the exact portion of resources provided to them, but there is a sense of portion independence in that they may be able to specify portions at a higher level of abstraction (e.g., country, state, or datacenter).
[0054] Rapid Elasticity: Features can be provisioned rapidly and elastically, in some cases automatically, and can be quickly scaled out, quickly released, and quickly scaled in. To the consumer, the features available for provisioning often appear unlimited, and any amount can be purchased at any time.
[0055] Measured Service: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at a level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, enabling transparency for both providers and consumers of the services being utilized.
[0056] The service model is as follows:
[0057] Software as a Service (SaaS): The functionality provided to the consumer is the use of the provider's applications running on a cloud infrastructure. The applications are accessible from a variety of client devices through thin-client interfaces such as web browsers (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, storage, or even individual application functions, with the possible exception of limited user-specific application configuration settings.
[0058] Platform as a Service (PaaS): The functionality offered to the consumer is the deployment of applications created or acquired by the consumer, written using programming languages and tools supported by the provider, onto a cloud infrastructure. The consumer does not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but does have control over the deployed applications and, in some cases, the application hosting environment configuration.
[0059] Infrastructure as a Service (IaaS): The functionality provided to the consumer is to provision processing, storage, network, and other basic computing resources onto which the consumer can deploy and run any software, which may include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure, but has control over the operating systems, storage, deployed applications, and possibly limited control over select networking components (e.g., host firewalls).
[0060] The deployment model is as follows:
[0061] Private Cloud: The cloud infrastructure is operated solely for the organization. The cloud infrastructure can be managed by the organization or a third party and can exist on-premise or off-premise.
[0062] Community Cloud: The cloud infrastructure is shared by several organizations to support a specific community with shared concerns (e.g., mission, security requirements, policies, and compliance considerations). The cloud infrastructure may be managed by the organization or a third party and may exist on-premise or off-premise.
[0063] Public Cloud: The cloud infrastructure is made available to the general public or large industry groups and is owned by an organization that sells cloud services.
[0064] Hybrid Cloud: A composition of two or more clouds (private, community, or public) where the cloud infrastructure remains a unique entity but is bound together by standardized or proprietary technologies that enable data and application portability (e.g., cloud bursting for load balancing between clouds).
[0065] A cloud computing environment is a service that focuses on statelessness, low coupling, modularity, and semantic interoperability. At the heart of cloud computing is an infrastructure that includes a network of interconnected nodes.
[0066] Referring now to FIG. 7, an exemplary cloud computing environment 50 is depicted. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 with which a local computing device used by a cloud consumer may communicate, such as, for example, a personal digital assistant (PDA) or cell phone 54A, a desktop computer 54B, a laptop computer 54C, or an automobile computer system 54N, or a combination thereof. The nodes 10 may communicate with each other. They may be physically or virtually grouped into one or more networks, such as a private, community, public, or hybrid cloud, or a combination thereof. This allows the cloud computing environment 50 to provide infrastructure, platform, or software, or a combination thereof, as a service without the cloud consumer having to maintain resources on the local computing device. It should be understood that the types of computing devices 54A-N depicted in FIG. 7 are merely exemplary and that the computing nodes 10 and the cloud computing environment 50 may communicate with any type of computerized device over any type of network or network addressable connection or both (e.g., using a web browser).
[0067] Referring now to Figure 8, a set of functional abstraction layers provided by cloud computing environment 50 (Figure 7) is shown. It should be understood in advance that the components, layers, and functions shown in Figure 8 are for illustrative purposes only, and embodiments of the present invention are not limited thereto. As shown, the following layers and corresponding functions are provided:
[0068] Hardware and software layer 60 includes hardware and software components. Examples of hardware components include mainframe 61, RISC (reduced instruction set computing) architecture based servers 62, servers 63, blade servers 64, storage devices 65, and networks and network components 66. In some embodiments, software components include network application server software 67 and database software 68.
[0069] The virtualization layer 70 provides an abstraction layer over which the following examples of virtual entities may be provided: virtual servers 71, virtual storage 72, virtual networks including virtual private networks 73, virtual applications and operating systems 74, and virtual clients 75.
[0070] In one embodiment, the management layer 80 may provide the following functions: Resource provisioning 81 provides dynamic acquisition of computing and other resources utilized to perform tasks within the cloud computing environment. Metering and pricing 82 provides cost tracking as resources are utilized within the cloud computing environment and charging or billing for the consumption of these resources. As an example, these resources may include application software licenses. Security provides identity verification for cloud consumers and tasks, and protection for data and other resources. User portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 provides allocation and management of cloud computing resources such that required service levels are met. Service Level Agreement (SLA) planning and fulfillment 85 provides pre-configuration and acquisition of cloud computing resources in anticipation of future requirements according to SLAs.
[0071] The workload tier 90 provides examples of functionality for which a cloud computing environment may be utilized. Examples of workloads and functions that may be provided from this tier include mapping and navigation 91, software development and lifecycle management 92, virtual classroom instructional delivery 93, data analytics processing 94, transaction processing 95, and data replication 96.
[0072] The present invention may be a system, method, or computer program product, or a combination thereof. The computer program product may include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to perform aspects of the present invention.
[0073] A computer readable storage medium may be a tangible device capable of holding and storing instructions for use by an instruction execution device. A computer readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer readable storage media includes portable computer diskettes, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), static random access memories (SRAM), portable compact disk read-only memories (CD-ROM), digital versatile disks (DVDs), memory sticks, floppy disks, mechanically encoded devices such as punch cards or ridge-in-groove structures having instructions recorded thereon, and any suitable combination of the foregoing. Computer-readable storage media, as used herein, should not be construed as being themselves transitory signals such as electric waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses through a fiber optic cable), or electrical signals transmitted over wires.
[0074] The computer readable program instructions described herein can be downloaded from a computer readable storage medium to each computing / processing device or to an external computer or storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network can include copper transmission cables, optical transmission fiber, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer readable program instructions from the network and sends the computer readable program instructions for storage in a computer readable storage medium in each computing / processing device.
[0075] The computer readable program instructions for carrying out the operations of the present invention may be either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state setting data, or source or object code written in any combination of one or more programming languages, including object oriented programming languages such as Smalltalk, C++, and traditional procedural programming languages such as the "C" programming language or similar programming languages. The computer readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or partially on the remote computer or entirely on the remote computer. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (e.g., via the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, a field programmable gate array (FPGA), or a programmable logic array (PLA), may execute computer readable program instructions according to state information of the computer readable program instructions to implement aspects of the invention.
[0076] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.
[0077] These computer readable program instructions may be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to generate a machine such that the instructions, executed via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / operations specified in one or more blocks of the flowcharts and / or block diagrams. These computer readable program instructions may also be stored on a computer readable storage medium that can cause a computer, programmable data processing apparatus, or other device, or combination thereof, to function in a particular manner, and thus a computer readable storage medium having instructions stored therein may include an article of manufacture including instructions that implement aspects of the functions / operations specified in one or more blocks of the flowcharts and / or block diagrams.
[0078] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device such that the instructions, which execute on the computer, other programmable apparatus, or other device, implement the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams, causing a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process.
[0079] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block of the flowcharts or block diagrams may represent a module, segment, or portion of instructions, including one or more executable instructions for implementing the specified logical function. In some alternative embodiments, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may in fact be executed substantially simultaneously, or the blocks may be executed in reverse order, depending on the functionality involved. It should also be noted that each block of the block diagrams and / or flowchart illustrations, as well as combinations of blocks in the block diagrams and / or flowchart illustrations, may be implemented by a dedicated hardware-based system that performs the specified functions or operations or implements a combination of dedicated hardware and computer instructions.
Claims
1. 1. A computer-implemented method for secure data replication in a data storage environment, comprising: receiving, by a database system, an instruction to modify a first data element from a first row of a table in a database, the database including a first copy of the table and a second copy of the table; In response to said receiving, by the database system: creating a first entry in a first change table, the first change table including an update record to be applied to the first copy of the table, the first entry including an update value provided by an instruction to be applied to the first data element in the first copy of the table; creating a second entry in a second change table, the second change table including an update record to be applied to a second copy of the table, the second entry corresponding to the first entry, the creating of the second entry comprising: in response to determining that the first data element is a secured data element, modifying the update value from the first entry into ciphertext using a security algorithm and storing the ciphertext as the content of the first data element in the second modification table in the second entry in place of the update value; in response to determining that the first data element is an unsecured data element, storing the updated value in the second entry as content of the first data element in the second change table without securing the updated value; modifying, by the database system, a second copy of the table in accordance with the instructions received using the second modification table based on securing the first data element, wherein the second copy of the table is used to respond to subsequent queries. Creating a second entry including To carry out The method includes:
2. The method of claim 1 , wherein the first data element is determined to be secured based on a setting of the database.
3. The method of claim 1 , wherein the first entry further includes a timestamp indicating a time when the first entry was created.
4. 4. The method of claim 3, wherein the second entry is created as part of periodic updates to the table, the second entry being created in response to the timestamp indicating that the first entry was created after a most recent periodic update.
5. The method of claim 1 , wherein converting the update value to the ciphertext comprises modifying the update value with a format-preserving security algorithm.
6. 2. The method of claim 1, wherein converting the update value to the ciphertext comprises changing a format of the update value, and a schema of the first change table is different from a schema of the second change table.
7. The method of claim 1 , wherein converting the update value to the ciphertext comprises storing security metadata that enables converting the ciphertext back to the update value.
8. The method of claim 7 , wherein the security metadata is stored in the second change table.
9. A memory device; one or more processors coupled to the memory device; A database system comprising: The one or more processors are configured to implement a method for secure data replication in a database, the database including a first copy of a table and a second copy of the table, the method comprising: receiving an instruction to modify a first data element in the table; and In response to said receiving, creating a first entry in a first change table, the first entry including a plurality of data elements including update values provided by instructions to be applied to the first data elements, the update values provided by the instructions; creating a second entry in a second change table, the creating of the second entry comprising: in response to determining that the first data element is a secured data element, modifying the update value from the first entry to ciphertext using a security algorithm and storing the ciphertext as the content of the first data element in the second modification table in place of the update value in the second entry; in response to determining that the first data element is an unsecured data element, storing the updated value in the second entry as content of the first data element in the second change table without securing the updated value; modifying a second copy of the table in accordance with the instructions received using the second modification table, the second copy of the table being used to respond to subsequent queries; Creating a second entry including To carry out A database system including:
10. 10. The system of claim 9, wherein the first data element is determined to be secured based on a setting of the database.
11. 10. The system of claim 9, wherein the first entry further includes a timestamp indicating a time when the first entry was created.
12. 12. The system of claim 11, wherein the second entry is created as part of periodic updates to the table, the second entry being created in response to the timestamp indicating that the first entry was created after the most recent periodic update.
13. 10. The system of claim 9, wherein converting the update value to the ciphertext comprises modifying the update value with a format-preserving security algorithm.
14. 10. The system of claim 9, wherein converting the update value to the ciphertext includes changing a format of the update value, and a schema of the first change table differs from a schema of the second change table.
15. 10. The system of claim 9, wherein converting the update value to the ciphertext comprises storing security metadata that enables converting the ciphertext back to the update value.
16. 16. The system of claim 15, wherein the security metadata is stored in the second change table.
17. 1. A computer program product comprising a storage medium readable by one or more processing circuits, the storage medium storing instructions executable by the one or more processing circuits to perform a method for secure data replication of a database, the database including a first copy of a table and a second copy of the table, the computer program product comprising: receiving an instruction to modify a first data element in the table, and in response; creating a first entry in a first change table, the first entry including a plurality of data elements including update values provided by instructions applied to the first data elements, the update values provided by the instructions; creating a second entry in a second change table, the creating of the second entry comprising: in response to determining that the first data element is a secured data element, modifying the update value from the first entry to ciphertext using a security algorithm and storing the ciphertext as the content of the first data element in the second modification table in place of the update value in the second entry; in response to determining that the first data element is an unsecured data element, storing the updated value in the second entry as content of the first data element in the second change table without securing the updated value; modifying a second copy of the table in accordance with the instructions received using the second modification table, the second copy of the table being used to respond to subsequent queries; Creating a second entry including To carry out A computer program comprising:
18. 20. The computer program product of claim 17, wherein the first data element is determined to be secured based on a setting of the database.
19. 18. The computer program product of claim 17, wherein the first entry further includes a timestamp indicating a time the first entry was created, and the second entry is created as part of periodic updates to the table, the second entry being created in response to the timestamp indicating that the first entry was created after a most recent periodic update.
20. 20. The computer program product of claim 17, wherein converting the update value to the ciphertext comprises changing a format of the update value, and wherein a schema of the first mutation table differs from a schema of the second mutation table.
Citation Information
Patent Citations
Database system, encrypted data search method, and computer program
JP2018097625A
Replicated encrypted data management
US20180241561A1