Cloud Proxy for Secure Data Protection Workflow
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data storage networks face security risks and management challenges due to the exposure of on-premises storage nodes to wide area and public cloud networks, and the tedious process of registering each storage node with backup service applications in cloud networks for data protection workflows.
Innovation Solution
Implementing a cloud proxy that allows node computing devices to communicate indirectly with backup service computing devices via primary inbound and outbound queues, preventing direct exposure to network traffic and enabling secure and efficient data protection workflows by leveraging a cloud proxy to manage data protection across storage clusters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If on-premises storage nodes are directly exposed to wide area and public cloud networks for backup service communication, then data protection workflows can be facilitated, but security risk increases
Solution Approach 1:
A cloud proxy is introduced as an intermediary component that sits between the backup service applications in the cloud network and the on-premises storage nodes. The cloud proxy receives requests from the backup service, forwards them to the appropriate storage nodes, and relays responses back. This intermediary architecture allows data protection workflows to function while preventing direct exposure of storage nodes to public cloud networks, thereby maintaining security.
2Ease of operation
If each storage node is individually registered with backup service applications in cloud network, then data protection workflows can be managed, but management complexity and time increase
Solution Approach 1:
The patent merges the registration and management functions for multiple storage nodes into a single cloud proxy instance. Instead of registering each storage node individually with the backup service applications, the cloud proxy is registered once and then manages communications with all storage nodes collectively. This consolidation dramatically reduces the time and complexity of onboarding new storage nodes to the data protection workflow.
3Productivity
If cloud backup service applications communicate directly with storage nodes across wide area networks, then backup functionality is achieved, but network exposure and security vulnerabilities increase
Solution Approach 1:
The patent introduces an additional architectural dimension by inserting the cloud proxy layer between the cloud backup service applications and on-premises storage nodes. This extra layer operates in a separate communication dimension, allowing backup functionality to be maintained through the proxy while the storage nodes remain isolated from direct wide area network exposure. The proxy handles all network communications, preserving security stability without compromising backup productivity.
Data Source
AI summary
Methods, non-transitory machine readable media, and computing devices that more securely facilitate data protection workflows are disclosed. With this technology, identification information for primary inbound and outbound queues is extracted from a registration token received from an administrator device. A registration request is inserted into the primary outbound queue using the identification information and one or more communication networks that are external to a data center. The primary inbound queue is polled using the identification information and the communication networks to retrieve messages from a backup service computing device that instantiated the queues and generated the registration token. Accordingly, nodes in a data center can communicate more securely with a cloud backup service via queues and without exposing any HTTP ports to the backup service. Advantageously, the backup service can learn the topology of a storage cluster and manage data protection workflows via communications with one of the constituent nodes.


