Cloud Proxy for Secure Data Protection Workflow

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage networks face security risks and management challenges due to the exposure of on-premises storage nodes to wide area and public cloud networks, and the tedious process of registering each storage node with backup service applications in cloud networks for data protection workflows.

Innovation Solution

Implementing a cloud proxy that allows node computing devices to communicate indirectly with backup service computing devices via primary inbound and outbound queues, preventing direct exposure to network traffic and enabling secure and efficient data protection workflows by leveraging a cloud proxy to manage data protection across storage clusters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If on-premises storage nodes are directly exposed to wide area and public cloud networks for backup service communication, then data protection workflows can be facilitated, but security risk increases

Engineering Contradiction:
Improvedata protection workflow facilitationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A cloud proxy is introduced as an intermediary component that sits between the backup service applications in the cloud network and the on-premises storage nodes. The cloud proxy receives requests from the backup service, forwards them to the appropriate storage nodes, and relays responses back. This intermediary architecture allows data protection workflows to function while preventing direct exposure of storage nodes to public cloud networks, thereby maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If each storage node is individually registered with backup service applications in cloud network, then data protection workflows can be managed, but management complexity and time increase

Engineering Contradiction:
Improvedata protection workflow managementVSAvoidregistration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent merges the registration and management functions for multiple storage nodes into a single cloud proxy instance. Instead of registering each storage node individually with the backup service applications, the cloud proxy is registered once and then manages communications with all storage nodes collectively. This consolidation dramatically reduces the time and complexity of onboarding new storage nodes to the data protection workflow.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If cloud backup service applications communicate directly with storage nodes across wide area networks, then backup functionality is achieved, but network exposure and security vulnerabilities increase

Engineering Contradiction:
Improvebackup functionalityVSAvoidsecurity stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an additional architectural dimension by inserting the cloud proxy layer between the cloud backup service applications and on-premises storage nodes. This extra layer operates in a separate communication dimension, allowing backup functionality to be maintained through the proxy while the storage nodes remain isolated from direct wide area network exposure. The proxy handles all network communications, preserving security stability without compromising backup productivity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11816003B2Methods for securely facilitating data protection workflows and devices thereof
Publication Date: 2023.11.14 NETAPP INC
  • US11816003B2 patent drawing
  • US11816003B2 patent drawing
  • US11816003B2 patent drawing

AI summary

Methods, non-transitory machine readable media, and computing devices that more securely facilitate data protection workflows are disclosed. With this technology, identification information for primary inbound and outbound queues is extracted from a registration token received from an administrator device. A registration request is inserted into the primary outbound queue using the identification information and one or more communication networks that are external to a data center. The primary inbound queue is polled using the identification information and the communication networks to retrieve messages from a backup service computing device that instantiated the queues and generated the registration token. Accordingly, nodes in a data center can communicate more securely with a cloud backup service via queues and without exposing any HTTP ports to the backup service. Advantageously, the backup service can learn the topology of a storage cluster and manage data protection workflows via communications with one of the constituent nodes.