Cloud Recovery Storage Manager Isolation for Secondary Copies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage management systems lack efficient and secure methods for protecting and managing data in cloud computing environments, particularly in scenarios requiring disaster recovery and test purposes, while ensuring isolation and integrity of secondary copies from the source system.

Innovation Solution

A recovery manager is deployed in a cloud computing environment to manage and restore secondary copies, with features to prevent access and interference between the source and recovery systems, ensuring data security and integrity through independent operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a recovery storage manager is deployed in a cloud computing environment to manage and restore secondary copies, then data restoration capability is improved, but system security and isolation may be compromised

Engineering Contradiction:
Improvedata restoration capabilityVSAvoidsystem security and isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is segmented into distinct components: a source storage manager for primary data management, a recovery storage manager for secondary copy management, and recovery clients for data restoration. This segmentation allows the recovery system to operate independently in a cloud environment while maintaining security isolation from the source system, resolving the contradiction between restoration capability and system security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The recovery storage manager acts as an intermediary between the source system's secondary copies and the recovery clients. It gains knowledge about secondary copies by restoring a management database and then initiates out-of-place restore operations, serving as a secure mediator that enables data restoration without compromising source system isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If the recovery manager is configured to prevent access from source system clients, then data integrity is improved, but system functionality is reduced

Engineering Contradiction:
Improvedata integrityVSAvoidsystem functionality
Core Design Contradiction:
Stability of the object's compositionVSEase of operation

Solution Approach 1:

Different access permissions are assigned to different components: source system clients are blocked from accessing the recovery system to protect data integrity, while authorized recovery clients are permitted to perform restoration operations. This local quality approach allows selective access control that maintains integrity while preserving necessary functionality.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The recovery storage manager performs preliminary actions by restoring a management database from the source system before initiating out-of-place restore operations. This preliminary action establishes the necessary knowledge and configuration for subsequent restoration operations, enabling functionality while maintaining security through pre-configured access controls.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the recovery system operates independently from the source system, then system reliability is improved, but operational complexity increases

Engineering Contradiction:
Improvesystem independenceVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The recovery storage manager gains knowledge about secondary copies by restoring a management database, creating a copy of the necessary configuration and metadata. This copying approach allows the recovery system to operate independently with its own knowledge base, reducing operational complexity while maintaining reliability through independent operation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250298774A1Cloud-based secure operation of a recovery storage manager
Publication Date: 2025.09.25 COMMVAULT SYSTEMS INC
  • US20250298774A1 patent drawing
  • US20250298774A1 patent drawing
  • US20250298774A1 patent drawing

AI summary

A secure data storage management “recovery system” operates in a cloud computing environment that is apart from a source system and source data being protected. A “recovery manager” in the cloud computing environment is responsible for restoring secondary copies that were generated by the source system. The recovery manager gains knowledge (metadata) about the secondary copies by restoring, for its own use, a management database of, and backed up by, the source system. The recovery manager initiates out-of-place restores of the secondary copies to “recovery clients” in the recovery cloud. The recovery system restores, to the recovery cloud, secondary copies from any cloud platform and/or from non-cloud data centers, including secondary copies stored locally, off-cloud by the source system. The recovery manager comprises new features that enforce its isolation from the source system and they act to protect the integrity of the secondary copies generated by the source system.