Cloud Retention Lock Metadata for Deduplicated Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data protection solutions for cloud storage lack the capability to extend on-premises retention lock protection to cloud environments, making data vulnerable to deletion or modification by cloud administrators, which is a compliance and governance standard requirement, especially in deduplication systems.
Innovation Solution
A system and method that efficiently extend retention lock protection from on-premises storage to cloud-based storage by utilizing new metadata elements and API calls to lock and manage retention policies on cloud objects, ensuring secure data retention and compliance with corporate governance and regulatory standards like SEC 17a-4(f) without increasing the total cost of ownership (TCO).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in cloud storage without retention lock protection, then storage accessibility and ease of management are improved, but data security and compliance with retention standards deteriorate due to potential deletion or modification by cloud administrators
Solution Approach 1:
The patent applies preliminary anti-action by implementing retention lock policies that preemptively prevent cloud administrators from deleting or modifying protected data before its retention period expires. The system proactively locks data objects in the cloud storage, establishing protective measures in advance that counteract potential harmful actions by administrators, thereby ensuring compliance with retention standards while maintaining cloud storage accessibility.
2Reliability
If traditional on-premises retention lock mechanisms are used for cloud storage, then data protection capability is improved, but system compatibility and architectural adaptability deteriorate due to lack of cloud-specific implementation
Solution Approach 1:
The patent employs an intermediary approach by introducing a cloud storage gateway or interface layer that mediates between traditional retention lock mechanisms and cloud storage infrastructure. This intermediary component translates on-premises retention lock concepts into cloud-compatible operations, enabling data protection capabilities to function effectively in cloud environments while maintaining compatibility with existing retention lock methodologies.
Solution Approach 2:
The patent applies parameter changes by adapting retention lock parameters and policies specifically for cloud storage environments. The system modifies retention period configurations, lock granularity levels, and access control parameters to suit cloud storage characteristics, thereby maintaining protection capabilities while enhancing adaptability to cloud infrastructure and operations.
3Ease of operation
If cloud administrators have full access to cloud storage objects, then storage management flexibility is improved, but data integrity and compliance enforcement deteriorate due to potential unauthorized modifications
Solution Approach 1:
The patent implements dynamics by creating a dynamic access control model where cloud administrator permissions are flexibly adjusted based on retention lock status. The system dynamically modifies access rights, allowing administrators to manage unprotected data with full flexibility while automatically restricting modification and deletion capabilities for retention-locked objects. This dynamic approach balances management flexibility with data integrity protection throughout the retention period.
Data Source
AI summary
Embodiments for retention locking a deduplicated file stored in cloud storage by defining object metadata for each object of the file, and comprising a lock count and a retention time based on an expiry date of the lock, with each object having segments, the object metadata further having a respective expiry date and lock count for each segment, where at least some segments are shared among two or more files. Also updating the lock count and retention time for all segments of the file being locked; and if the object is not already locked, locking the object using a retention lock defining a retention time and updating the object metadata with a new lock count and the retention time, otherwise incrementing the lock count and updating the retention time for the expiry date if expiry date of a previous lock is older than a current expiry date.


