Cloud Snapshot Management via Key Segmentation and Incremental Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud providers face challenges in managing snapshots for remote extensions of their network substrate, including insufficient storage capacity and security risks due to key sharing for encrypted data, which hinders efficient and secure snapshot management across different computing environments.
Innovation Solution
The solution involves maintaining snapshots at the cloud provider network substrate, allowing the remote extension to access and update them without storing the entire volume, and enforcing encryption key boundaries to prevent key sharing, ensuring secure and efficient snapshot management by decrypting and re-encrypting data as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If snapshots are stored at the remote extension, then access speed is improved, but storage capacity becomes insufficient
Solution Approach 1:
The patent transitions snapshot storage from a single location (remote extension) to multiple dimensions: primary storage at the cloud provider network substrate and cache/storage at the remote extension. This multi-dimensional storage architecture allows snapshots to be accessible from both locations, providing fast local access while maintaining adequate storage capacity at the cloud substrate.
2Reliability
If encryption keys are shared for encrypted snapshot storage, then security is improved through centralized control, but key security boundaries are compromised
Solution Approach 1:
The patent segments the encryption key management into separate key stores at the cloud provider network substrate and the remote extension. Each key store contains its own encryption keys, eliminating the need to share keys across security boundaries. This segmentation maintains centralized control over snapshot data while preserving key security boundaries.
3Manufacturing precision
If entire volume data is transferred for snapshot creation, then snapshot completeness is improved, but bandwidth usage increases
Solution Approach 1:
The patent extracts only the necessary portions of volume data for snapshot creation rather than transferring the entire volume. By identifying and transferring only the specific data blocks that need to be snapshotted, the system maintains snapshot completeness while significantly reducing bandwidth consumption.
4Loss of energy
If incremental snapshots are generated at the remote extension, then bandwidth usage is reduced, but storage capacity at remote extension becomes insufficient
Solution Approach 1:
The patent merges incremental snapshot storage at the remote extension with full snapshot storage at the cloud provider network substrate. This combination allows the system to benefit from reduced bandwidth usage through incremental snapshots while offloading the storage burden to the cloud substrate, thereby avoiding local storage capacity constraints.
Data Source
AI summary
Systems and methods for efficient and secure management of encrypted “snapshots” for a remote provider substrate extension (“PSE”) of a cloud provider network substrate are provided. The PSE may request and obtain a snapshot from the cloud provider network substrate, restore a volume from the snapshot, make changes to data in the restored volume, and/or initiate the creation and storage of a new snapshot that includes incremental updates to the original snapshot to reflect the changes made to data in the volume. An encrypted snapshot stored within the cloud provider network substrate may be decrypted using a cloud provider key designed for internal use only, and then re-encrypted using a PSE-specific key before providing the snapshot to the PSE, thereby avoiding the sharing of the cloud provider internal use only key outside the cloud provider network substrate.


