Cloud Snapshot Management via Key Segmentation and Incremental Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud providers face challenges in managing snapshots for remote extensions of their network substrate, including insufficient storage capacity and security risks due to key sharing for encrypted data, which hinders efficient and secure snapshot management across different computing environments.

Innovation Solution

The solution involves maintaining snapshots at the cloud provider network substrate, allowing the remote extension to access and update them without storing the entire volume, and enforcing encryption key boundaries to prevent key sharing, ensuring secure and efficient snapshot management by decrypting and re-encrypting data as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If snapshots are stored at the remote extension, then access speed is improved, but storage capacity becomes insufficient

Engineering Contradiction:
Improvesnapshot access speedVSAvoidstorage capacity
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The patent transitions snapshot storage from a single location (remote extension) to multiple dimensions: primary storage at the cloud provider network substrate and cache/storage at the remote extension. This multi-dimensional storage architecture allows snapshots to be accessible from both locations, providing fast local access while maintaining adequate storage capacity at the cloud substrate.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If encryption keys are shared for encrypted snapshot storage, then security is improved through centralized control, but key security boundaries are compromised

Engineering Contradiction:
Improvecentralized key controlVSAvoidkey sharing security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the encryption key management into separate key stores at the cloud provider network substrate and the remote extension. Each key store contains its own encryption keys, eliminating the need to share keys across security boundaries. This segmentation maintains centralized control over snapshot data while preserving key security boundaries.

Inventive Principle:
Principle #1Segmentation

3Manufacturing precision

If entire volume data is transferred for snapshot creation, then snapshot completeness is improved, but bandwidth usage increases

Engineering Contradiction:
Improvesnapshot completenessVSAvoidbandwidth consumption
Core Design Contradiction:
Manufacturing precisionVSLoss of energy

Solution Approach 1:

The patent extracts only the necessary portions of volume data for snapshot creation rather than transferring the entire volume. By identifying and transferring only the specific data blocks that need to be snapshotted, the system maintains snapshot completeness while significantly reducing bandwidth consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

4Loss of energy

If incremental snapshots are generated at the remote extension, then bandwidth usage is reduced, but storage capacity at remote extension becomes insufficient

Engineering Contradiction:
Improvebandwidth savingsVSAvoidremote storage capacity
Core Design Contradiction:
Loss of energyVSQuantity of substance

Solution Approach 1:

The patent merges incremental snapshot storage at the remote extension with full snapshot storage at the cloud provider network substrate. This combination allows the system to benefit from reduced bandwidth usage through incremental snapshots while offloading the storage burden to the cloud substrate, thereby avoiding local storage capacity constraints.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11809735B1Snapshot management for cloud provider network extensions
Publication Date: 2023.11.07 AMAZON TECH INC
  • US11809735B1 patent drawing
  • US11809735B1 patent drawing
  • US11809735B1 patent drawing

AI summary

Systems and methods for efficient and secure management of encrypted “snapshots” for a remote provider substrate extension (“PSE”) of a cloud provider network substrate are provided. The PSE may request and obtain a snapshot from the cloud provider network substrate, restore a volume from the snapshot, make changes to data in the restored volume, and/or initiate the creation and storage of a new snapshot that includes incremental updates to the original snapshot to reflect the changes made to data in the volume. An encrypted snapshot stored within the cloud provider network substrate may be decrypted using a cloud provider key designed for internal use only, and then re-encrypted using a PSE-specific key before providing the snapshot to the PSE, thereby avoiding the sharing of the cloud provider internal use only key outside the cloud provider network substrate.