Content-Aware Cloud Storage Migration Security Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud object storage migration techniques often fail to preserve security requirements during data migration, leading to potential security breaches and compliance issues due to differences in security levels between source and target cloud object data stores.

Innovation Solution

The Content-Aware Storage Classification (CASC) system identifies security requirements of data blobs based on their content and metadata, determines suitable target cloud object data stores that match these requirements, and assigns data blobs accordingly, using artificial intelligence techniques like natural language processing and machine learning to ensure security compliance with regulations such as GDPR and HIPAA.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is migrated between cloud object data stores using existing techniques, then data migration is achieved, but security requirements are not preserved

Engineering Contradiction:
Improvesecurity requirement preservationVSAvoidcompatibility with different security levels
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies different security measures to different data blobs based on their specific security requirements. Each data blob is evaluated individually and assigned to target cloud object data stores that match its specific security needs, rather than applying a uniform security level to all data. This resolves the contradiction by making the security approach adaptable to local (individual data) requirements while maintaining overall security reliability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the security parameter (security level) of the target cloud object data store to match the security requirements of the source data. By dynamically adjusting security parameters based on data classification and requirements, the system preserves security reliability while adapting to different security levels across various target stores.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security requirements are strictly enforced during migration, then security compliance is improved, but migration flexibility and target store selection are reduced

Engineering Contradiction:
Improvesecurity complianceVSAvoidtarget cloud store selection flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the migration process into distinct phases: security requirement identification, target cloud object data store determination, and data blob assignment. This segmentation allows security compliance to be enforced systematically at each stage while maintaining flexibility in target store selection. The segmentation resolves the contradiction by making security enforcement manageable and adaptable rather than rigid.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically determines target cloud object data stores based on real-time assessment of security requirements and available target stores. Rather than statically restricting migration options, the system adaptively selects from multiple potential targets that satisfy security requirements, thus maintaining both security compliance and migration flexibility.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If manual security assessment is performed for each data migration, then security accuracy is improved, but computing resources and time are increased

Engineering Contradiction:
Improvesecurity requirement identification accuracyVSAvoidmigration efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables data blobs to effectively self-assess their security requirements through automated analysis of their characteristics and metadata. The cloud object data store itself participates in determining its security requirements, reducing the need for extensive manual assessment while maintaining high accuracy in security requirement identification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs security requirement identification and target store determination as preliminary actions before actual data migration begins. By preparing and classifying data security requirements in advance, the system achieves accurate security assessment without increasing the time and resources needed during the actual migration execution.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230237177A1Content aware storage of cloud object storage
Publication Date: 2023.07.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20230237177A1 patent drawing
  • US20230237177A1 patent drawing
  • US20230237177A1 patent drawing

AI summary

A pending data migration is detected, that is related to a set of one or more data blobs. The set of data blobs are stored on a source cloud object data store. The set of data blobs are retrieved, from the source cloud object data store. A security requirement for the set of data blobs is identified based on the set of data blobs and based on the source cloud object data store. A set of one or more potential target cloud object data stores from a set of additional cloud object data stores is determined. The set of data blobs is assigned, in response to the determination, to a first potential target cloud object data store of the set of potential target cloud object data stores. The assignment is based on the security requirement.