Cross-Zone Data Segmentation for Secure Scalable Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern data storage systems face challenges in balancing scalability, security, and performance when utilizing both local and cloud-based storage resources, as different approaches often conflict and require efficient coordination of data distribution across varying security zones.
Innovation Solution
A system and method that utilizes a storage controller to map logical storage resources across different security zones, applying distribution policies to divide data into segments stored on local and cloud-based resources, ensuring security, redundancy, and performance through encryption, replication, and parity-based recovery structures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored on local storage resources, then data security and access speed are improved, but storage scalability and flexibility are limited
Solution Approach 1:
The patent divides data into multiple segments and distributes them across different storage resources in various security zones. This segmentation allows the system to maintain security by keeping sensitive data segments in secure local storage while improving scalability by storing less sensitive segments in cloud-based storage, thus resolving the contradiction between data security and storage scalability.
Solution Approach 2:
The patent applies different storage qualities to different data segments based on their security requirements. Critical data segments are stored with higher security measures in local storage zones, while non-critical segments use cloud-based storage with standard security. This local quality approach allows the system to optimize security for what matters most while gaining scalability benefits elsewhere.
2Adaptability or versatility
If data is distributed across multiple security zones, then storage scalability and flexibility are improved, but system complexity increases
Solution Approach 1:
The patent introduces a storage controller as an intermediary component that manages data distribution across multiple security zones. This intermediary handles the complexity of coordinating between different storage resources, security zones, and distribution policies, thereby enabling storage flexibility without requiring the user system to directly manage the underlying complexity.
Solution Approach 2:
The system implements feedback mechanisms where the storage controller continuously monitors the state of distributed data segments and adjusts distribution policies accordingly. This feedback loop automates the management of multi-zone storage complexity, allowing the system to maintain optimal performance and security without manual intervention.
3Reliability
If data is divided and stored in different security zones, then data availability and redundancy are improved, but data access time increases
Solution Approach 1:
The patent implements preliminary actions by pre-positioning data segments in appropriate security zones based on their access patterns and security requirements. Frequently accessed segments are placed in zones that balance security and access speed, while the system pre-establishes retrieval paths to minimize access time when data is needed, thus reducing the time penalty of distributed storage.
Data Source
AI summary
The technologies described herein are generally directed toward maintaining data coherence after an updating node fails during an update. According to an embodiment, a system can comprise a processor and a memory that can enable performance of operations including respectively mapping a logical storage resource to first and second storage resources in first and second security zones associated with first provider and second providers. The operations can further include receiving a request to store a data resource at the logical storage resource. Further, the operations can include, based on a distribution policy associated with the data resource, dividing, by the storage controller equipment, the data resource into a first storage segment stored on the first storage resource and a second storage segment stored on the second storage resource.


