Data Storage Migration Based on Vulnerability Classifications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage systems in clusters fail to account for security vulnerabilities, putting sensitive data at risk by storing it on vulnerable systems, which can lead to data corruption and inefficiencies in storage usage.

Innovation Solution

A method to dynamically classify data and assess storage system vulnerabilities, allowing for conditional migration of data from vulnerable to secure storage systems based on predetermined security criteria, ensuring only secure systems store sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is stored on all storage systems within a cluster for load balancing and resource utilization, then storage efficiency and resource utilization are improved, but data security deteriorates because vulnerable storage systems may compromise sensitive data

Engineering Contradiction:
Improvestorage efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by assigning different security levels to different storage systems within the cluster based on their vulnerability characteristics. Each storage system is evaluated and tagged with a security level (e.g., secure, vulnerable, deprecated), and data placement policies are customized accordingly. Sensitive data is restricted to storage systems with 'secure' tags, while less sensitive data can be placed on systems with lower security ratings, thereby maintaining high storage efficiency while protecting critical data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of data placement from uniform distribution across all storage systems to selective placement based on dynamically determined security parameters. The system continuously monitors storage system characteristics (hardware, software, firmware versions) and adjusts security levels and data placement policies in response to vulnerability updates, patch applications, and deprecation events, optimizing both security and storage utilization over time.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If data migration is performed frequently to maintain optimal security positioning, then data security is improved, but system performance and operational complexity worsen due to continuous data movement

Engineering Contradiction:
Improvedata securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by proactively monitoring and evaluating storage system security characteristics before data placement decisions are made. The system continuously assesses storage system vulnerability levels, applies security patches, and updates deprecation status in advance. When a storage system transitions from secure to vulnerable status, the system preemptively identifies affected sensitive data and initiates migration before security incidents can occur, rather than reacting after breaches happen.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by making data placement policies flexible and adaptive rather than static. The system dynamically adjusts security levels of storage systems based on real-time characteristics such as patch status, hardware/software version updates, and vulnerability database changes. Data placement policies are automatically recalculated and adjusted in response to these dynamic conditions, allowing the system to optimize security positioning without requiring constant manual intervention or excessive data shuffling.

Inventive Principle:
Principle #15Dynamics

3Reliability

If strict security criteria are applied to data placement, then data security is improved, but storage space utilization deteriorates because fewer storage systems are eligible to store data

Engineering Contradiction:
Improvedata securityVSAvoidstorage space utilization
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by implementing differentiated security requirements for different data types and storage systems. Instead of applying uniform strict security criteria to all data, the system classifies data by sensitivity level and matches it with appropriately rated storage systems. Sensitive data requiring high security is placed only on storage systems with 'secure' tags, while less sensitive data can be placed on systems with 'vulnerable' or 'deprecated' tags, thereby maximizing storage space utilization while maintaining adequate security for each data class.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of security criteria from fixed and uniform to variable and data-specific. The system adjusts security requirements based on data classification, storage system characteristics, and risk tolerance parameters. As storage systems transition between security states (secure → vulnerable → deprecated), the system dynamically modifies which data can be placed on them, allowing flexible optimization of both security and storage utilization without imposing unnecessarily restrictive constraints.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11042646B2Selecting data storage based on data and storage classifications
Publication Date: 2021.06.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11042646B2 patent drawing
  • US11042646B2 patent drawing
  • US11042646B2 patent drawing

AI summary

A computer-implemented method according to one embodiment includes determining a classification associated with an instance of data, determining a vulnerability level of a first storage system at which the instance of data is currently located, and conditionally migrating the instance of data from the first storage system to a second storage system, based on the classification associated with the instance of data and the vulnerability level of the first storage system.