Data Storage Migration Based on Vulnerability Classifications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data storage systems in clusters fail to account for security vulnerabilities, putting sensitive data at risk by storing it on vulnerable systems, which can lead to data corruption and inefficiencies in storage usage.
Innovation Solution
A method to dynamically classify data and assess storage system vulnerabilities, allowing for conditional migration of data from vulnerable to secure storage systems based on predetermined security criteria, ensuring only secure systems store sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is stored on all storage systems within a cluster for load balancing and resource utilization, then storage efficiency and resource utilization are improved, but data security deteriorates because vulnerable storage systems may compromise sensitive data
Solution Approach 1:
The patent applies local quality by assigning different security levels to different storage systems within the cluster based on their vulnerability characteristics. Each storage system is evaluated and tagged with a security level (e.g., secure, vulnerable, deprecated), and data placement policies are customized accordingly. Sensitive data is restricted to storage systems with 'secure' tags, while less sensitive data can be placed on systems with lower security ratings, thereby maintaining high storage efficiency while protecting critical data.
Solution Approach 2:
The patent changes the parameter of data placement from uniform distribution across all storage systems to selective placement based on dynamically determined security parameters. The system continuously monitors storage system characteristics (hardware, software, firmware versions) and adjusts security levels and data placement policies in response to vulnerability updates, patch applications, and deprecation events, optimizing both security and storage utilization over time.
2Reliability
If data migration is performed frequently to maintain optimal security positioning, then data security is improved, but system performance and operational complexity worsen due to continuous data movement
Solution Approach 1:
The patent applies preliminary action by proactively monitoring and evaluating storage system security characteristics before data placement decisions are made. The system continuously assesses storage system vulnerability levels, applies security patches, and updates deprecation status in advance. When a storage system transitions from secure to vulnerable status, the system preemptively identifies affected sensitive data and initiates migration before security incidents can occur, rather than reacting after breaches happen.
Solution Approach 2:
The patent implements dynamics by making data placement policies flexible and adaptive rather than static. The system dynamically adjusts security levels of storage systems based on real-time characteristics such as patch status, hardware/software version updates, and vulnerability database changes. Data placement policies are automatically recalculated and adjusted in response to these dynamic conditions, allowing the system to optimize security positioning without requiring constant manual intervention or excessive data shuffling.
3Reliability
If strict security criteria are applied to data placement, then data security is improved, but storage space utilization deteriorates because fewer storage systems are eligible to store data
Solution Approach 1:
The patent applies local quality by implementing differentiated security requirements for different data types and storage systems. Instead of applying uniform strict security criteria to all data, the system classifies data by sensitivity level and matches it with appropriately rated storage systems. Sensitive data requiring high security is placed only on storage systems with 'secure' tags, while less sensitive data can be placed on systems with 'vulnerable' or 'deprecated' tags, thereby maximizing storage space utilization while maintaining adequate security for each data class.
Solution Approach 2:
The patent changes the parameter of security criteria from fixed and uniform to variable and data-specific. The system adjusts security requirements based on data classification, storage system characteristics, and risk tolerance parameters. As storage systems transition between security states (secure → vulnerable → deprecated), the system dynamically modifies which data can be placed on them, allowing flexible optimization of both security and storage utilization without imposing unnecessarily restrictive constraints.
Data Source
AI summary
A computer-implemented method according to one embodiment includes determining a classification associated with an instance of data, determining a vulnerability level of a first storage system at which the instance of data is currently located, and conditionally migrating the instance of data from the first storage system to a second storage system, based on the classification associated with the instance of data and the vulnerability level of the first storage system.


