Database Volume Mapping Without Agent Installation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In hybrid cloud data services, it is challenging to immediately identify and delete data corresponding to a database due to the complexity of mapping between database applications and storage volumes, especially when multiple databases and storage systems are involved, and existing solutions require installing agents that pose security risks and logistical difficulties in acquiring authentication information.

Innovation Solution

A management system that detects the relation between a database and a volume by accessing authentication information, monitoring access patterns, and managing the relationship without the need for an agent installation, utilizing side channel analysis techniques, data catalogs, and performance data to automate the detection process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If an agent is installed on the server to detect the mapping between database application and storage volume, then the detection capability is improved, but the security risk increases due to authentication information sharing

Engineering Contradiction:
Improvedetection capabilityVSAvoidsecurity risk
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication information from the server environment and stores it externally in a data catalog. The agent on the server only needs to query this external catalog rather than containing or sharing authentication credentials, thus eliminating the security risk while maintaining detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a data catalog as an intermediary component that stores authentication information and mapping relationships. This mediator allows the agent to detect volume mappings without directly accessing or sharing sensitive authentication information between systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If an agent is installed on each virtual machine to detect database-volume mapping, then the detection accuracy is improved, but the operational complexity increases due to manual authentication information acquisition

Engineering Contradiction:
Improvedetection accuracyVSAvoidoperational complexity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent creates a universal data catalog that serves all virtual machines and database applications centrally. Instead of each VM requiring separate authentication configuration, the universal catalog stores all authentication information and mapping relationships, allowing any agent to query the same centralized repository and achieve accurate detection without manual configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary action by pre-collecting and storing all authentication information and database-volume mapping relationships in the data catalog before the detection process begins. This preliminary setup eliminates the need for manual authentication acquisition during operation, reducing operational complexity while maintaining detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11748317B2Management system, method for management by management system, and recording medium
Publication Date: 2023.09.05 HITACHI VANTARA LTD
  • US11748317B2 patent drawing
  • US11748317B2 patent drawing
  • US11748317B2 patent drawing

AI summary

Provided is a management system for managing a relation between a database and a volume without installing an agent. A management system manages a relation between a data catalog and a volume of a storage system storing data to be used by the data catalog. A processor of the management system accesses data that is included in the data catalog and that includes authentication information of the volume; detects the number of accesses to the volume in a time range including a timing of the access to the data; and manages the relation between the data catalog and the volume on the basis of the number of accesses.