Encrypted Logical-Volume Replication Across Untrusted Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing systems face challenges in securely and efficiently replicating data between untrusted private computing networks while managing disparities in data storage sizes and ensuring data integrity and trust between unaffiliated networks.
Innovation Solution
A method involving encryption and one-time-use keys is employed to facilitate secure data replication and manipulation between untrusted private computing networks, with mechanisms for negotiating storage agreements and preventing unauthorized data manipulation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is replicated between untrusted private computing networks, then data backup and availability are improved, but data security and trust are compromised
Solution Approach 1:
The patent applies preliminary action by encrypting data with one-time-use keys before replication to untrusted networks. The encryption is performed in advance, so that even if the replicated data is intercepted or accessed unauthorizedly during transmission or storage, it remains secure. This pre-encryption approach ensures data security is maintained while enabling replication to untrusted networks for backup and availability.
Solution Approach 2:
The patent uses encryption keys as an intermediary mechanism between trusted and untrusted networks. The one-time-use keys act as a mediator that allows data to be securely replicated across untrusted networks without compromising security. The keys enable controlled access and ensure that only authorized parties can decrypt and access the replicated data, thus bridging the trust gap between networks.
2Object-affected harmful factors
If encryption is applied to replicated data, then data security is improved, but data manipulation capability deteriorates
Solution Approach 1:
The patent applies self-service by enabling the replicated data to be automatically decrypted and manipulated at the destination network using the one-time-use keys. The system is designed so that the encrypted data can be seamlessly decrypted and manipulated without requiring manual intervention or compromising security. This allows automated data operations while maintaining encryption-based security throughout the replication and manipulation process.
3Reliability
If reciprocal storage agreements are negotiated between networks, then trust and data integrity are improved, but system complexity increases
Solution Approach 1:
The patent applies parameter changes by transforming the trust relationship between networks into verifiable parameters such as encryption key validation and data integrity checks. Instead of complex qualitative trust negotiations, the system uses quantitative parameters like key matching, data checksums, and protocol compliance to establish and verify reciprocal storage agreements. This simplifies the negotiation mechanism while maintaining data integrity and trust.
Data Source
AI summary
Different management applications corresponding to different private computing systems that are untrusted with respect to each other reciprocally agree to store for each other replicated versions of logical volumes of storage arrays as backups. A management server corresponding to one or more storage arrays at a local one of the computing systems encrypts a volume to be backed up at the other remote computing system and transmits the encrypted version to the remote computing system. The remote computing system cannot modify or delete a portion of an array that has stored thereon the encrypted version of the logical volume without having a configuration-change key generated by the local management server, which may generate the configuration-change key to facilitate mirroring at the remote storage array a modification made to the local storage array.


