Encrypted Logical-Volume Replication Across Untrusted Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing systems face challenges in securely and efficiently replicating data between untrusted private computing networks while managing disparities in data storage sizes and ensuring data integrity and trust between unaffiliated networks.

Innovation Solution

A method involving encryption and one-time-use keys is employed to facilitate secure data replication and manipulation between untrusted private computing networks, with mechanisms for negotiating storage agreements and preventing unauthorized data manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is replicated between untrusted private computing networks, then data backup and availability are improved, but data security and trust are compromised

Engineering Contradiction:
Improvedata availabilityVSAvoiddata security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by encrypting data with one-time-use keys before replication to untrusted networks. The encryption is performed in advance, so that even if the replicated data is intercepted or accessed unauthorizedly during transmission or storage, it remains secure. This pre-encryption approach ensures data security is maintained while enabling replication to untrusted networks for backup and availability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses encryption keys as an intermediary mechanism between trusted and untrusted networks. The one-time-use keys act as a mediator that allows data to be securely replicated across untrusted networks without compromising security. The keys enable controlled access and ensure that only authorized parties can decrypt and access the replicated data, thus bridging the trust gap between networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encryption is applied to replicated data, then data security is improved, but data manipulation capability deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata manipulation
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies self-service by enabling the replicated data to be automatically decrypted and manipulated at the destination network using the one-time-use keys. The system is designed so that the encrypted data can be seamlessly decrypted and manipulated without requiring manual intervention or compromising security. This allows automated data operations while maintaining encryption-based security throughout the replication and manipulation process.

Inventive Principle:
Principle #25Self-service

3Reliability

If reciprocal storage agreements are negotiated between networks, then trust and data integrity are improved, but system complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidnegotiation mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming the trust relationship between networks into verifiable parameters such as encryption key validation and data integrity checks. Instead of complex qualitative trust negotiations, the system uses quantitative parameters like key matching, data checksums, and protocol compliance to establish and verify reciprocal storage agreements. This simplifies the negotiation mechanism while maintaining data integrity and trust.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12418550B2Untrusted remote replication partnering
Publication Date: 2025.09.16 DELL PROD LP
  • US12418550B2 patent drawing
  • US12418550B2 patent drawing
  • US12418550B2 patent drawing

AI summary

Different management applications corresponding to different private computing systems that are untrusted with respect to each other reciprocally agree to store for each other replicated versions of logical volumes of storage arrays as backups. A management server corresponding to one or more storage arrays at a local one of the computing systems encrypts a volume to be backed up at the other remote computing system and transmits the encrypted version to the remote computing system. The remote computing system cannot modify or delete a portion of an array that has stored thereon the encrypted version of the logical volume without having a configuration-change key generated by the local management server, which may generate the configuration-change key to facilitate mirroring at the remote storage array a modification made to the local storage array.