Immutable Object Locking for Cloud Snapshot Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data management systems face challenges in securely managing snapshots in cloud environments, as backup data is vulnerable to security threats, ransomware attacks, accidental deletion, and compliance issues with immutable object locking schemes that lack flexibility and incur high storage costs.

Innovation Solution

The implementation of immutable object locking for snapshot management in data management systems, which involves generating snapshots, partitioning them into data objects, storing these objects in cloud environments with applied immutable locks, and periodically extending these locks to match the retention period of the snapshots, thereby ensuring data integrity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional immutable object locking schemes are applied to all backup data, then data security and integrity are improved, but storage costs increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidstorage costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies immutable object locking selectively only to snapshot data objects that meet specific criteria (e.g., older snapshots, critical system snapshots), rather than uniformly to all backup data. This localized application maintains security for important data while avoiding the high storage costs of applying immutability universally.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The backup data is segmented into different categories based on retention policies and criticality. The system divides snapshot data objects into groups where only certain segments require immutable locking, allowing differential security approaches that balance protection needs with cost efficiency.

Inventive Principle:
Principle #1Segmentation

2Reliability

If immutable object locking is applied to prevent accidental deletion, then data integrity is improved, but flexibility in data management is reduced

Engineering Contradiction:
Improvedata integrityVSAvoiddata management flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically determines which snapshot data objects require immutable locking based on retention policies, data criticality, and temporal factors. This dynamic approach allows the immutability status to change over time and based on conditions, maintaining flexibility while ensuring integrity when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters for applying immutability from a static all-or-nothing approach to a conditional approach based on multiple parameters including snapshot age, data type, retention policy compliance, and criticality level. This allows flexible data management while maintaining integrity for appropriate data sets.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive immutable locking is implemented for ransomware protection, then security against threats is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity against threatsVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary assessment of snapshot data objects to determine which ones require immutable locking before applying the protection. This preliminary action includes evaluating retention policies, data criticality, and threat risk levels, allowing the system to proactively apply immutability only where necessary rather than implementing complex comprehensive locking.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary evaluation layer that assesses whether snapshot data objects meet the criteria for immutable locking. This intermediary component simplifies the overall system by providing a clear decision-making framework that mediates between security requirements and operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12332839B2Immutable object locking for snapshot management
Publication Date: 2025.06.17 RUBRIK INC
  • US12332839B2 patent drawing
  • US12332839B2 patent drawing
  • US12332839B2 patent drawing

AI summary

Methods, systems, and devices for data management are described. A data management system (DMS) may receive an indication of a storage configuration for an object storage location within a cloud environment. The DMS may generate a snapshot of a computing system in accordance with a backup policy associated with the computing system. The DMS may cause one or more data objects corresponding to the snapshot to be stored in the object storage location within the cloud environment in accordance with the storage configuration. The DMS may apply immutable object locks to the one or more data objects within the object storage location. The DMS may execute, in accordance with the backup policy associated with the computing system, one or more jobs that cause the respective immutable object locks for the one or more data objects to be extended one or more times during a retention period for the snapshot.