Data Migration Intermediary Preserving IP Security Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data migration systems disrupt network file system access and fail to preserve IP-based security policies during the migration process, causing interruptions and security policy inconsistencies.

Innovation Solution

A data migration system that intercepts communications between clients and source/destination file systems, replicates file system objects asynchronously, and manipulates response attributes to maintain seamless access and security policy continuity, allowing clients to transition transparently from the source to the destination file system without interruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data migration is performed using existing systems, then data can be transferred from source to destination file system, but network file system access is disrupted and IP-based security policies are not preserved

Engineering Contradiction:
Improvesecurity policy preservationVSAvoidfile system access continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a migration server as an intermediary component positioned between clients and the source/destination file systems. This mediator intercepts communications, manages the migration process, and ensures security policies are preserved by maintaining IP address mappings throughout the migration, thereby resolving the contradiction between data transfer and continuous access with policy preservation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by establishing the migration server and configuring security policy mappings before the actual data migration begins. This allows the system to pre-configure IP address preservation rules and security policy associations, ensuring that when migration occurs, security policies are automatically maintained without disrupting file system access

Inventive Principle:
Principle #10Preliminary action

2Productivity

If data migration interrupts file system access, then security policies can be maintained, but client productivity and service continuity are reduced

Engineering Contradiction:
Improvefile system access continuityVSAvoidmigration system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The migration server acts as a transparent intermediary that clients interact with normally, while it handles the complex migration logic in the background. This approach maintains simple client-side operations and continuous access, while concentrating system complexity within the migration server's interception and translation mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If IP addresses are changed during migration, then destination file system can be accessed, but IP-based security policies from source file system are lost

Engineering Contradiction:
Improvedestination file system accessibilityVSAvoidsecurity policy consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system dynamically changes the IP address parameter of the migration server to match the source file system's IP address during migration operations. This parameter change allows the migration server to impersonate the source file system to clients, ensuring IP-based security policies remain consistent while enabling access to the destination file system through the migrated data

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9300692B2System and method for implementing data migration while preserving security policies of a source filer
Publication Date: 2016.03.29 NETAPP INC
  • US9300692B2 patent drawing
  • US9300692B2 patent drawing
  • US9300692B2 patent drawing

AI summary

A data migration system in which security policies of a source file system are preserved, in an environment in which clients actively issue communications for the source filer while data is migrated to a destination file system.