Multi-Instance Data Migration for Secure Tenant Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current database systems face challenges in efficiently and securely migrating data from one data center to another, particularly in multi-tenant environments, where minimal disruption and high security are crucial.
Innovation Solution
The system employs multiple computing instances with specific rights to isolate, enumerate, and transfer data, using a data isolation system to identify and tag tenants, a migration batching component to manage batches, and a data move system to move data from a source to a target data center, ensuring secure and efficient transfer with minimal user disruption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is migrated from source data center to target data center using conventional methods, then data transfer is achieved, but security risks increase and system disruption occurs
Solution Approach 1:
The patent segments the data migration process into distinct phases: identification, enumeration, copying, and verification. Multiple computing instances are segmented with specific roles (first instance for enumeration, second instance for copying, third instance for verification). This segmentation allows secure data transfer while maintaining system stability, as each instance operates independently with limited access rights.
Solution Approach 2:
The patent introduces an intermediary data container that temporarily holds data during migration between source and target data centers. This intermediary structure enables secure data transfer without direct exposure between source and target systems, reducing security risks and minimizing disruption to ongoing operations.
2Reliability
If multiple computing instances are used with different access rights, then security is improved, but device complexity increases
Solution Approach 1:
The patent applies local quality by assigning different access rights to different computing instances based on their specific functions. The first computing instance has enumeration rights, the second has copying rights, and the third has verification rights. This localized assignment of permissions enhances security while keeping each instance's complexity manageable through role-specific access control.
Data Source
AI summary
Data to be moved from a source system to a target system, for a set of tenants, is first identified. The data is enumerated by a first computing instance in the source system to obtain an enumeration list. Data is copied from the source system to the target system based on the enumeration list by a second computing instance. The data in the source and target systems is then enumerated by a third computing instance to determine whether any data is still to be moved and another enumeration list is generated. The data still to be moved is then moved based on the other enumeration list.


