Network Data Reduction and Encryption Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network infrastructure struggles to efficiently enable encryption, deduplication, and compression features across all components simultaneously without causing inefficient storage and performance resource usage, due to dependencies and varying support levels across different infrastructure levels.
Innovation Solution
A method and system that determine an optimal combination of encryption and data reduction techniques by analyzing performance parameters and historical data from a knowledge base to configure devices within a network, considering dependencies and threshold values, to optimize storage utilization while meeting security requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption, deduplication, and compression features are enabled on all network devices simultaneously, then data security and storage efficiency are improved, but device compatibility issues and performance degradation occur
Solution Approach 1:
The patent applies local quality by enabling encryption, deduplication, and compression features selectively on specific network devices based on their individual capabilities and requirements. The system evaluates each device's support for these features and configures them locally rather than uniformly across all devices, thus maintaining data security where supported while avoiding compatibility issues on devices that don't support these features.
Solution Approach 2:
The system dynamically determines the optimal configuration of data protection features by evaluating current network conditions, device capabilities, and performance metrics. The configuration can be adjusted over time based on changing requirements and device performance, allowing the system to adapt to new devices and evolving security needs without requiring a static all-or-nothing approach.
2Reliability
If encryption, deduplication, and compression features are enabled on all network devices simultaneously, then data security and storage efficiency are improved, but system performance deteriorates
Solution Approach 1:
The patent applies local quality by enabling encryption, deduplication, and compression features selectively on specific network devices based on their individual capabilities and requirements. The system evaluates each device's support for these features and configures them locally rather than uniformly across all devices, thus maintaining data security where supported while avoiding compatibility issues on devices that don't support these features.
Solution Approach 2:
The system implements partial action by enabling data protection features on only those devices where they provide net benefit. Rather than applying all features universally, the system selectively applies encryption, deduplication, and compression to specific devices based on their capabilities and the nature of their data traffic, avoiding the performance overhead on devices where these features would be counterproductive.
3Quantity of substance
If data reduction techniques are applied aggressively to meet storage requirements, then storage utilization is optimized, but data security requirements may be compromised
Solution Approach 1:
The patent applies segmentation by separating the data protection workflow into distinct stages: encryption is performed first on sensitive data, creating ciphertext, and then deduplication and compression are applied to the encrypted data. This segmentation ensures that security requirements are met at the encryption stage while storage optimization is achieved at the deduplication and compression stages, with each stage operating independently on the output of the previous stage.
Data Source
AI summary
A specification of a target network environment including target devices is received. The specification includes an identity of each of the target devices and a compression feature requirement, a deduplication feature requirement, and an encryption feature requirement of the target network environment. A performance parameter corresponding to each of the requirements is computed based on the specification. Possible combinations of the target devices and enabled features in the target devices are determined to meet the specification. Each possible combination is compared to a knowledge base to determine a performance reduction for each of the enabled features based upon the performance parameters. A desired combination of the enabled features is determined from the possible combinations for each target device based upon the comparison. The desired combination includes a combination having a performance reduction that does not exceed a threshold value for data reduction in one or more enabled features.


