Online Data Transformation for Concurrent File Rekeying

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing rekeying solutions in data security require lengthy application downtime or maintenance windows, disrupting user applications and IT operations, as they necessitate shutting down or denying access to files during the rekeying process, which can be incomplete within specified timeframes.

Innovation Solution

A method for concurrent or contemporaneous rekeying of files with input/output processing, using metadata to track key usage and status, allowing interleaved file access and rekeying operations, ensuring data integrity and minimizing downtime through multithreaded execution and atomicity of file portions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional rekeying methods are used to ensure data security, then data security is improved, but application downtime increases and user access is disrupted

Engineering Contradiction:
Improvedata securityVSAvoidapplication downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the file into multiple portions and processes them independently. Different portions can be rekeyed at different times using different keys, allowing the rekeying operation to proceed without requiring complete system shutdown. This segmentation enables continuous access to portions of the file that are not currently being rekeyed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent establishes a mapping structure in advance that records the relationship between file portions and their corresponding keys. This preliminary action allows the system to quickly determine which key to use for each portion during rekeying operations, enabling seamless transitions between keys without requiring application downtime.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If file access is blocked during rekeying to ensure data integrity, then data integrity is improved, but productivity decreases due to denied access

Engineering Contradiction:
Improvedata integrityVSAvoidI/O operations throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different access control policies to different portions of the file based on their rekeying status. Portions currently being rekeyed are blocked from access, while portions that have been rekeyed or are not yet scheduled for rekeying remain accessible. This local quality approach ensures data integrity for rekeyed portions while maintaining productivity through continued access to other portions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces a mapping structure as an intermediary between the file portions and the rekeying process. This mapping tracks which portions are being rekeyed and coordinates access requests accordingly, allowing the system to maintain data integrity without unnecessarily blocking productive I/O operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If rekeying is performed on the entire file at once to ensure complete security transformation, then security compliance is improved, but the time required for rekeying increases significantly

Engineering Contradiction:
Improvesecurity complianceVSAvoidrekeying duration
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent divides the file into multiple portions and rekeys them independently and concurrently. This segmentation allows the rekeying operation to proceed in parallel across different portions of the file, significantly reducing the total rekeying duration while ensuring that each portion meets security compliance requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables continuous rekeying operations by allowing I/O operations to proceed concurrently with rekeying on different portions of the file. This continuity ensures that security transformation is completed efficiently without requiring complete system interruption, maintaining both compliance and operational efficiency.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP3565177B1Online data transformation
Publication Date: 2021.05.05 THALES DIS CPL USA INC
  • EP3565177B1 patent drawingFigure 1A
  • EP3565177B1 patent drawingFigure 1B
  • EP3565177B1 patent drawingFigure 2

AI summary

A method for data transformation is provided. The method includes interleaving input/output (1/0) processing of files or blocks and rekeying of the files or blocks. The method includes blocking from the rekeying the portion of the file or blocks while the portion of the file or blocks is subjected to the I/O processing and blocking from the 1/0 processing the portion of the file or blocks while the portion of the file or blocks is subjected to the rekeying. The method further includes writing metadata regarding status of the rekeying of the portion of the file or blocks, and regarding a key applied in the rekeying of the portion of the file or blocks, wherein at least one method operation is performed by a processor. A computer readable media and a system are provided also.