Secure Data Replication Access Policy for Heterogeneous Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data replication techniques lack security for heterogeneous storage controllers, where different architectures and operating systems complicate secure data transfer across networks, making unauthorized access a risk, especially in disaster recovery scenarios.
Innovation Solution
Establishing an access policy with authentication and authorization mechanisms, such as password or certificate authentication, and access control, to securely replicate data between heterogeneous storage controllers, ensuring only authorized access and encryption when necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data replication is implemented between heterogeneous storage controllers with different architectures and operating systems, then data redundancy and disaster recovery capabilities are improved, but security risks and unauthorized access vulnerabilities increase
Solution Approach 1:
The patent introduces an access policy as an intermediary layer between heterogeneous storage controllers. This access policy includes authentication mechanisms (password or certificate-based) and authorization rules that mediate data replication requests, ensuring that only authenticated and authorized controllers can access replicated data, thus preventing unauthorized access while maintaining replication functionality across different architectures and operating systems
Solution Approach 2:
The patent changes the security parameters by implementing dynamic authentication and authorization mechanisms. The access policy can be configured with different authentication methods (password or certificate) and can dynamically adjust authorization levels based on the replication scenario, allowing the system to adapt security settings to match the specific needs of heterogeneous storage controller environments
2Reliability
If access control mechanisms are implemented for secure data replication, then security is improved, but system complexity increases
Solution Approach 1:
The access policy is designed as a universal mechanism that can be applied across different storage controller architectures and operating systems. It provides multi-functional security capabilities including authentication, authorization, and access control in a single integrated framework, reducing the need for separate security implementations for each controller type and thereby managing complexity
3Reliability
If authentication and authorization mechanisms are established between storage controllers, then unauthorized access is prevented, but data transfer overhead increases
Solution Approach 1:
The patent implements preliminary authentication and authorization actions by establishing access policies before data replication begins. The authentication (password or certificate verification) and authorization (access rule validation) are performed upfront, allowing subsequent data transfers to proceed with verified credentials, thereby minimizing repeated authentication overhead during actual replication operations
Data Source
AI summary
One or more techniques and/or computing devices are provided for secure data replication. For example, a first storage controller may host first storage within which storage resources (e.g., files, logical unit numbers (LUNs), volumes, etc.) are stored. The first storage controller may establish an access policy with a001 second storage controller to which data is to be replicated from the first storage. The access policy may define an authentication mechanism for the first storage controller to authenticate the second storage controller, an authorization mechanism specifying a type of access that the second storage controller has for a storage resource, and an access control mechanism specifying how the second storage controller's access to data of the storage resource is to be controlled. In this way, data replication requests may be authenticated and authorized so that data may be provided, according to the access control mechanism, in a secure manner.


