Security Level Tagging for Storage Tier Placement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise data storage systems face challenges in securing and managing data due to lack of prior knowledge about the intended security profiles of application data, leading to difficulties in determining appropriate storage locations, encryption levels, and compliance with regulatory requirements.

Innovation Solution

Implementing a security level tagging process that assigns a data security level descriptor to files, allowing for automated placement of data in storage tiers based on its security level, ensuring that files are stored in environments with security levels greater than or equal to their own, and enabling dynamic security adjustments as data sensitivity changes over time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored without security level classification, then storage simplicity is maintained, but data security and compliance control deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidstorage management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data into different security levels (e.g., public, private, confidential, restricted) and creates separate storage tiers for each security level. This segmentation allows the system to apply appropriate security controls and encryption to each tier, improving data security while maintaining manageable complexity through organized categorization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security measures and storage conditions to different portions of data based on their security level. Each security tier receives customized protection (e.g., encryption at rest, access controls, retention policies) appropriate to its sensitivity, rather than applying uniform security measures to all data.

Inventive Principle:
Principle #3Local quality

2Reliability

If all data is encrypted with high security measures, then data security is improved, but storage cost increases

Engineering Contradiction:
Improvedata securityVSAvoidstorage cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies encryption and security measures locally to only those data tiers that require them, based on their security classification. Public data may be stored without encryption while confidential data receives full encryption, optimizing the balance between security and storage cost by avoiding unnecessary security measures on less sensitive data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the security parameters (encryption level, access control strength, retention period) based on the data's security classification. This allows the system to adjust security measures dynamically according to data sensitivity, ensuring adequate protection while minimizing unnecessary security overhead and associated costs.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If security level descriptors are manually assigned to files, then data classification accuracy is improved, but operational complexity increases

Engineering Contradiction:
Improvedata classification accuracyVSAvoidoperational simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent enables files to self-categorize into appropriate security tiers based on their content, metadata, or other attributes. The system automatically analyzes files and assigns security level descriptors without requiring manual intervention, thereby maintaining classification accuracy while significantly reducing operational complexity and administrator burden.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where the system continuously monitors data access patterns, security events, and compliance requirements, and automatically adjusts security level assignments and tier placements. This feedback loop ensures accurate classification while automating the process, eliminating the need for manual reclassification.

Inventive Principle:
Principle #23Feedback

4Ease of operation

If data is stored in a single location, then storage management is simplified, but compliance with regional regulations deteriorates

Engineering Contradiction:
Improvestorage management simplicityVSAvoidregulatory compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data storage across multiple geographic locations and jurisdictions, creating separate storage tiers for different regions. This segmentation allows the system to comply with regional data sovereignty laws and regulations by keeping data within appropriate geographic boundaries, while maintaining simplified management through centralized control of the tiering system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies location-specific storage policies and compliance measures to data based on its security level and regulatory requirements. Each geographic region receives customized storage treatment appropriate to local laws, while the overall system maintains simplified management through automated policy enforcement and centralized monitoring.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12072992B2Data security classification for storage systems using security level descriptors
Publication Date: 2024.08.27 EMC IP HLDG CO LLC
  • US12072992B2 patent drawing
  • US12072992B2 patent drawing
  • US12072992B2 patent drawing

AI summary

A security level tagging process to enable a user to associate a security level descriptor with a file, or a namespace directory where files and subdirectories inherit the security level descriptor from a parent directory. A parser can be used to automatically set a security level descriptor based on the contents of the file and/or attributes of files, or an administrator can associate a security level to a storage tier in the file system so that files are placed on the storage tiers with the matching security level as the file security level descriptor. The placement of the file on a storage tier depends on the data security level descriptor of the file and the security level of the storage so that files are placed on tiers where security level associated with the tier is greater than or equal to data security level of the file. Files can be migrated among storage tiers as their security levels may change.