Security Level Tagging for Storage Tier Placement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise data storage systems face challenges in securing and managing data due to lack of prior knowledge about the intended security profiles of application data, leading to difficulties in determining appropriate storage locations, encryption levels, and compliance with regulatory requirements.
Innovation Solution
Implementing a security level tagging process that assigns a data security level descriptor to files, allowing for automated placement of data in storage tiers based on its security level, ensuring that files are stored in environments with security levels greater than or equal to their own, and enabling dynamic security adjustments as data sensitivity changes over time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored without security level classification, then storage simplicity is maintained, but data security and compliance control deteriorate
Solution Approach 1:
The patent segments data into different security levels (e.g., public, private, confidential, restricted) and creates separate storage tiers for each security level. This segmentation allows the system to apply appropriate security controls and encryption to each tier, improving data security while maintaining manageable complexity through organized categorization.
Solution Approach 2:
The patent applies different security measures and storage conditions to different portions of data based on their security level. Each security tier receives customized protection (e.g., encryption at rest, access controls, retention policies) appropriate to its sensitivity, rather than applying uniform security measures to all data.
2Reliability
If all data is encrypted with high security measures, then data security is improved, but storage cost increases
Solution Approach 1:
The patent applies encryption and security measures locally to only those data tiers that require them, based on their security classification. Public data may be stored without encryption while confidential data receives full encryption, optimizing the balance between security and storage cost by avoiding unnecessary security measures on less sensitive data.
Solution Approach 2:
The patent changes the security parameters (encryption level, access control strength, retention period) based on the data's security classification. This allows the system to adjust security measures dynamically according to data sensitivity, ensuring adequate protection while minimizing unnecessary security overhead and associated costs.
3Measurement precision
If security level descriptors are manually assigned to files, then data classification accuracy is improved, but operational complexity increases
Solution Approach 1:
The patent enables files to self-categorize into appropriate security tiers based on their content, metadata, or other attributes. The system automatically analyzes files and assigns security level descriptors without requiring manual intervention, thereby maintaining classification accuracy while significantly reducing operational complexity and administrator burden.
Solution Approach 2:
The patent implements a feedback mechanism where the system continuously monitors data access patterns, security events, and compliance requirements, and automatically adjusts security level assignments and tier placements. This feedback loop ensures accurate classification while automating the process, eliminating the need for manual reclassification.
4Ease of operation
If data is stored in a single location, then storage management is simplified, but compliance with regional regulations deteriorates
Solution Approach 1:
The patent segments data storage across multiple geographic locations and jurisdictions, creating separate storage tiers for different regions. This segmentation allows the system to comply with regional data sovereignty laws and regulations by keeping data within appropriate geographic boundaries, while maintaining simplified management through centralized control of the tiering system.
Solution Approach 2:
The patent applies location-specific storage policies and compliance measures to data based on its security level and regulatory requirements. Each geographic region receives customized storage treatment appropriate to local laws, while the overall system maintains simplified management through automated policy enforcement and centralized monitoring.
Data Source
AI summary
A security level tagging process to enable a user to associate a security level descriptor with a file, or a namespace directory where files and subdirectories inherit the security level descriptor from a parent directory. A parser can be used to automatically set a security level descriptor based on the contents of the file and/or attributes of files, or an administrator can associate a security level to a storage tier in the file system so that files are placed on the storage tiers with the matching security level as the file security level descriptor. The placement of the file on a storage tier depends on the data security level descriptor of the file and the security level of the storage so that files are placed on tiers where security level associated with the tier is greater than or equal to data security level of the file. Files can be migrated among storage tiers as their security levels may change.


