Security Module for Data Center SAN Failure Continuity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Geographically distributed data centers face challenges in maintaining data security and integrity while ensuring efficient data synchronization and continuity, particularly in scenarios where latency and downtime need to be minimized.
Innovation Solution
Implementing a security module that generates a secure string based on UTC system time and configuration parameters, encrypts it, and appends it to a SAN failure notification, allowing secure data continuity operations between data centers by validating encrypted requests through a second security module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is synchronized between geographically distributed data centers, then data availability is improved, but data security and integrity may be compromised during transmission
Solution Approach 1:
The system performs preliminary encryption of data before transmission between data centers. The security module encrypts data using encryption keys stored in secure elements, ensuring that data is protected before it leaves the source data center, thus preventing security threats during transmission while maintaining data availability.
Solution Approach 2:
The patent introduces a security module as an intermediary component between data centers. This security module manages encryption keys, performs encryption/decryption operations, and validates data integrity, acting as a mediator that protects data during synchronization while enabling data availability.
2Object-affected harmful factors
If security measures are implemented for data transmission, then data security is improved, but transmission latency increases
Solution Approach 1:
Encryption keys are pre-generated and stored in secure elements before data transmission occurs. This preliminary setup eliminates the need for time-consuming key exchange or generation during actual data synchronization, reducing transmission latency while maintaining strong security measures.
Solution Approach 2:
The security module performs encryption and decryption operations autonomously using pre-stored keys in secure elements, without requiring external authentication or key management interventions during transmission, thus minimizing the time overhead of security measures.
3Stability of the object's composition
If data is encrypted and validated between data centers, then data integrity is improved, but system complexity increases
Solution Approach 1:
The patent combines the security module with the existing data center infrastructure, integrating encryption key storage in secure elements and encryption operations into the data synchronization workflow. This merging approach maintains data integrity while avoiding the need for completely separate, complex security systems.
Solution Approach 2:
The security module serves multiple functions: storing encryption keys, performing encryption/decryption, and validating data integrity. This multi-functional design reduces overall system complexity by consolidating security operations into a single versatile component rather than requiring separate mechanisms for each function.
Data Source
AI summary
A method for managing data availability includes making a first determination by a first security module (FSM) that a first storage area network (SAN) infrastructure in a first data center has experienced a failure. The method also includes generating a secure string based on a first configuration parameter. Further, the method includes appending the secure string to a SAN failure notification to generate a secure string-appended request. In addition, the method includes sending the secure string-appended request to a second data center, wherein the second data center is selected based on a second configuration parameter. Moreover, the method includes making a second determination that the encrypted secure string-appended request is valid. Further, the method includes offloading processing of requests sent to the first data center using the second data center.


