Storage Network Data Protection Using Separate Alert Paths
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection schemes in storage systems are vulnerable to attacks like ransomware, which can corrupt or disable backup copies, rendering data recovery impossible.
Innovation Solution
Implementing a storage network with separate data paths for production data and protection information, using a data protection node that manages replicated data and implements threat detection and recovery mechanisms, while keeping operations transparent and invisible to users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If backup copies are maintained for data protection, then data recovery capability is improved, but vulnerability to ransomware attacks increases because backup copies can be corrupted or disabled
Solution Approach 1:
The system segments data protection into multiple independent components: a data protection node that receives copies of data, a separate data path for protection information, and distinct storage locations for production and backup data. This segmentation ensures that even if one component is compromised by ransomware, other components remain functional and can still enable data recovery.
Solution Approach 2:
The patent introduces a data protection node as an intermediary component between the production storage system and the backup storage. This intermediary receives data copies, manages protection information separately, and can restore data even when the original production data is encrypted by ransomware, thus mediating the vulnerability between backup maintenance and ransomware attacks.
2Reliability
If separate data paths are used for production data and protection information, then security against attacks is improved, but device complexity increases
Solution Approach 1:
The data protection node is designed as a multi-functional component that handles multiple tasks: receiving data copies from production storage, storing protection information separately, detecting data protection conditions, and executing restoration operations. This consolidation of multiple functions into a single node reduces the overall system complexity while maintaining separate data paths for security.
Solution Approach 2:
The data protection node autonomously performs data protection operations without requiring continuous user intervention. It automatically receives data copies, manages protection information, detects when data protection conditions occur, and executes restoration operations independently, thereby simplifying the operational complexity of the separate data path architecture.
3Ease of operation
If data protection operations are kept transparent and invisible to users, then ease of operation is improved, but difficulty of detecting and measuring protection effectiveness worsens
Solution Approach 1:
The system implements feedback mechanisms where the data protection node monitors data protection conditions and can report status information. The node tracks when data copies are received, when protection information is stored, and when restoration operations are executed, providing feedback about protection effectiveness while maintaining transparent operation for end users.
Data Source
AI summary
An apparatus may include a storage medium, at least one communication interface configured to receive storage data, and at least one control circuit configured to perform one or more operations including transferring, using the at least one communication interface, protection information for the storage data, and storing, in the storage medium, based on the protection information, the storage data. The transferring the protection information may include receiving, using the at least one communication interface, alert information. The at least one control circuit may be further configured to perform an operation including detecting a data protection condition, and the transferring the protection information may include sending, using the at least one communication interface, based on the detecting, alert information. The at least one control circuit may be further configured to perform, based on the protection information, a data protection operation. The data protection operation may include a data lock operation.


