Storage Appliance Migration for Virtual Data Center Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual data centers face performance issues due to the significant computing, storage, and networking resources consumed by enforcing security policies, which can impact primary applications.

Innovation Solution

Migrating storage for workloads to storage appliances with native capabilities to facilitate the application of security policies, such as encrypting sensitive data or scanning for malware, by identifying and utilizing storage appliances with the necessary functionalities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are enforced within the virtual data center using computing resources, then security compliance is achieved, but primary application performance deteriorates due to resource consumption

Engineering Contradiction:
Improvesecurity complianceVSAvoidapplication performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts security policy enforcement functionality from the virtual data center computing resources and relocates it to storage appliances. This separation removes the security processing load from the application server, eliminating the performance impact while maintaining security compliance. The storage appliance independently handles encryption, scanning, and other security operations on stored data without requiring virtual data center resources.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If security policies are enforced by processing data through virtual data center resources, then security controls are applied, but computing resources are significantly consumed

Engineering Contradiction:
Improvesecurity control effectivenessVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The storage appliance performs security policy enforcement autonomously without requiring external processing resources. The storage appliance self-services security functions including data encryption, malware scanning, and compliance verification directly at the storage layer, eliminating the need for additional computing resources in the virtual data center to process security operations.

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If storage appliances without native security functionality are used, then storage capacity is provided, but additional computing resources are required for security policy implementation

Engineering Contradiction:
Improvestorage capacityVSAvoidsystem architecture
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The storage appliance is designed with multiple integrated functions including both storage capacity and native security policy enforcement capabilities. This multi-functionality allows a single component to provide both data storage and security controls, eliminating the need for separate security processing infrastructure and simplifying the overall system architecture while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9171178B1Systems and methods for optimizing security controls for virtual data centers
Publication Date: 2015.10.27 CA TECH INC
  • US9171178B1 patent drawing
  • US9171178B1 patent drawing
  • US9171178B1 patent drawing

AI summary

A computer-implemented method for optimizing security controls for virtual data centers may include 1) identifying a security policy that applies to at least one workload configured to store data on a first storage appliance, 2) identifying at least one storage-appliance functionality capable of implementing at least a part of the security policy, 3) identifying a second storage appliance that possesses the storage-appliance functionality, and 4) migrating the data from the first storage appliance to the second storage appliance in response to identifying the security policy and the storage-appliance functionality. Variants include methods, systems, and computer-readable media.