Storage Appliance Migration for Virtual Data Center Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual data centers face performance issues due to the significant computing, storage, and networking resources consumed by enforcing security policies, which can impact primary applications.
Innovation Solution
Migrating storage for workloads to storage appliances with native capabilities to facilitate the application of security policies, such as encrypting sensitive data or scanning for malware, by identifying and utilizing storage appliances with the necessary functionalities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security policies are enforced within the virtual data center using computing resources, then security compliance is achieved, but primary application performance deteriorates due to resource consumption
Solution Approach 1:
The patent extracts security policy enforcement functionality from the virtual data center computing resources and relocates it to storage appliances. This separation removes the security processing load from the application server, eliminating the performance impact while maintaining security compliance. The storage appliance independently handles encryption, scanning, and other security operations on stored data without requiring virtual data center resources.
2Reliability
If security policies are enforced by processing data through virtual data center resources, then security controls are applied, but computing resources are significantly consumed
Solution Approach 1:
The storage appliance performs security policy enforcement autonomously without requiring external processing resources. The storage appliance self-services security functions including data encryption, malware scanning, and compliance verification directly at the storage layer, eliminating the need for additional computing resources in the virtual data center to process security operations.
3Quantity of substance
If storage appliances without native security functionality are used, then storage capacity is provided, but additional computing resources are required for security policy implementation
Solution Approach 1:
The storage appliance is designed with multiple integrated functions including both storage capacity and native security policy enforcement capabilities. This multi-functionality allows a single component to provide both data storage and security controls, eliminating the need for separate security processing infrastructure and simplifying the overall system architecture while maintaining comprehensive security coverage.
Data Source
AI summary
A computer-implemented method for optimizing security controls for virtual data centers may include 1) identifying a security policy that applies to at least one workload configured to store data on a first storage appliance, 2) identifying at least one storage-appliance functionality capable of implementing at least a part of the security policy, 3) identifying a second storage appliance that possesses the storage-appliance functionality, and 4) migrating the data from the first storage appliance to the second storage appliance in response to identifying the security policy and the storage-appliance functionality. Variants include methods, systems, and computer-readable media.


