Storage Array Cyber Recovery Orchestration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber resiliency and recovery solutions are inadequate for addressing pervasive logical corruption, such as ransomware, and lack effective methods for identifying and recovering 'good' data in a multi-site environment, particularly in the context of cyber security frameworks like NIST's which focus on Identify, Protect, Detect, Respond, and Recover.
Innovation Solution
A storage system that enables data replication and recovery operations by determining the host device's connectivity to a recovery storage array, generating snapshots, and synchronizing clocks to ensure data integrity, with an orchestration layer that extends disaster recovery tools to cyber recovery frameworks, allowing for immutable data copies and recovery at the object or dataset level.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data replication and recovery operations are performed in a multi-site environment, then data integrity and cyber resiliency are improved, but system complexity and difficulty of managing connectivity across sites increase
Solution Approach 1:
The patent introduces an orchestration layer as an intermediary component that manages data replication and recovery operations across multi-site environments. This orchestration layer abstracts the complexity of inter-site connectivity management, enabling reliable data replication while hiding the underlying system complexity from users and administrators.
Solution Approach 2:
The storage system is designed with multi-functional capabilities that enable it to perform both primary storage and recovery operations across multiple sites. The system can adapt its behavior based on connectivity conditions, providing universal functionality that works whether sites are directly connected or accessed indirectly through the storage network, thereby improving reliability without proportionally increasing complexity.
2Productivity
If direct connectivity access is provided to recovery storage array, then recovery speed and productivity are improved, but security risks and access control complexity increase
Solution Approach 1:
The patent implements dynamic access control mechanisms that adjust connectivity permissions based on operational context. The host device can be granted direct connectivity access to the recovery storage array when recovery operations are needed, while maintaining security through conditional access policies. This dynamic approach enables fast recovery when necessary while minimizing security risks during normal operations.
Solution Approach 2:
The orchestration layer acts as a mediator that controls and monitors access between host devices and the recovery storage array. It can provide direct connectivity access when appropriate for recovery operations while maintaining security through authenticated access control, thereby enabling productivity improvements without exposing the system to unnecessary security risks.
3Object-affected harmful factors
If indirect connectivity access is provided to recovery storage array, then security and access control are improved, but recovery speed and productivity decrease
Solution Approach 1:
The system dynamically adjusts the connectivity path between host devices and recovery storage array based on operational requirements. During normal operations, indirect connectivity through the storage network is maintained for security. During recovery operations, the system can switch to direct connectivity modes to improve recovery speed, thus balancing security control with productivity needs.
4Reliability
If snapshots are generated frequently for recovery operations, then data recovery capability and reliability are improved, but storage overhead and system resources increase
Solution Approach 1:
The patent implements dynamic snapshot management that adjusts snapshot frequency and retention policies based on data change rates, criticality of data, and available storage resources. This parameter-based approach enables the system to maintain high data recovery capability for critical data while reducing storage overhead for less critical data, thereby resolving the contradiction between reliability and storage consumption.
Data Source
AI summary
Embodiments of the present disclosure include receiving one or more input/output (IO) requests at a storage array from a host device. Furthermore, the IO requests can include at least one data replication and recovery operation. In addition, the host device's connectivity access to a recovery storage array can be determined. Data replication and recovery operations can be performed based on the host device's connectivity to the recovery storage array.


