Storage System Recovery Dataset Management for Security Threats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional storage systems face inefficiencies in data management and security, particularly in detecting and responding to potential security threats, and in optimizing storage operations across multiple flash drives without redundant write operations.

Innovation Solution

The implementation of a storage system architecture that includes dual storage array controllers with primary and secondary status, utilizing non-volatile random access memory (NVRAM) for quick data buffering, and employing erasure coding and mirroring schemes to ensure data redundancy and availability, along with proactive data rebuilding across storage nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional storage systems perform write operations across multiple flash drives, then data redundancy is achieved, but redundant write operations increase system complexity and reduce efficiency

Engineering Contradiction:
Improvedata redundancyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides data into multiple segments or chunks that are distributed across different flash drives. Each flash drive stores a portion of the segmented data, allowing redundancy to be achieved through systematic distribution rather than redundant copying of entire datasets. This segmentation approach reduces the complexity of managing redundant writes while maintaining data reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary actions by pre-establishing mapping relationships between data segments and flash drive locations before write operations occur. The system pre-configures erasure coding parameters and redundancy schemes, so that when data needs to be written, the segmentation and distribution across multiple drives follows predetermined patterns. This eliminates the need for complex real-time decisions during write operations, reducing system complexity while ensuring data redundancy.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional storage systems write data to multiple flash drives, then data availability is improved, but redundant write operations increase processing time

Engineering Contradiction:
Improvedata availabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-calculating and storing metadata that describes the distribution pattern of data segments across flash drives. When a write operation is needed, the system uses this pre-stored metadata to quickly determine which drives to write to and in what order, eliminating complex real-time calculations. This preliminary preparation significantly reduces processing time while maintaining data availability across multiple drives.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial action by writing data segments to a subset of flash drives in parallel rather than sequentially writing to all drives. The system identifies a sufficient number of drives needed for the required redundancy level and performs write operations only to those drives simultaneously. This partial parallelization approach reduces overall processing time compared to sequential writes while still achieving the necessary data availability.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If storage systems implement comprehensive data protection mechanisms, then security against threats is improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improvesecurity against threatsVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the storage system automatically detects, responds to, and recovers from security threats without requiring complex external intervention. The system includes automated monitoring of data integrity, automatic initiation of recovery procedures when threats are detected, and self-management of security policies. This self-service approach maintains high security against threats while reducing operational overhead by eliminating the need for complex manual security management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback mechanisms that continuously monitor the storage system for security threats and automatically adjust protection measures based on detected conditions. The system provides real-time feedback on data integrity status, threat detection results, and system health metrics, using this feedback to dynamically adjust security measures. This feedback-driven approach ensures comprehensive security while managing complexity through automated, adaptive responses rather than static, overly complex security architectures.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11675898B2Recovery dataset management for security threat monitoring
Publication Date: 2023.06.13 PURE STORAGE INC
  • US11675898B2 patent drawing
  • US11675898B2 patent drawing
  • US11675898B2 patent drawing

AI summary

An illustrative method includes a data protection system directing a storage system to generate recovery datasets over time in accordance with a data protection parameter set, the recovery datasets usable to restore data maintained by the storage system to a state corresponding to a selectable point in time, determining that the storage system is possibly being targeted by a security threat, and modifying, in response to the determining that the storage system is possibly being targeted by the security threat, the data protection parameter set for one or more of the recovery datasets.