Storage Tier Encryption Hinting for Data Relocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage systems in multi-tiered environments face challenges in efficiently managing and relocating data between encrypted and non-encrypted storage tiers, particularly in ensuring data security and optimizing storage capacity while maintaining performance.

Innovation Solution

A method and system that utilize a hint mechanism to direct data storage and relocation between self-encrypting drives (SED) and non-SED drives based on tiering preferences and requirements, allowing for dynamic encryption status changes and automated data movement to optimize storage utilization and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored on encrypted storage tiers (SED drives), then data security is improved, but storage capacity and performance are reduced

Engineering Contradiction:
Improvedata securityVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system dynamically moves data between encrypted and non-encrypted storage tiers based on security requirements and access patterns. The data storage system monitors data characteristics and automatically relocates data portions to appropriate tiers, making the encryption status dynamic rather than static, thereby optimizing both security and storage capacity utilization.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The storage system divides data into different portions and stores them on different types of drives based on security requirements. Not all data needs to be encrypted at all times - only portions that require security are stored on SED drives, while other portions can be stored on non-encrypted drives for capacity optimization.

Inventive Principle:
Principle #1Segmentation

2Reliability

If data is stored on encrypted storage tiers, then data security is improved, but system performance is reduced

Engineering Contradiction:
Improvedata securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts encryption status based on data access patterns and security requirements. Frequently accessed data that doesn't require security can be moved to non-encrypted tiers for faster access, while maintaining security for sensitive data portions, thereby optimizing overall system performance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different portions of the storage system have different encryption properties. The system applies encryption selectively to specific data portions or LUNs based on their security requirements, rather than uniformly encrypting all data, allowing performance-optimized non-encrypted storage for data that doesn't require security.

Inventive Principle:
Principle #3Local quality

3Productivity

If hint mechanism is used to direct data storage, then storage optimization is improved, but device complexity is increased

Engineering Contradiction:
Improvestorage optimizationVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The data storage system automatically monitors data characteristics, security requirements, and access patterns, then autonomously decides which data portions should be stored on encrypted or non-encrypted tiers. The system self-manages the complexity of hint interpretation and data relocation without requiring external intervention, optimizing storage while managing complexity internally.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9684593B1Techniques using an encryption tier property with application hinting and I/O tagging
Publication Date: 2017.06.20 EMC IP HLDG CO LLC
  • US9684593B1 patent drawing
  • US9684593B1 patent drawing
  • US9684593B1 patent drawing

AI summary

Techniques are described for storing data. A command is issued from a client to a data storage system. The data storage system includes a plurality of storage tiers comprising a first storage tier of physical storage devices and a second storage tier of physical storage devices, wherein data stored on any physical storage device of the first storage tier is stored in an encrypted form and data stored on any physical storage device of the second storage tier is not stored in an encrypted form. The command includes a hint indicating whether data stored at a first logical address range of a first logical device is stored in an encrypted form. The command is received at the data storage system. First data written to the first logical device at the first logical address range is stored on one or more physical storage devices of any of said first storage tier and said second storage tier in accordance with the hint.