Tag-Based Policy Architecture for Virtualized Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computing environments, existing security infrastructures often fail to prevent unauthorized copying or replication of confidential data across regions or cloud service providers, despite network-level protections, leaving customers without reliable data protection and limited flexibility in data replication solutions.

Innovation Solution

A tag-based policy architecture is implemented using cryptographically-verifiable metadata to authenticate and authorize access to virtualized storage resources, with a centralized control plane and distributed metavisors enforcing data policies by applying volume tags that are cryptographically bound to data encryption keys, ensuring secure data access and replication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network-level security protection is implemented, then data security is improved, but unauthorized copying of confidential data can still occur

Engineering Contradiction:
Improvedata securityVSAvoidunauthorized copying
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments data protection into multiple layers: network-level security, volume-level encryption, and tag-based access control. Each layer addresses specific security gaps, with volume tags providing fine-grained control over data replication and access that network security alone cannot provide

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite security architecture combining network security infrastructure with cryptographic volume encryption and metadata tagging. This multi-component system integrates different security mechanisms (firewalls, encryption algorithms, policy enforcement) to provide comprehensive protection that prevents both network attacks and unauthorized data copying

Inventive Principle:
Principle #40Composite materials

2Adaptability or versatility

If data replication across regions and CSPs is enabled, then data accessibility and flexibility are improved, but data protection and compliance control are worsened

Engineering Contradiction:
Improvedata replication flexibilityVSAvoiddata protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies volume tags and encryption configurations to data volumes before replication occurs. The control plane pre-establishes security policies, encryption keys, and access controls that travel with the replicated data, ensuring protection is maintained across regions and CSPs without requiring post-replication security configuration

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a control plane as an intermediary that manages security policies and coordinates between different CSPs and regions. The control plane enforces data protection rules, manages encryption key distribution, and validates volume tags during replication operations, maintaining security control while enabling flexible cross-region data movement

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cryptographic verification of volume tags is implemented, then data access security is improved, but system complexity is worsened

Engineering Contradiction:
Improvedata access securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-verification through cryptographic signatures embedded in volume tags. The metadata itself contains the means to verify its authenticity (digital signatures, hash values), allowing the system to automatically validate data integrity and access permissions without requiring complex external verification infrastructure

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms security verification from a complex process into simple parameter validation. By encoding security attributes as structured metadata parameters with standardized formats, the system reduces cryptographic verification to comparing and validating predefined parameters, significantly simplifying the verification process while maintaining strong security

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10509914B1Data policy implementation in a tag-based policy architecture
Publication Date: 2019.12.17 VMWARE INC
  • US10509914B1 patent drawing
  • US10509914B1 patent drawing
  • US10509914B1 patent drawing

AI summary

A technique implements data policy deployed in a tag-based policy architecture of a virtualized computing environment. Implementation of the data policy may include applying volume tags to data stored on virtualized storage resources, such as disks organized as volumes, based on instances that generate the data, contents of the data, and/or sensitivity of the data. The volume tags may be applied in a cryptographically strong manner to prevent tampering of the tagged data. To that end, the volume tags are cryptographically associated with the data, wherein such association is effected by binding the tags to a data encryption key stored on the volumes (disks) and used to encrypt/decrypt the data stored on the volumes.