Tag-Based Policy Architecture for Virtualized Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized computing environments, existing security infrastructures often fail to prevent unauthorized copying or replication of confidential data across regions or cloud service providers, despite network-level protections, leaving customers without reliable data protection and limited flexibility in data replication solutions.
Innovation Solution
A tag-based policy architecture is implemented using cryptographically-verifiable metadata to authenticate and authorize access to virtualized storage resources, with a centralized control plane and distributed metavisors enforcing data policies by applying volume tags that are cryptographically bound to data encryption keys, ensuring secure data access and replication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network-level security protection is implemented, then data security is improved, but unauthorized copying of confidential data can still occur
Solution Approach 1:
The patent segments data protection into multiple layers: network-level security, volume-level encryption, and tag-based access control. Each layer addresses specific security gaps, with volume tags providing fine-grained control over data replication and access that network security alone cannot provide
Solution Approach 2:
The patent creates a composite security architecture combining network security infrastructure with cryptographic volume encryption and metadata tagging. This multi-component system integrates different security mechanisms (firewalls, encryption algorithms, policy enforcement) to provide comprehensive protection that prevents both network attacks and unauthorized data copying
2Adaptability or versatility
If data replication across regions and CSPs is enabled, then data accessibility and flexibility are improved, but data protection and compliance control are worsened
Solution Approach 1:
The patent applies volume tags and encryption configurations to data volumes before replication occurs. The control plane pre-establishes security policies, encryption keys, and access controls that travel with the replicated data, ensuring protection is maintained across regions and CSPs without requiring post-replication security configuration
Solution Approach 2:
The patent introduces a control plane as an intermediary that manages security policies and coordinates between different CSPs and regions. The control plane enforces data protection rules, manages encryption key distribution, and validates volume tags during replication operations, maintaining security control while enabling flexible cross-region data movement
3Reliability
If cryptographic verification of volume tags is implemented, then data access security is improved, but system complexity is worsened
Solution Approach 1:
The patent implements self-verification through cryptographic signatures embedded in volume tags. The metadata itself contains the means to verify its authenticity (digital signatures, hash values), allowing the system to automatically validate data integrity and access permissions without requiring complex external verification infrastructure
Solution Approach 2:
The patent transforms security verification from a complex process into simple parameter validation. By encoding security attributes as structured metadata parameters with standardized formats, the system reduces cryptographic verification to comparing and validating predefined parameters, significantly simplifying the verification process while maintaining strong security
Data Source
AI summary
A technique implements data policy deployed in a tag-based policy architecture of a virtualized computing environment. Implementation of the data policy may include applying volume tags to data stored on virtualized storage resources, such as disks organized as volumes, based on instances that generate the data, contents of the data, and/or sensitivity of the data. The volume tags may be applied in a cryptographically strong manner to prevent tampering of the tagged data. To that end, the volume tags are cryptographically associated with the data, wherein such association is effected by binding the tags to a data encryption key stored on the volumes (disks) and used to encrypt/decrypt the data stored on the volumes.


