Tape Failover via Clustered Encryption Key Broadcasting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In tape failover systems, when a security appliance in the primary path fails, the alternative path may not have the necessary encryption key, leading to failed operations due to lack of encryption information.

Innovation Solution

Implementing a system where encryption keys are broadcast to all security appliances in a cluster, allowing secondary paths to encrypt and decrypt data, and using external key servers for storage, ensuring seamless failover across a cluster of security appliances between a host and a tape backup system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If alternative paths are provided for tape failover, then system reliability is improved, but encryption key availability deteriorates because secondary paths lack the necessary encryption keys

Engineering Contradiction:
Improvetape failover capabilityVSAvoidencryption key availability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary actions by having the primary security appliance broadcast encryption keys to all secondary security appliances before failover occurs. This ensures that when failover is needed, the secondary appliances already possess the necessary encryption keys to immediately continue operation without interruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism where the primary security appliance acts as a key distributor, broadcasting encryption keys to secondary appliances through a network communication channel. This intermediary key distribution system resolves the contradiction by enabling secondary paths to obtain encryption keys without compromising the security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If encryption keys are broadcast to all security appliances, then failover operational continuity is improved, but key security management complexity increases

Engineering Contradiction:
Improveoperational continuity during failoverVSAvoidkey management system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal key management approach where a single primary security appliance serves multiple functions: it acts as both a security appliance for data encryption and as a key distribution center for all secondary appliances. This multi-functionality reduces overall system complexity compared to having separate key management systems for each appliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Secondary security appliances automatically receive and store encryption keys through broadcast from the primary appliance without requiring manual key management or complex key distribution protocols. This self-service approach simplifies key management by eliminating the need for administrators to manually configure key sharing between multiple appliances.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8160257B1Tape failover across a cluster
Publication Date: 2012.04.17 NETAPP INC
  • US8160257B1 patent drawing
  • US8160257B1 patent drawing
  • US8160257B1 patent drawing

AI summary

A security appliance that encrypts and decrypts information is installed in each of redundant multi-paths between a host system and a back up tape storage system. The host system is arranged to detect failures in a primary path to the tape system being used. When the failure is detected, the host system enables transfers to the same tape system through an alternative path. Encryption keys and host/tape designators (identifiers) are broadcast among the security appliances in the alternative data paths. When the host system switches from the primary path to the secondary path, even though the secondary security appliance did not generate the encryption keys, the secondary path security appliance will have such keys and will properly encrypt and transfer data from the host to the tape system. The secondary will also properly retrieve encrypted data from the tape system, decrypt it and deliver it to the host. All of these operations will be transparent (invisible) to a running application in the host.