Tiering Preferences for Encrypted Storage Relocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tiered data storage environments, existing technologies face challenges in efficiently managing and relocating data between encrypted and non-encrypted storage tiers based on workload and activity levels, leading to suboptimal performance and security.
Innovation Solution
A method and system that utilize self-encrypting drives (SEDs) to automatically encrypt and decrypt data, allowing data to be dynamically relocated between storage tiers based on tiering preferences and requirements, including specifying settings for logical devices to move data portions between SED and non-SED tiers based on activity levels and performance characteristics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored on self-encrypting drives (SEDs) to enhance security, then data security is improved, but storage performance and accessibility are worsened due to encryption overhead
Solution Approach 1:
The system dynamically relocates data portions between SED and non-SED storage tiers based on workload activity levels. Frequently accessed data is moved to non-SED tiers for faster access, while less frequently accessed data remains on SED tiers for security. This dynamic adjustment resolves the contradiction by optimizing the trade-off between security and performance based on actual usage patterns.
Solution Approach 2:
Different portions of the same logical device are stored with different encryption characteristics based on their specific access patterns and security requirements. Hot data portions are stored on non-SED tiers for performance, while cold data portions are stored on SED tiers for security, allowing each data portion to have optimized local characteristics rather than applying a uniform encryption approach to all data.
2Productivity
If data is dynamically relocated between encrypted and non-encrypted tiers based on workload, then storage efficiency is improved, but system complexity increases
Solution Approach 1:
The storage system automatically monitors workload activity levels and performs data relocation between SED and non-SED tiers without requiring manual intervention. The system self-manages the complexity of encryption key management, data migration, and tier selection based on predefined policies, resolving the contradiction by automating the complex tasks rather than requiring manual management.
Solution Approach 2:
The patent introduces a storage management layer that acts as an intermediary between the host system and the heterogeneous storage tiers. This intermediary handles the complexity of data placement, encryption/decryption coordination, and tier selection, shielding the host system from complexity while enabling efficient data relocation between encrypted and non-encrypted storage.
3Reliability
If encryption is applied to all storage tiers, then data security is maximized, but access speed and performance are reduced
Solution Approach 1:
The storage system is segmented into multiple tiers with different encryption characteristics - SED tiers for security-critical or cold data and non-SED tiers for performance-critical or hot data. This segmentation allows the system to maximize security for data that needs it while maintaining high access speeds for data that requires fast performance, resolving the contradiction by applying different security measures to different segments of the storage system.
Data Source
AI summary
Techniques are described for storing data. A plurality of storage tiers are provided including a first set and a second set of storage tiers of physical devices. Data stored on any physical device in the first set is stored in an encrypted form. Data stored on any physical device in the second set is not stored in an encrypted form. A first value is specified for a first setting that is any of a tiering preference and tiering requirement indicating that at least one data portion of a logical device is to be stored on physical device(s) of a storage tier storing data in an encrypted form. Responsive to specifying the first value as the first setting, the at least one data portion of the logical device currently stored on physical device(s) of the second set are relocated to physical device(s) of the first set.


