Transparent Data Encryption During Storage Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data migration systems are limited in transferring data extents within a logical device or combining extents from multiple devices, failing to reduce the number of unit control blocks required and not providing transparent, concurrent migration without interrupting normal data processing, especially when handling sensitive data.
Innovation Solution
A method and apparatus for migrating data extents by generating control data structures to identify and store locations, mirroring data sets, and dynamically replicating data to consolidate logical devices, while intercepting and encrypting data for secure storage and transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is transferred from older data storage facilities to newer data storage facilities to improve performance and capacity, then storage capacity and performance are improved, but data security is compromised during transfer
Solution Approach 1:
The patent applies preliminary action by encrypting data before it is transferred from older to newer storage facilities. The encryption is performed in advance during the migration process, ensuring that data security is maintained throughout the transfer operation, thereby resolving the contradiction between improving storage capacity and maintaining data security.
Solution Approach 2:
The patent extracts the encryption function from the data transfer process, applying it specifically to the migrated data. By isolating and applying encryption to the data being transferred, the system maintains security for sensitive data during migration while allowing normal operations to continue, thus resolving the security concern without compromising the productivity improvement from facility upgrades.
2Device complexity
If data extents are migrated between logical devices to consolidate storage, then the number of unit control blocks is reduced, but normal data processing operations are interrupted
Solution Approach 1:
The patent applies preliminary action by performing encryption on data extents before completing the migration process. This allows the migration to proceed through controlled phases where data is encrypted and transferred to new logical devices, consolidating storage and reducing unit control blocks while maintaining system availability through careful timing and phased execution.
Solution Approach 2:
The patent segments the data migration process into distinct phases: identifying data extents, encrypting them, transferring to target logical devices, and updating system references. This segmentation allows normal data processing to continue on non-migrated data while migration occurs on specific extents, reducing unit control blocks without completely interrupting operations.
3Object-affected harmful factors
If data is encrypted during migration to maintain security, then data security is improved, but migration complexity increases
Solution Approach 1:
The patent applies universality by implementing encryption functionality that can be applied to any data being migrated between logical devices. The encryption mechanism is designed as a general-purpose solution that handles various data types and migration scenarios, reducing the need for specialized complexity for different encryption requirements while maintaining high security standards.
Data Source
AI summary
Managing data on a storage device includes intercepting unencrypted data to be stored on the storage device, where intercepting unencrypted data is transparent to an application storing the data on the storage device and encrypting the data prior to storage on the storage device. The storage device may include a tape drive and/or a disk drive. Managing data on a storage device may also include migrating data from a first storage location to a second storage location. The first storage location may be the same as the second storage location or the first storage location may be different from the second storage location. The unencrypted data may be intercepted during migration. Managing data on a storage device may also include decrypting data read from the storage device.


