Transparent Data Encryption During Storage Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data migration systems are limited in transferring data extents within a logical device or combining extents from multiple devices, failing to reduce the number of unit control blocks required and not providing transparent, concurrent migration without interrupting normal data processing, especially when handling sensitive data.

Innovation Solution

A method and apparatus for migrating data extents by generating control data structures to identify and store locations, mirroring data sets, and dynamically replicating data to consolidate logical devices, while intercepting and encrypting data for secure storage and transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is transferred from older data storage facilities to newer data storage facilities to improve performance and capacity, then storage capacity and performance are improved, but data security is compromised during transfer

Engineering Contradiction:
Improvestorage capacityVSAvoiddata security
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by encrypting data before it is transferred from older to newer storage facilities. The encryption is performed in advance during the migration process, ensuring that data security is maintained throughout the transfer operation, thereby resolving the contradiction between improving storage capacity and maintaining data security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the encryption function from the data transfer process, applying it specifically to the migrated data. By isolating and applying encryption to the data being transferred, the system maintains security for sensitive data during migration while allowing normal operations to continue, thus resolving the security concern without compromising the productivity improvement from facility upgrades.

Inventive Principle:
Principle #2Taking out (Extraction)

2Device complexity

If data extents are migrated between logical devices to consolidate storage, then the number of unit control blocks is reduced, but normal data processing operations are interrupted

Engineering Contradiction:
Improvenumber of unit control blocksVSAvoiddata processing operations
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent applies preliminary action by performing encryption on data extents before completing the migration process. This allows the migration to proceed through controlled phases where data is encrypted and transferred to new logical devices, consolidating storage and reducing unit control blocks while maintaining system availability through careful timing and phased execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the data migration process into distinct phases: identifying data extents, encrypting them, transferring to target logical devices, and updating system references. This segmentation allows normal data processing to continue on non-migrated data while migration occurs on specific extents, reducing unit control blocks without completely interrupting operations.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If data is encrypted during migration to maintain security, then data security is improved, but migration complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidmigration process
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies universality by implementing encryption functionality that can be applied to any data being migrated between logical devices. The encryption mechanism is designed as a general-purpose solution that handles various data types and migration scenarios, reducing the need for specialized complexity for different encryption requirements while maintaining high security standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8281152B2Storage data encryption
Publication Date: 2012.10.02 EMC IP HLDG CO LLC
  • US8281152B2 patent drawing
  • US8281152B2 patent drawing
  • US8281152B2 patent drawing

AI summary

Managing data on a storage device includes intercepting unencrypted data to be stored on the storage device, where intercepting unencrypted data is transparent to an application storing the data on the storage device and encrypting the data prior to storage on the storage device. The storage device may include a tape drive and/or a disk drive. Managing data on a storage device may also include migrating data from a first storage location to a second storage location. The first storage location may be the same as the second storage location or the first storage location may be different from the second storage location. The unencrypted data may be intercepted during migration. Managing data on a storage device may also include decrypting data read from the storage device.