Universal File Virtualization With Disaggregated Control and Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage systems face challenges in managing and securing data across multiple cloud services, on-premise locations, and disparate storage silos, particularly in ensuring data availability, security, and compliance with regulations like GDPR.
Innovation Solution
The implementation of a Universal File System (UFS) that provides a unified file system interface across various storage silos, enabling intelligent file-level storage virtualization, decentralized data storage, and integrated security features to ensure data accessibility, security, and compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored in multiple cloud services and on-premise locations, then data availability and security are improved, but system complexity and difficulty of management increase
Solution Approach 1:
The system segments data management into distinct components: a universal file system layer for access, a virtualization layer for abstraction, and multiple storage backends for data residency. This segmentation allows each layer to independently manage its complexity while maintaining overall system reliability through distributed storage across cloud and on-premise locations.
Solution Approach 2:
The patent introduces a universal file system and storage virtualization layer as intermediaries between applications and diverse storage backends. These intermediaries abstract the complexity of managing data across multiple cloud services and on-premise locations, providing a unified access interface while maintaining data availability and security through decentralized storage.
2Reliability
If data is stored in multiple cloud services and on-premise locations, then data security is improved, but ease of operation deteriorates
Solution Approach 1:
The universal file system implements multi-functionality by providing a single interface that handles data access, security policies, and compliance requirements across all storage locations. This universal layer manages data security consistently whether data resides in cloud services or on-premise locations, improving ease of operation while maintaining security through centralized policy enforcement.
Solution Approach 2:
The storage virtualization layer acts as an intermediary that simplifies operations by abstracting the complexity of managing data across multiple locations. It provides unified security management, compliance enforcement, and data access controls, making the system easier to operate while maintaining security through decentralized storage architecture.
3Device complexity
If a single storage location is used, then system complexity is reduced, but vulnerability to cyber attacks increases
Solution Approach 1:
The system segments data storage across multiple independent locations including cloud services and on-premise infrastructure. This segmentation ensures that a cyber attack on one location does not compromise the entire data set, reducing vulnerability while maintaining manageable complexity through the universal file system abstraction layer.
Solution Approach 2:
The patent adds a new dimension to storage architecture by introducing a virtualization layer that sits between the access plane and the data plane. This dimensional addition allows data to be distributed across multiple storage locations without increasing operational complexity, as the virtualization layer manages the distribution and access uniformly.
4Loss of energy
If cloud storage is used, then operational expenses are reduced, but control over data management is reduced
Solution Approach 1:
The universal file system and virtualization layer serve as intermediaries that restore data management control when using cloud storage. These layers provide centralized policy enforcement, security management, and compliance controls while leveraging cloud storage's cost advantages, thus maintaining operational expense benefits while regaining data management versatility and control.
Solution Approach 2:
The system implements feedback mechanisms through centralized logging, monitoring, and policy enforcement at the universal file system layer. This feedback loop allows the organization to maintain control over data management by continuously monitoring and enforcing policies across cloud and on-premise storage, while still benefiting from the cost efficiency of cloud storage services.
Data Source
AI summary
The present disclosure relates to Universal File Virtualization (UFV) that functions like a single virtual data hub spanning on-premise storage at various data silos, data centers cloud data resources stored in IaaS, PaaS and SaaS, remote office and branch office and hybrid-clouds primarily catering secondary data storage combining cyber resilience technologies, information security, file storage and object storage technologies. Invention is built upon disaggregated control plane, security plane and decentralized data plane architecture. The system controller, security controller and Universal File System modules implement various file virtualization, security or data services algorithms to data that passes through it. All technologies are applied across various on-premise data vaults, cloud providers, storage sites and cloud services. The present disclosure also brings in new concept called UFV, implementing a secure, UFS spanning all disparate data sources of a corporation distributed across geographies and cloud services, with centralized control plane, security plane and a decentralized data plane built out of secure vaults controlled by a data controller.


