Universal File Virtualization With Split Control and Decentralized Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage systems face challenges in managing and securing data across multiple cloud and on-premise locations due to lack of unified access, security, and resilience, particularly in the face of cyber threats like ransomware, with existing file systems failing to provide integrated security, content analytics, and centralized control.

Innovation Solution

The implementation of a Universal File System (UFS) with a split control plane, security plane, and decentralized data plane architecture, enabling secure, intelligent file virtualization across disparate storage silos, using metadata controllers to decouple data access from storage locations and provide unified visibility and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored in multiple cloud and on-premise locations, then data availability and accessibility are improved, but security control and unified management become more difficult

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments storage into multiple independent locations (cloud and on-premise) while maintaining centralized control through a metadata service. Each storage location operates independently but is coordinated through the unified namespace, allowing data to be accessible across multiple locations without proportionally increasing security control complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a metadata service as an intermediary between clients and physical storage locations. This mediator handles security control, access permissions, and data location management centrally, while clients interact with a simplified unified namespace, thus improving data accessibility without proportionally increasing security control complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If centralized storage is used, then security control is simplified, but vulnerability to ransomware attacks increases

Engineering Contradiction:
Improvesecurity control complexityVSAvoidcyber resilience
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system segments physical storage into multiple independent locations across different cloud providers and on-premise systems. This segmentation ensures that a ransomware attack on one location does not compromise all data, maintaining cyber resilience while keeping security control simplified through centralized metadata management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent converts the potential harm of distributed storage (increased complexity) into a benefit by using the metadata service to abstract away the complexity. The distributed architecture provides cyber resilience against ransomware, while the centralized metadata service maintains simplified security control, effectively converting the architectural complexity into a security advantage.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Ease of operation

If data is virtualized across disparate storage silos, then unified access is improved, but system complexity increases

Engineering Contradiction:
Improveunified accessVSAvoidvirtualization architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The metadata service acts as an intermediary that abstracts the complexity of disparate storage silos. Clients interact with a unified namespace through simple operations, while the metadata service handles the complex tasks of data location resolution, access coordination, and namespace management across multiple storage systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The metadata service provides universal functionality across different storage systems, implementing a unified namespace that works consistently across cloud and on-premise locations. This multi-functional approach allows diverse storage silos to be accessed through a single interface, improving ease of operation without requiring each system to be customized.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of manufacture

If cloud storage is used, then upfront investment is reduced, but data control and security visibility are worsened

Engineering Contradiction:
Improveupfront investmentVSAvoiddata control visibility
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The metadata service serves as an intermediary that restores data control visibility when using cloud storage. It maintains a centralized view of all data locations including cloud storage, enabling the organization to track and control data across cloud and on-premise systems without requiring direct access to each cloud provider's internal systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments data control functions into two parts: physical storage management (handled by cloud providers) and logical data control (handled by the metadata service). This segmentation allows the organization to use cost-effective cloud storage while maintaining centralized data control and visibility through the metadata service's unified namespace.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250004996A1Universal file virtualization with disaggregated control plane, security plane and decentralized data plane
Publication Date: 2025.01.02 CHACKO PETER
  • US20250004996A1 patent drawing
  • US20250004996A1 patent drawing
  • US20250004996A1 patent drawing

AI summary

The present disclosure relates to Universal File Virtualization (UFV) that functions like a single virtual data hub spanning on-premise storage at various data silos, data centers cloud data resources stored in IaaS, PaaS and SaaS, remote office and branch office and hybrid-clouds primarily catering secondary data storage combining cyber resilience technologies, information security, file storage and object storage technologies. The proposed solution is built upon disaggregated control plane, security plane and decentralized data plane architecture. The system controller, security controller and Universal File System modules implement various file virtualization, security or data services algorithms to data that passes through it. The present disclosure also brings in a new concept called UFV, implementing a secure, UFS spanning all disparate data sources of a corporation distributed across geographies and cloud services, with centralized control plane, security plane and a decentralized data plane built out of secure vaults controlled by a data controller.