Universal File Virtualization With Split Control and Decentralized Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage systems face challenges in managing and securing data across multiple cloud and on-premise locations due to lack of unified access, security, and resilience, particularly in the face of cyber threats like ransomware, with existing file systems failing to provide integrated security, content analytics, and centralized control.
Innovation Solution
The implementation of a Universal File System (UFS) with a split control plane, security plane, and decentralized data plane architecture, enabling secure, intelligent file virtualization across disparate storage silos, using metadata controllers to decouple data access from storage locations and provide unified visibility and control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is stored in multiple cloud and on-premise locations, then data availability and accessibility are improved, but security control and unified management become more difficult
Solution Approach 1:
The system segments storage into multiple independent locations (cloud and on-premise) while maintaining centralized control through a metadata service. Each storage location operates independently but is coordinated through the unified namespace, allowing data to be accessible across multiple locations without proportionally increasing security control complexity.
Solution Approach 2:
The patent introduces a metadata service as an intermediary between clients and physical storage locations. This mediator handles security control, access permissions, and data location management centrally, while clients interact with a simplified unified namespace, thus improving data accessibility without proportionally increasing security control complexity.
2Device complexity
If centralized storage is used, then security control is simplified, but vulnerability to ransomware attacks increases
Solution Approach 1:
The system segments physical storage into multiple independent locations across different cloud providers and on-premise systems. This segmentation ensures that a ransomware attack on one location does not compromise all data, maintaining cyber resilience while keeping security control simplified through centralized metadata management.
Solution Approach 2:
The patent converts the potential harm of distributed storage (increased complexity) into a benefit by using the metadata service to abstract away the complexity. The distributed architecture provides cyber resilience against ransomware, while the centralized metadata service maintains simplified security control, effectively converting the architectural complexity into a security advantage.
3Ease of operation
If data is virtualized across disparate storage silos, then unified access is improved, but system complexity increases
Solution Approach 1:
The metadata service acts as an intermediary that abstracts the complexity of disparate storage silos. Clients interact with a unified namespace through simple operations, while the metadata service handles the complex tasks of data location resolution, access coordination, and namespace management across multiple storage systems.
Solution Approach 2:
The metadata service provides universal functionality across different storage systems, implementing a unified namespace that works consistently across cloud and on-premise locations. This multi-functional approach allows diverse storage silos to be accessed through a single interface, improving ease of operation without requiring each system to be customized.
4Ease of manufacture
If cloud storage is used, then upfront investment is reduced, but data control and security visibility are worsened
Solution Approach 1:
The metadata service serves as an intermediary that restores data control visibility when using cloud storage. It maintains a centralized view of all data locations including cloud storage, enabling the organization to track and control data across cloud and on-premise systems without requiring direct access to each cloud provider's internal systems.
Solution Approach 2:
The system segments data control functions into two parts: physical storage management (handled by cloud providers) and logical data control (handled by the metadata service). This segmentation allows the organization to use cost-effective cloud storage while maintaining centralized data control and visibility through the metadata service's unified namespace.
Data Source
AI summary
The present disclosure relates to Universal File Virtualization (UFV) that functions like a single virtual data hub spanning on-premise storage at various data silos, data centers cloud data resources stored in IaaS, PaaS and SaaS, remote office and branch office and hybrid-clouds primarily catering secondary data storage combining cyber resilience technologies, information security, file storage and object storage technologies. The proposed solution is built upon disaggregated control plane, security plane and decentralized data plane architecture. The system controller, security controller and Universal File System modules implement various file virtualization, security or data services algorithms to data that passes through it. The present disclosure also brings in a new concept called UFV, implementing a secure, UFS spanning all disparate data sources of a corporation distributed across geographies and cloud services, with centralized control plane, security plane and a decentralized data plane built out of secure vaults controlled by a data controller.


