Virtual Storage Domain Hashing for Content Addressable Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Content addressable storage systems face challenges in data usage reporting, security, and fault containment, particularly in cloud environments where diverse user needs require dedicated storage, performance optimization, and encryption mechanisms, necessitating enhanced multi-tenancy compliance.
Innovation Solution
The implementation of virtual storage domains with unique identifiers in content addressable systems allows users to define storage efficiency, performance, and security policies, mapping these policies to virtual storage domains and incorporating them into hash functions for data processing, ensuring data isolation and efficient storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of substance
If content addressable storage systems store data with unique hash signatures to achieve storage efficiency, then redundant data is eliminated and storage space is optimized, but data isolation and security for multiple users cannot be ensured
Solution Approach 1:
The patent segments the storage system into multiple virtual storage domains, each with its own namespace and hash signature calculation. This segmentation allows data from different users to be isolated in separate domains while maintaining storage efficiency within each domain. The system divides the unified storage space into domain-specific segments that can independently manage their own deduplication and security policies.
Solution Approach 2:
The patent introduces virtual storage domains as an intermediary layer between the physical storage system and multiple users. Each domain acts as a mediator that calculates unique hash signatures for its data, enabling both deduplication within the domain and isolation from other domains. This intermediary structure resolves the conflict between shared storage efficiency and user-specific data isolation.
2Productivity
If a unified storage infrastructure is used to support multiple users, then resource utilization is improved, but user-specific security policies and data protection cannot be implemented
Solution Approach 1:
The patent implements dynamic virtual storage domains that can be created, modified, and configured based on user-specific requirements. Each domain can have its own security policies, access controls, and hash calculation methods dynamically adjusted without affecting other domains. This dynamic configuration enables the system to adapt to diverse user needs while maintaining unified resource management.
Solution Approach 2:
The patent applies local quality by allowing each virtual storage domain to have customized security policies, access controls, and data protection mechanisms tailored to specific user requirements. Different domains can implement different encryption methods, permission structures, and retention policies while sharing the same physical infrastructure, thus providing both resource efficiency and policy flexibility.
3Loss of substance
If data is shared across multiple users in a cloud environment, then storage efficiency is improved, but fault containment and security isolation between users deteriorate
Solution Approach 1:
The patent segments the storage system into isolated virtual domains, each with its own hash signature calculation and data management. This segmentation contains potential security failures or faults within individual domains, preventing them from affecting other users. Simultaneously, each domain maintains storage efficiency through its own deduplication mechanisms.
Solution Approach 2:
The virtual storage domain acts as an intermediary that mediates between the shared physical storage infrastructure and individual users. It calculates domain-specific hash signatures that provide both deduplication within the domain and security isolation from other domains, thus resolving the conflict between storage efficiency and security containment.
Data Source
AI summary
A method, system and program is described for providing virtual storage domains for content addressable system. At least one tenant data storage policy is configured for at least one tenant in a storage system. A virtual storage domain is created based on the tenant data storage policy, each virtual storage domain having a unique identifier (ID). The corresponding virtual storage domain ID is tagged to a data request based on a data set policy when data belonging to a data set gets written to the storage system. A hash signature is calculated for the data taking the data content and the storage domain ID as inputs to calculate the hash signature.


