Virtualized Encryptor Scaling for Datacenter Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securely transferring data between datacenters, such as hardware encryptors and full-mesh configurations, face limitations in scalability and cost due to processing constraints and high computational requirements, making them inefficient for varying data transfer demands.

Innovation Solution

Implementing a system with virtualized encryptors and route balancers that dynamically adjust the number of encryptors based on demand, using peer-to-peer connections and cryptographic keys for secure communication, and utilizing parallel packet-processing techniques to enhance data transfer efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware encryptors are used to secure data transfer between datacenters, then data security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvedata securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces hardware encryptors (mechanical/physical system) with software-based virtual machine encryptors. This substitution maintains data security functionality while eliminating the need for dedicated hardware devices, thereby reducing device complexity and cost.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates virtual copies of encryptor functionality through virtual machines rather than using physical hardware copies. This allows multiple instances of encryption capability to be deployed software-based, reducing the complexity associated with hardware management and deployment.

Inventive Principle:
Principle #26Copying

2Reliability

If full-mesh configurations are used to establish secure connections between all hosts, then data security is improved, but device complexity and computational requirements increase

Engineering Contradiction:
Improvedata securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the full-mesh connection requirement by introducing virtual machine encryptors as intermediate nodes. Instead of requiring direct secure connections between all host pairs, the system segments connections into host-to-encryptor and encryptor-to-encryptor links, significantly reducing the number of required connections and overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual machine encryptors as intermediary components between source and destination hosts. These intermediaries handle the cryptographic operations and secure communication establishment, eliminating the need for complex full-mesh configurations while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If fixed numbers of encryptors are deployed at each datacenter, then device complexity is reduced, but adaptability to varying data transfer demands deteriorates

Engineering Contradiction:
Improvedevice complexityVSAvoidadaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic scaling of virtual machine encryptors based on data transfer demand. The system can automatically provision additional encryptor instances during peak periods and de-provision them during low-demand periods, providing adaptability while maintaining manageable complexity through automated orchestration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates universal encryptor instances that can serve multiple purposes and adapt to different data transfer scenarios. These virtual machine encryptors can be dynamically allocated to different host pairs and data transfer requirements, providing versatility without requiring specialized hardware for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If more encryptors are deployed to handle peak data transfer demands, then productivity is improved, but device complexity and cost increase

Engineering Contradiction:
Improvedata transfer capacityVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements periodic monitoring and dynamic adjustment of encryptor instances based on data transfer demand patterns. The system scales encryptor capacity periodically or on-demand rather than maintaining fixed over-provisioned resources, improving productivity during peaks while avoiding the complexity and cost of permanent high-capacity deployments.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10911416B2Secured transfer of data between datacenters
Publication Date: 2021.02.02 SALESFORCE INC
  • US10911416B2 patent drawing
  • US10911416B2 patent drawing
  • US10911416B2 patent drawing

AI summary

In various embodiments, a method of transferring data between datacenters may be performed. The method may include running a first plurality of host programs and a first plurality of encryption units at a first datacenter. The method may further include establishing, between the first datacenter and a second datacenter, secure communication connections between each of the first plurality of encryption units and a corresponding one of a second plurality of encryption units running at the second datacenter. The method may further include transferring, by the first datacenter, data from the first plurality of host programs to a second plurality of host programs running at the second datacenter.