Storage Volume Migration Encryption Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud environments, volume mobility functions that migrate volumes between storage systems can lead to data leakage or loss due to mismatched encryption levels between source and destination, compromising security and flexibility during volume migration.
Innovation Solution
A computer system with a management device that compares encryption settings of volumes to be migrated with their destination, notifying security administrators to ensure matching encryption levels, thus preventing data leakage and enabling secure, flexible encryption changes without impairing volume mobility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If volume migration is enabled between storage systems with different encryption settings, then volume mobility and flexibility are improved, but data security and confidentiality are compromised due to encryption level mismatches
Solution Approach 1:
The management device performs preliminary comparison of encryption settings between source and destination volumes before migration execution. This advance check prevents security compromises by identifying encryption level mismatches before data movement occurs, allowing preventive actions to be taken.
Solution Approach 2:
The system implements a feedback mechanism where the management device notifies administrators of encryption setting differences and prevents migration until the issue is resolved. This feedback loop ensures security requirements are met while maintaining volume mobility functionality.
2Reliability
If encryption function is enforced at migration destination, then data security is improved, but migration flexibility and ease of operation deteriorate due to restricted encryption changes
Solution Approach 1:
The system applies encryption requirements locally at the destination volume level rather than globally. The management device checks encryption settings specifically at the destination and only enforces requirements where needed, allowing flexibility in other areas of the system.
Solution Approach 2:
The encryption requirement enforcement is dynamic rather than static. The system allows encryption settings to be adjusted and synchronized between source and destination, providing adaptability while maintaining security. The notification mechanism allows administrators to resolve issues and proceed with migration when conditions are met.
Data Source
AI summary
A computer system regarding which there is no possibility that data loss or data leakage will occur caused by volume migration is provided.The computer system includes: a memory resource to be accessed by a host computer; a storage system for providing a volume, which logicizes the memory resource, to the host computer; and a management device for managing migration of the volume. When detecting a task of migration of the volume based on a request from a first administrator, the management device compares an encryption function setting status of the volume with the encryption function setting status of a migration destination object of the volume; and sends notice of this comparison result to a second administrator, who is different from the first administrator, for security management of the storage system.


