WORM Data Migration via Universal Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current WORM data migration techniques face challenges in verifying the integrity and permanence of data when migrating from one storage system to another, especially across different technologies, due to proprietary digital signatures that restrict verification to the original storage system.

Innovation Solution

A method involving a human-readable, digitally signed signature file is created for WORM data, which includes metadata and cryptographic hashes, allowing verification of data integrity and permanence across different storage systems and technologies, enabling 'out-of-band' verification without requiring secure data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary digital signature verification is used to ensure data integrity, then data security is improved, but verification is restricted to the original storage system only

Engineering Contradiction:
Improvedata integrity verificationVSAvoidcross-system verification capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates to storage systems. These certificates act as trusted mediators that enable verification across different storage systems. Instead of relying on proprietary signatures restricted to single systems, the CA-issued certificates serve as universal intermediaries that both source and destination systems can trust, thereby enabling cross-system verification while maintaining data integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal certificate verification mechanism that works across multiple storage systems and technologies. By using industry-standard digital certificates issued by trusted CAs rather than proprietary signatures, the verification process becomes universally applicable. The destination storage system can verify migrating WORM data from any source system that uses the same certificate authority, providing multi-functional verification capability across heterogeneous storage environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If WORM data is migrated using standard copying mechanisms, then migration simplicity is improved, but verification of data integrity and permanence becomes problematic

Engineering Contradiction:
Improvemigration process simplicityVSAvoiddata integrity verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by creating digital signatures of the WORM data at the source storage system before migration occurs. These signatures are generated in advance and stored securely. During migration, the destination system can immediately verify the data using these pre-created signatures, eliminating the need for complex post-migration verification processes. This preliminary signature creation simplifies the overall migration verification workflow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the destination storage system verifies the migrated WORM data against the original digital signatures and provides verification results. This feedback loop ensures that data integrity is confirmed after migration. The system can report verification status, errors, or warnings back to administrators, enabling them to assess whether the migration was successful and take corrective action if needed.

Inventive Principle:
Principle #23Feedback

3Reliability

If optical WORM storage is used to meet regulatory requirements, then data permanence is improved, but data throughput and access speed deteriorate

Engineering Contradiction:
Improvedata permanenceVSAvoiddata throughput
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent enables creation of verified copies of WORM data that can be stored on faster media. By using digital signatures to prove data integrity, the system allows migration of WORM data to magnetic disk or other high-speed storage while maintaining the legal and regulatory equivalence of the original optical WORM storage. The signature verification provides the trust necessary to use faster alternative media without compromising data permanence requirements.

Inventive Principle:
Principle #26Copying

4Speed

If magnetic storage devices are used for WORM implementation, then access speed and capacity are improved, but ease of verification across different storage systems deteriorates

Engineering Contradiction:
Improvedata access speedVSAvoidcross-technology verification
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent changes the verification parameter from proprietary signature formats specific to each storage technology to universal digital certificate formats. By adopting industry-standard cryptographic verification mechanisms that work across different storage technologies (optical, magnetic, tape, etc.), the system enables cross-technology verification. The verification process depends on cryptographic parameters rather than technology-specific parameters, allowing magnetic storage systems to verify data from optical systems and vice versa.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7774610B2Method and apparatus for verifiably migrating WORM data
Publication Date: 2010.08.10 NETAPP INC
  • US7774610B2 patent drawing
  • US7774610B2 patent drawing
  • US7774610B2 patent drawing

AI summary

A file system in a storage system allows a user to designate data as write-once read-many (WORM) data. The WORM data are stored in a first set of storage media of the storage system. Signature data are generated from the WORM data. Using the signature data, the integrity of the WORM data can be verified.