WORM Data Migration via Universal Digital Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current WORM data migration techniques face challenges in verifying the integrity and permanence of data when migrating from one storage system to another, especially across different technologies, due to proprietary digital signatures that restrict verification to the original storage system.
Innovation Solution
A method involving a human-readable, digitally signed signature file is created for WORM data, which includes metadata and cryptographic hashes, allowing verification of data integrity and permanence across different storage systems and technologies, enabling 'out-of-band' verification without requiring secure data transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proprietary digital signature verification is used to ensure data integrity, then data security is improved, but verification is restricted to the original storage system only
Solution Approach 1:
The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates to storage systems. These certificates act as trusted mediators that enable verification across different storage systems. Instead of relying on proprietary signatures restricted to single systems, the CA-issued certificates serve as universal intermediaries that both source and destination systems can trust, thereby enabling cross-system verification while maintaining data integrity.
Solution Approach 2:
The patent implements a universal certificate verification mechanism that works across multiple storage systems and technologies. By using industry-standard digital certificates issued by trusted CAs rather than proprietary signatures, the verification process becomes universally applicable. The destination storage system can verify migrating WORM data from any source system that uses the same certificate authority, providing multi-functional verification capability across heterogeneous storage environments.
2Ease of operation
If WORM data is migrated using standard copying mechanisms, then migration simplicity is improved, but verification of data integrity and permanence becomes problematic
Solution Approach 1:
The patent applies preliminary action by creating digital signatures of the WORM data at the source storage system before migration occurs. These signatures are generated in advance and stored securely. During migration, the destination system can immediately verify the data using these pre-created signatures, eliminating the need for complex post-migration verification processes. This preliminary signature creation simplifies the overall migration verification workflow.
Solution Approach 2:
The patent implements feedback mechanisms where the destination storage system verifies the migrated WORM data against the original digital signatures and provides verification results. This feedback loop ensures that data integrity is confirmed after migration. The system can report verification status, errors, or warnings back to administrators, enabling them to assess whether the migration was successful and take corrective action if needed.
3Reliability
If optical WORM storage is used to meet regulatory requirements, then data permanence is improved, but data throughput and access speed deteriorate
Solution Approach 1:
The patent enables creation of verified copies of WORM data that can be stored on faster media. By using digital signatures to prove data integrity, the system allows migration of WORM data to magnetic disk or other high-speed storage while maintaining the legal and regulatory equivalence of the original optical WORM storage. The signature verification provides the trust necessary to use faster alternative media without compromising data permanence requirements.
4Speed
If magnetic storage devices are used for WORM implementation, then access speed and capacity are improved, but ease of verification across different storage systems deteriorates
Solution Approach 1:
The patent changes the verification parameter from proprietary signature formats specific to each storage technology to universal digital certificate formats. By adopting industry-standard cryptographic verification mechanisms that work across different storage technologies (optical, magnetic, tape, etc.), the system enables cross-technology verification. The verification process depends on cryptographic parameters rather than technology-specific parameters, allowing magnetic storage systems to verify data from optical systems and vice versa.
Data Source
AI summary
A file system in a storage system allows a user to designate data as write-once read-many (WORM) data. The WORM data are stored in a first set of storage media of the storage system. Signature data are generated from the WORM data. Using the signature data, the integrity of the WORM data can be verified.


