WORM Retention Management via Trusted Time Source
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
WORM storage systems face challenges in ensuring data integrity during the retention period, as the stored retention date can be tampered with, allowing illicit changes to WORM files, due to potential manipulation of the retention date or time source, compromising the trustworthiness of the metadata and current time.
Innovation Solution
Implementing a retention management system that utilizes a trusted time source and WORM protection features to securely set, manage, and expire retention dates, ensuring that WORM files are protected from changes during their designated retention period by using a retention manager to handle retention period settings, extensions, and expiry checks, and providing options for file disposition after expiry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the retention date is stored in metadata without additional protection, then the system simplicity is maintained, but the data integrity is compromised due to potential tampering
Solution Approach 1:
The patent applies preliminary action by calculating and storing the retention expiry date at the time of file creation, rather than relying on continuous time source verification. This pre-calculated date is stored in file metadata and serves as the authoritative reference for determining when retention expires, eliminating the need to trust the current time source during retention enforcement.
Solution Approach 2:
The patent introduces an intermediary mechanism by using the stored retention expiry date as a mediator between the file system and the time source. Instead of directly comparing current time with retention period, the system uses the pre-stored expiry date as an intermediate reference point, which cannot be manipulated without detection, thus ensuring data integrity while maintaining system simplicity.
2Productivity
If the current time source is trusted without verification, then the operational efficiency is maintained, but the security against time manipulation is weakened
Solution Approach 1:
The system performs the time verification action in advance by storing the calculated retention expiry date when the file is created. This preliminary calculation eliminates the need for continuous verification of the current time source, maintaining operational efficiency while ensuring security against time manipulation.
Solution Approach 2:
The patent applies preliminary anti-action by pre-calculating the retention expiry date and storing it as an immutable reference. This pre-established reference prevents any subsequent manipulation of the time source from affecting the retention enforcement, as the system will always compare against the stored expiry date rather than the current time source.
3Reliability
If WORM designation protection includes protection of the retention date metadata, then the data integrity is improved, but the ease of legitimate modification is reduced
Solution Approach 1:
The patent applies local quality by differentiating the protection level of different metadata fields. The retention expiry date is stored with WORM protection to prevent tampering, while other non-critical metadata fields remain modifiable. This selective protection ensures data integrity for critical retention information while maintaining ease of operation for legitimate modifications to other file attributes.
Data Source
AI summary
A write-once-read-many, WORM, storage system is arranged to store datasets each with associated attributes including a WORM attribute indicating the dataset's WORM status, and to protect from change or deletion WORM datasets, and at least certain of their attributes including those relevant to WORM status. Retention management capabilities are provided for such a storage system, including the ability to set a given dataset for retention for a particular retention period by storing a corresponding retention date in an attribute of the dataset, and setting the WORM attribute to indicate that the dataset is a WORM dataset. Also provided is the ability to determine expiry of the retention period for the given dataset, and then to remove the stored retention date and change the WORM attribute of the dataset to indicate that it is no longer a WORM dataset.


