US2023334024A1PendingUtilityA1

Universal file virtualization with disaggregated control plane, security plane and decentralized data plane

Assignee: CHACKO PETERPriority: Dec 20, 2018Filed: Jun 23, 2023Published: Oct 19, 2023
Est. expiryDec 20, 2038(~12.4 yrs left)· nominal 20-yr term from priority
Inventors:Peter Chacko
G06F 16/188H03M 13/373G06F 9/4451G06F 21/6218G06F 16/1748G06F 16/1824G06F 16/164H04L 47/193H03M 13/3761H04L 63/10H04L 63/20
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present disclosure relates to Universal File Virtualization (UFV) that functions like a single virtual data hub spanning on-premise storage at various data silos, data centers cloud data resources stored in IaaS, PaaS and SaaS, remote office and branch office and hybrid-clouds primarily catering secondary data storage combining cyber resilience technologies, information security, file storage and object storage technologies. The proposed solution is built upon disaggregated control plane, security plane and decentralized data plane architecture. The system controller, security controller and Universal File System modules implement various file virtualization, security or data services algorithms to data that passes through it. The present disclosure also brings in a new concept called UFV, implementing a secure, UFS spanning all disparate data sources of a corporation distributed across geographies and cloud services, with centralized control plane, security plane and a decentralized data plane built out of secure vaults controlled by a data controller.

Claims

exact text as granted — not AI-modified
1 . A method for implementing storage intrusion detection and a real time response system for a Universal File System (UFS) comprising a decentralized data plane, a system controller and a security controller, the method comprising:
 transferring data sets from a primary storage associated with a plurality of storage systems to a set of secure vaults;   separating user data, metadata and security data from the data sets, wherein separating further comprises:
 transmitting the user data to a decentralized data plane through a predefined data path; 
 transmitting the metadata to a system controller through a predefined control path; and 
 transmitting the security data to a security controller through a predefined security plane; 
   separating and sending storage intrusion data, including ransomware attack signatures, in the data sets to the security controller through the predefined security plane,   wherein the method further comprises performing, at the security controller, at least one of:
 retrieving security configuration and security policy data corresponding to the data sets from the system controller; 
 checking storage intrusion activities such as ransomware attack signature; 
 verifying the data qualification parameters with security configuration data; 
 effectuating a real time response to intrusion incidence, against an storage activity anomaly detected during the verification, in accordance with the security response parameters; and 
 allowing a matched data to be stored in matched storage partitions of the UFS if no storage activity anomaly is detected, 
   wherein the method further comprises performing, at the decentralized data plane, at least one of:
 storing the user data as immutable objects; 
 running as an independent object storage system as part of third-party cloud storage services or as an onPremise object storage system; 
 responding to a command request and a data request received from the security controller; 
 responding to the command request and the data request received from system controller; 
 responding to the command request and the data request received from one or more configured UFS module; 
 sharing the user data without a statically configured IP address and ports with no network reachability to inbound network service and using reverse TCP data flows for data exchange; and 
 exchanging data with a data proxy, through send operation and receive operation over a reverse TCP flow, 
   wherein the secure vaults store a redundantly coded, sharded fragments of the user data revealing no data for ransomware attack tolerance, need no open ports for in-bound connection requests or static IP address, and   wherein the security controller centrally monitors one or more data input and output activities performed on the storage controller.   
     
     
         2 . The method of  claim 1 , wherein the security response includes at least one of disabling the UFS module from a further data service. 
     
     
         3 . The method of  claim 1  further comprises implementing a gold copy file system against ransomware attack, for a Universal File System (UFS) comprising a security controller functioning as a security plane and a centralized system controller having UFS modules configured to execute a method comprising the steps of:
 receiving data sets from a plurality of data sources at a plurality of data silos; 
 extracting metadata, user data and security profile data at UFS modules; 
 transferring metadata to a metadata controller; 
 transferring security profile and security configuration data to a security controller, wherein a decentralized data plane associated with the UFS is configured to execute a method comprising the steps of:
 storing user data as immutable objects; 
 responding to command and data requests from the security controller; 
 responding to command and data requests from the system controller; 
 responding to command and data requests from the UFS modules; 
 initiating TCP connections with a data proxy; 
 using reverse TCP data flows for data exchange; 
 transferring data from the data proxy over the TCP connections, creating a backup epoch; and 
 updating the gold copy with new epoch, after matching ransomware attack signature verification to create the new epoch, in accordance with the data qualification parameters, 
 
 wherein the secure vaults provide no open ports for in-bound connection requests or static IP address and use the reverse TCP data flows to exchange data with the data proxy. 
 
     
     
         4 . The method of  claim 3 , further comprises implementing a ransomware resilient file system supporting multiple data sites, and integrated as universal file system, the method comprising steps of:
 receiving a security profile and a security configuration data from different sites;   classifying the data according to criticality and sensitivity of the data with predefined data classification parameters;   processing different data according to a security profile stored at the security controller;   initiating the configured data services at the system controller;   disallowing an update of latest gold copy data with the new epoch, if the ransomware attack signature verification succeeds;   disabling the UFS module on matching security policy upon detecting an input/output anomaly as real-time response, in accordance with the security profile data associated with the data set; and   sending a shutdown message to the UFS module and the security vault from the security controller.   
     
     
         5 . The method of  claim 4 , wherein the UFS modules are located in different sites distributed across a Wide Area Network (WAN). 
     
     
         6 . The method of  claim 4 , wherein intrusion responses can be different based upon security response parameters and data classification configuration, which is centrally enforced from the system controller and the security controller. 
     
     
         7 . A system for implementing a multi-silo data backup with a built-in ransomware resilience, the system comprising a system controller, a security controller, a secure vault and UFS modules, the UFS modules configured to execute a method comprising the steps of:
 receiving data sets from a plurality of data sources at a plurality of data silos;   extracting metadata, user data and security profile data from the received data;   transferring metadata to the system controller; and   transferring a security profile and a security configuration data to the security controller, wherein the secure vault is configured to execute a method comprising the steps of:
 storing user data as immutable objects; 
 responding to command and data requests from the security controller; 
 responding to command and data requests from the system controller; 
 responding to command and data requests from the configured UFS modules; 
 initiating TCP connections with a data proxy; 
 using reverse TCP data flows for the data exchange; 
 transferring the data from the data proxy over the TCP flow, creating a backup epoch, updating known gold copy with new epoch after matching ransomware attack signature verification to create the new epoch, in accordance with the data qualification parameters, 
   wherein the secure vault uses reverse TCP flow to exchange data with the data proxy and the plurality of said UFS modules retrieve the metadata from a local storage, and the second set of user data from the plurality of secure vaults, associated with data controller, and the security profile from the security controller, in response to receiving a data request from a user at second set of the plurality of UFS modules running in second set of data silos.   
     
     
         8 . An architecture for implementing real time intrusion response to storage systems across multiple-sites, comprising:
 a system controller; and   UFS modules consisting of a data proxy, a security controller and a decentralized data containers attached to a data controller,   wherein the decentralized data containers are capable of executing data services and exchange data with third-party cloud storage services, and configured to execute a method comprising the steps of:
 receiving a data synchronously with external data clients without any in-bound connection establishment; 
 exchanging data without any open ports for in-bound TCP/IP connection requests; 
 initiating connections, and keep sending alive messages to the data proxy; 
 exchanging messages with the data proxy to initiate data exchange; 
 executing data receive operation using a reverse TCP flow; 
 executing data send operation, using the reverse TCP flow; and 
 storing data in an immutable, versioned binary objects at data containers, 
   wherein the data containers are connected to security controller configured to execute a method comprising the steps of:
 receiving security profile data from the system controller module; 
 monitoring the data activity operations on the plurality of configured data containers associated with data controller; 
 monitoring the data activity operations on the plurality of configured UFS modules; 
 perform real-time ransomware attack monitoring; 
 extracting system activity events from the plurality of UFS modules and the plurality of data containers; 
 processing security events data coming in through security plane for detecting any anomaly, for triggering security response parameters; and 
 initiating the attack response actions in accordance with security response parameters on the plurality of data containers associated with data controller, upon detecting any storage activity anomaly. 
   
     
     
         9 . The architecture of  claim 8 , wherein the system controller and the security controller are connected to a plurality of data containers in a decentralized manner, while the user data, metadata and the security data get transmitted over data path, control path and security plane respectively, with security and metadata distributed to the UFS modules across sites. 
     
     
         10 . The architecture of  claim 8 , wherein the UFS modules retrieve the metadata from a local storage and a second set of user data from the plurality of secure vaults associated with data controller and the security profile from the security controller in response to receiving a data request from a user at second set of the plurality of UFS modules running in second set of data silos.

Join the waitlist — get patent alerts

Track US2023334024A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.