IP Library Granted Patent US 12,353,552
Granted Patent B2
US 12,353,552 · App. 17/968,847 · Granted Jul 8, 2025

Zero-trust remote replication

Inventors: Yaron Dar (Sudbury, MA); Arieh Don (Newton, MA); Krishna Deepak Nuthakki (Bangalore, IN)
Assignee: DELL PRODUCTS L.P.
G06F21/568G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,353,552
App. No.
17/968,847
Granted
Jul 8, 2025
Kind
B2
Abstract

A disaster recovery site storage array causes an instance of a host application or selected executables running on a host server to validate changes to an asynchronously updated replica of a storage object. Snapshots of the replica are generated before and after each set of changes to the replica are received from a remote storage array. Validation is performed by mounting snapshots to the instance of the associated host application and causing the host application instance to validate the data. If a snapshot is determined to be invalid, then the replica to recovered with the most recent known-valid snapshot. Alternatively, if each set of changes is validated prior to being applied to the replica, invalid changes are not applied to the replica. Unvalidated snapshots may be accumulated and validated independently from application of sets of changes to the replica, thereby decoupling validation from replication.

Claims (27)

1. A method comprising:

receiving, from a first or second storage system, a set of changes to an asynchronously replicated storage object, the changes comprising data updates;

generating an unvalidated snapshot that contains the set of changes; and

prompting performance of validation on the unvalidated snapshot to detect one or more of data corruption and malicious data encryption.

2. The method of claim 1 further comprising applying the set of changes to the asynchronously replicated storage object prior to generating the unvalidated snapshot.

3. The method of claim 2 further comprising generating the unvalidated snapshot from the asynchronously replicated storage object.

4. The method of claim 3 further comprising performing validation on the unvalidated snapshot using an instance of a host application associated with the asynchronously replicated storage object.

5. The method of claim 3 further comprising performing validation on the unvalidated snapshot using executables of a host application associated with the asynchronously replicated storage object.

6. The method of claim 3 further comprising accumulating a plurality of unvalidated snapshots and performing validation on an oldest one of the plurality of unvalidated snapshots.

7. The method of claim 6 further comprising recovering the asynchronously replicated storage object with a most recent known-valid snapshot responsive to detection of an invalid snapshot.

8. An apparatus comprising:

a plurality of compute nodes than manage access to an array of non-volatile drives on which data of an asynchronously replicated storage object is stored, at least one of the compute nodes configured to receive a set of changes to the asynchronously replicated storage object from a remote storage system, the changes comprising data updates, generate an unvalidated snapshot that contains the set of changes, and prompting performance of validation on the unvalidated snapshot to detect one or more of data corruption and malicious data encryption.

9. The apparatus of claim 8 further comprising the at least one compute node configured to apply the set of changes to the asynchronously replicated storage object prior to generating the unvalidated snapshot.

10. The apparatus of claim 9 further comprising the at least one compute node configured to generate the unvalidated snapshot from the asynchronously replicated storage object.

11. The apparatus of claim 10 further comprising the at least one compute node configured to perform validation on the unvalidated snapshot using an instance of a host application associated with the asynchronously replicated storage object.

12. The apparatus of claim 10 further comprising the at least one compute node configured to perform validation on the unvalidated snapshot using executables of a host application associated with the asynchronously replicated storage object.

13. The apparatus of claim 10 further comprising the at least one compute node configured to accumulate a plurality of unvalidated snapshots and perform validation on an oldest one of the plurality of unvalidated snapshots.

14. The apparatus of claim 13 further comprising the at least one compute node configured to recover the asynchronously replicated storage object with a most recent known-valid snapshot responsive to detection of an invalid snapshot.

15. A non-transitory computer-readable storage medium storing instructions that when executed by a storage array compute node perform a method comprising:

receiving, from a first or second storage system, a set of changes to an asynchronously replicated storage object, the changes comprising data updates;

generating an unvalidated snapshot that contains the set of changes; and

prompting performance of validation on the unvalidated snapshot to detect one or more of data corruption and malicious data encryption.

16. The non-transitory computer-readable storage medium of claim 15 in which the method further comprises applying the set of changes to the asynchronously replicated storage object prior to generating the unvalidated snapshot.

17. The non-transitory computer-readable storage medium of claim 16 in which the method further comprises generating the unvalidated snapshot from the asynchronously replicated storage object.

18. The non-transitory computer-readable storage medium of claim 17 in which the method further comprises performing validation on the unvalidated snapshot using an instance of a host application associated with the asynchronously replicated storage object.

19. The non-transitory computer-readable storage medium of claim 17 in which the method further comprises performing validation on the unvalidated snapshot using executables of a host application associated with the asynchronously replicated storage object.

20. The non-transitory computer-readable storage medium of claim 17 in which the method further comprises accumulating a plurality of unvalidated snapshots and performing validation on an oldest one of the plurality of unvalidated snapshots.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2022
From: DAR, YARON; DON, ARIEH; NUTHAKKI, KRISHNA DEEPAK
To: DELL PRODUCTS L.P.
Reel/Frame 061464/0136 →
Continuity (2)
Related Publication 20240134985A1 · Apr 25, 2024
Related Publication 20240232358A9 · Jul 11, 2024
References Cited (8)
US 9652326B1 · Bauer · 2017 [cited by examiner]
US 10459632B1 · Chen · 2019 [cited by examiner]
US 11061609B2 · Beauchamp · 2021 [cited by examiner]
US 11531474B1 · Matsushita · 2022 [cited by examiner]
US 11593186B2 · Niles · 2023 [cited by examiner]
US 11716382B2 · Longinov · 2023 [cited by examiner]
US 11995041B2 · Kaushik · 2024 [cited by examiner]
US 12050553B2 · Curtis-Maury · 2024 [cited by examiner]