IP Library Granted Patent US 7,383,407
Granted Patent B1
US 7,383,407 · App. 11/590,542 · Granted Jun 3, 2008

Synchronous replication for system and data security

Assignee: Symantec Operating Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,383,407
App. No.
11/590,542
Filed
Oct 31, 2006
Granted
Jun 3, 2008
Kind
B1
Art Unit
2189
USPC
711/162
Abstract

A method, system, and computer-readable medium for maintaining up-to-date, consistent backup copies of primary data that are immune to corruption even when security of the primary data is breached. Independent security domains are established for primary and secondary data, such that access to each security domain must be obtained independently of access to the other security domains. For example, a host computer system having access to data storage in the primary security domain does not have access to data storage in the secondary security domain, and vice versa. Changes to primary data are synchronously replicated over a tightly controlled replication link from primary data storage in the primary security domain to secondary data storage in the secondary security domain. A change to the data is completed in the primary security domain when an acknowledgement is received that the change to the data has been stored in secondary data storage.

Claims (62)

1. A method comprising:

initiating a modification to data stored in a first data storage unit;

replicating the modification to the data stored in the first data storage unit to data stored in a second storage unit, wherein

the first data storage unit is in a first security domain,

the second storage unit is in a second security domain, and

the first security domain and the second security domain are independent of one another; and

completing the modification to the data in the first storage unit in response to receiving an indication that the modification has been made to the data in second data storage unit in the second security domain.

2. The method of claim 1 wherein the initiating comprises:

initiating the modification to the data stored in the second data storage unit in an order relative to each modification of a set of modifications to the data stored in the first data storage unit.

3. The method of claim 1 wherein

a first host controls access to the first security domain; and

a second host controls access to the second security domain.

4. The method of claim 3 further comprising:

the first host accessing data stored in the second security domain by requesting an operation to be performed on the second data storage unit; and

making the corresponding modification to the copy of second host.

5. The method of claim 4 wherein

the causing the operation to be performed on the second data storage unit comprises

sending a command to perform the operation from a first storage manager associated with the first data storage unit to a second storage manager associated with the second data storage unit.

6. The method of claim 4 wherein

the operation comprises a restoration operation of a portion of the data from third data storage unit; and

the causing the operation to be performed on the second data storage unit comprises

causing a corresponding portion of the data stored in the second data storage unit to be restored from fourth data storage unit corresponding to the third data storage unit, wherein

the corresponding portion of the data stored in the second data storage unit is a copy of the portion of the data stored in the first data storage unit after the operation on the second data storage unit.

7. The method of claim 3 wherein

the data stored in the second data storage unit in an order relative to each corresponding modification of a corresponding set of modifications to the data stored in the second data storage unit, wherein

the data stored in the first data storage unit after making the set of modifications is the same as the copy of the data stored in the second data storage unit after making the corresponding set of modifications.

8. The method of claim 3 wherein

the first data storage unit is inaccessible directly by the second host.

9. The method of claim 1 further comprising:

determining that the operation was performed on the first data storage unit between a first modification of a plurality of modifications to the data stored in the first data storage unit and a second modification of a plurality of modifications to the data stored in the first data storage unit, wherein

the causing the operation to be performed on the second data storage unit comprises

causing the operation to be performed on the copy of the data stored in the second data storage unit after a corresponding first modification is made to the copy of the data stored in the second storage unit and before a corresponding second modification is made to the copy of the data stored in the second storage unit, and

the data stored in the first data storage unit after the operation is the same as the copy of the data stored in the second data storage unit after the operation.

10. The method of claim 9 wherein

the causing the operation to be performed on the second data storage unit further comprises inserting a command to perform the operation, wherein

the command is inserted in the modifications between the first modification and the second modification.

11. The method of claim 1 further comprising:

restoring the data stored in the first data storage unit from the second data storage unit when the data stored in the first data storage unit is corrupted.

12. The method of claim 1 further comprising:

saving a version of data stored in the second data storage unit prior to storing the modification to the data stored in the second data storage unit.

13. The method of claim 12 wherein

both the version of the data and the modification to the data are accessible after storing the modification to the data stored in the second data storage unit.

14. The method of claim 1 further comprising:

writing the modification to the data to a log; and

writing the modification to the data from the log to a storage volume, wherein the second data storage unit comprises

a log, and

a storage volume.

15. The method of claim 14 further comprising:

allocating space in the second data storage unit for the modification to the data when writing the modification to the data from the log to the storage volume.

16. The method of claim 14 further comprising:

writing an oldest modification to the data from the log to the storage volume.

17. The method of claim 1 further comprising:

periodically making a new snapshot of the set of snapshots, wherein the second data storage unit comprises

a log,

a storage volume, and

a set of snapshots of the storage volume.

18. The method of claim 17 wherein

at least one of the set of snapshots is one of a copy-on-write snapshot and an instant snapshot.

19. The method of claim 17 further comprising:

writing the modification to the log,

writing a version of data stored in the storage volume to the copy-on-write snapshot, and

writing the modification to the data to the storage volume after writing the version of the data to the copy-on-write snapshot.

Assignments (13)
AMENDMENT NO. 1 TO PATENT SECURITY AGREEMENT Recorded Apr 8, 2025
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2025
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 070335/0013 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC (F/K/A VERITAS US IP HOLDINGS LLC)
Reel/Frame 069712/0090 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY IN PATENTS AT R/F 037891/0726 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS US IP HOLDINGS, LLC
Reel/Frame 054535/0814 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
MERGER AND CHANGE OF NAME Recorded Apr 18, 2016
From: VERITAS US IP HOLDINGS LLC; VERITAS TECHNOLOGIES LLC
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 038455/0752 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037891/0726 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037891/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2016
From: SYMANTEC CORPORATION
To: VERITAS US IP HOLDINGS LLC
Reel/Frame 037697/0412 →
CHANGE OF NAME Recorded Oct 1, 2007
From: VERITAS OPERATING CORPORATION
To: SYMANTEC OPERATING CORPORATION
Reel/Frame 019899/0213 →
Continuity (1)
Continuation 1069947500 · Oct 31, 2003