Restricted delivery storage cartridge
By introducing a restricted transfer control engine into the storage system and utilizing restricted transfer instructions and access to secret information, the problems of malware attacks and unauthorized transfer in the storage system are solved, thereby improving data security and system protection.
Patent Information
- Application Number
- CN202110417519.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-07-29
- Filing Date
- 2021-04-19
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2041-04-19
AI Technical Summary
Existing storage systems are vulnerable to malware attacks, such as ransomware attacks, which result in data being encrypted and unable to be recovered by users. Existing technologies are also difficult to effectively prevent the unauthorized delivery of storage boxes, posing the risk of data leakage and loss.
By introducing a restricted transport control engine into the storage system, the transport process of storage boxes is controlled by using restricted transport instructions and access secret information, ensuring that only authorized entities can transport restricted storage boxes and preventing unauthorized operations.
It effectively prevents malware attacks, ensures data security, prevents unauthorized storage box delivery, and improves system security and data protection capabilities.
Smart Images

Figure CN114063898B_ABST
Abstract
Description
Background Art
[0001] Storage systems can store digital information in magnetic tape cassettes. A tape drive is an electronic device that can read data from, write data to, and initialize a magnetic tape cassette. A magnetic tape cassette can include and hold a magnetic tape reel and can be loaded into a magnetic tape drive so that the cassette can be used for reading, writing, and / or initialization. The magnetic tape contained in the magnetic tape cassette is in the form of an elongated storage medium that moves on a tape head in a magnetic tape drive. The storage medium in the magnetic tape cassette can include magnetic storage media or optical storage media. BRIEF DESCRIPTION OF THE DRAWINGS
[0002] Some embodiments of the present disclosure are described with reference to the following drawings.
[0003] Figure 1 is a block diagram of an arrangement including a repository according to some examples.
[0004] Figures 2 to 7 are flow diagrams of various processes according to some examples.
[0005] Figure 8 is a block diagram of a storage medium storing machine-readable instructions according to some examples.
[0006] Figure 9 is a block diagram of a repository based on some examples.
[0007] Figure 10 is a flowchart of a process according to some examples.
[0008] Throughout the drawings, the same reference numerals denote similar, but not necessarily identical, elements. The drawings are not necessarily drawn to scale, and the size of some parts may be exaggerated to more clearly illustrate the examples shown. Furthermore, the drawings provide examples and / or implementations consistent with the description; however, the description is not limited to the examples and / or implementations provided in the drawings. DETAILED DESCRIPTION
[0009] In the present disclosure, unless the context clearly indicates otherwise, the use of the terms "a", "an", or "the" is intended to include the plural forms as well. Moreover, the terms "comprise", "including", "comprising", "containing", "having", and "containing" when used in the present disclosure specify the presence of stated elements, but do not exclude the presence or addition of other elements.
[0010] A "tape library" may refer to a physical structure in which multiple tape cartridges may be housed. The tape cartridges may be physically stored in physical storage slots of the tape library. A physical storage slot is a container or chamber into which a tape cartridge may be placed or removed.
[0011] The tape library can also include a tape cartridge transport device (or multiple tape transport devices) and a tape drive (or multiple tape drives). The tape cartridge transport device can include a robot, a tape cartridge picker, a tape cartridge gripper, a tape cartridge carriage, or any other type of mechanism for transporting a tape cartridge. The tape cartridge transport device can physically transport a tape cartridge from a physical storage slot to a tape drive, and vice versa.
[0012] The tape drive includes a motor for rotating a spool of a tape cartridge loaded in the tape drive. Rotation of the tape cartridge spool causes the tape in the tape cartridge to be wound or unwound, which causes the tape to move within the tape cartridge or into or out of the tape cartridge. The tape drive also includes a tape head having read and write elements to read data on a tape of the tape cartridge and write data to the tape.
[0013] The tape library can receive a command from a user or computing device to transport a tape cartridge from a storage slot and load the tape cartridge into a tape drive. The command received by the tape library is processed by machine-readable instructions stored on a machine-readable storage medium and executed by processing resources of the tape library.
[0014] A tape cartridge can be loaded into or unloaded from a tape drive. Loading a tape cartridge into a tape drive allows a remote initiator (a user, a computing device, or other entity) to perform reads and writes to a tape in the tape cartridge. A remote initiator refers to an entity that is separate from the tape library, but the remote initiator can be able to access the tape library over a communication medium, such as a wired network, a wireless network, or other type of communication medium.
[0015] In some examples, the tape cartridges in the tape library are used to store backup data for a host system. The host system for which the tape cartridges are to store backup data can include one or more computing devices. “Backup data” refers to data that is based on original data in the host system, where the backup data can refer to a copy of the original data or to any other data that is computed based on the original data from which the original data can be recovered if the original data is lost or corrupted for any reason. In other examples, the tape cartridges in the tape library can be used to store archival data or other types of data.
[0016] Malware attacks can attempt to remove or destroy original data stored in a host system. In addition, malware attacks can also attempt to remove or destroy data stored in a backup system, such as a tape library. An example of such a malware attack is a ransomware attack, in which an unauthorized entity (e.g., a user, program, or machine) encrypts data in a host system as well as in a backup storage system, such as a tape library. The encryption of data in the host system and data in the tape library can use an encryption key. Without the encryption key, a user of the host system cannot recover the encrypted data.
[0017] To prevent malware attacks, such as ransomware attacks, the tape library can deny any request to transport a tape cartridge between different destinations in the tape library unless the request is received from an authorized requester.
[0018] Although reference is made to using a tape library for data backup, the tape library can store data for other purposes.
[0019] Also, although reference is made to a tape library in some examples, it should be noted that techniques or mechanisms in accordance with some embodiments of the present disclosure can be applied to other types of storage systems that include storage cartridges that can be transported to storage drives for reading, writing, and initialization. To "transport" a storage cartridge in a storage system means to physically move the storage cartridge between different physical locations in the storage system. An example of another type of storage system is a disk-based storage system or a solid state storage system, in which the storage cartridges include disk-based storage cartridges or solid state drives (SSDs), respectively. Disk-based storage cartridges store data on rotatable media, such as magnetic media or optical media. SSDs include integrated circuit memory devices for storing data.
[0020] In accordance with some embodiments of the present disclosure, a computer (such as in a storage system or external to a storage system) receives a command to transport a storage cartridge from a physical storage slot to a storage drive in a storage system. The computer determines whether the storage cartridge is associated with a restricted transport indication set by a configuration operation in the storage system. In response to determining that the storage cartridge is associated with the restricted transport indication, the system checks for an indication that access to secret information was received and denies processing of the command to transport the storage cartridge in the absence of the indication that access to secret information was received.
[0021] In some examples, "accessing secret information" can refer to a password, a certificate, a signature, or any other "secret" information (i.e., known to a specified entity to perform an action, and intended not to be disclosed to entities other than the specified entity). "An indication that access secret information was received" can refer to receiving the access secret information itself, or can refer to receiving other information that provides an indication that the access secret information can have been previously received. In the latter example, an indication that access secret information was received can include a token, session information (e.g., a session cache), or the like. A "token" can refer to any element of information that, when set to a particular value, provides an indication of an event, such as a prior authentication of an entity based on access secret information provided by the entity. Session information refers to information stored as part of a session established between an entity and a storage system, where the session can have been established based on access secret information provided by the entity.
[0022] Example Storage
[0023] Figure 1 is a block diagram of an example arrangement including a storage repository 102 (e.g., a tape library or another type of storage repository) that is accessible by a host system 104 (or by any of a plurality of host systems 104). Communication between the host system 104 and the storage repository 102 can be over a network 103, such as a local area network (LAN), a wide area network (WAN), a storage area network (SAN), the Internet, or the like. The network 103 can include wired networks and / or wireless networks.
[0024] The host system 104 includes a computing device (or a plurality of computing devices) that is capable of issuing requests to access data stored in cartridges of the storage repository 102. For example, the host system 104 can access data in cartridges of the storage repository 102 as part of a data backup operation in which original data stored by the host system 104 (or by another system) is copied to the storage repository 102 for storage in cartridges (or a plurality of cartridges).
[0025] The host system 104 can also access data in one or more cartridges of the storage repository 102 by, for example, reading data of the one or more cartridges during a restore operation in which data stored by the one or more cartridges is copied back to the host system 104 or another system. The restore operation can be used to restore original data that was corrupted or lost.
[0026] In other examples, access to data stored in one or more cartridges of the storage repository 102 can be part of other types of operations performed by the one or more host systems 104.
[0027] In Figure 1In the example of FIG. 1 , the storage boxes are divided into a plurality of partitions 1 to N (where N ≥ 2). In other examples, the storage boxes in storage repository 102 are not divided into a plurality of partitions. A "partition" refers to a subset of storage boxes in storage repository 102 that is physically or logically separated from another subset of storage boxes in storage repository 102. Storage boxes in different partitions may be accessed by corresponding different host systems, or may be used to store different types of data or for any other purpose.
[0028] exist Figure 1 In the example of FIG, storage cartridge 106-1 is removably mounted in physical storage slot (or more simply "storage slot") 108-1 of partition 1. Similarly, storage cartridge 106-N is removably mounted in storage slot 108-N of partition N.
[0029] It should be noted that a storage cartridge 106-i (i=1 to N) can be removed from a corresponding storage slot 108-i to be transported by a transport device 110 to a different location in the storage library 102, for example, to a storage drive 112-i in partition i or to another storage slot in partition i. Each partition i can include a single storage drive 112-i or multiple storage drives.
[0030] Despite Figure 1 Only one conveyor device 110 is shown in the figure, but in other examples, the storage library 102 may include multiple conveyor devices. A "conveyor device" may refer to any mechanism that can physically transport storage boxes between different locations in the storage library 102. Examples of conveyor devices include pickers, robots, grippers, brackets, etc.
[0031] In accordance with Figure 1 In the example shown, the storage library 102 includes a storage interface 114 and a management interface 116 that is separate from the storage interface 114. The storage interface 114 is used to transfer data and control information between the storage library 102 and the host system 104. The data transferred through the storage interface 114 includes write data, which is transmitted by the host system 104 to the storage library 102 for storage in a storage cartridge, or read data, which is retrieved from the storage cartridge and transferred to the host system 104.
[0032] Control information that may be communicated through storage interface 114 may include commands received from host system 104 for performing data access operations (such as write operations or read operations) in storage library 102. Additionally, the commands may include commands for determining the status of storage library 102 (or a portion of storage library 102).
[0033] In some examples, storage interface 114 is a small computer system interface (SCSI) through which storage library 102 can receive SCSI commands from host system 104 and through which write data or read data is exchanged.
[0034] In other examples, the storage interface 114 includes a high-speed non-volatile memory (NVMe) TM ) interface, NVMe TM Commands and data can be exchanged through this high-speed non-volatile memory interface.
[0035] In a further example, the storage interface 114 may be according to another protocol, whether standardized, proprietary, or open source.
[0036] The management interface 116 of the repository 102 is separate from the storage interface 114 and provides a separate communication path between external entities and the repository 102. An "external entity" is an entity (e.g., a program, machine, person, etc.) that is external to the repository 102. For example, the external entity may include the host system 104, the administrator system 105 (e.g., a computing system associated with an administrator of the repository 102), and the like.
[0037] The management interface 116 is used to perform various management tasks related to the repository 102, including configuration of the repository 102, monitoring of the repository 102, etc. An example of the management interface 116 is a Representational State Transfer (REST) application programming interface (API), which can be used to provide network services (referred to as RESTful network services). The REST API supports various routines (also referred to as methods) and rules that define how external entities will interact with the repository 102 through the management interface 116.
[0038] In a further example, the repository 102 may also include an administrator interface 117, which in some examples may be referred to as a remote management interface (RMI). The administrator interface 117 may be in the form of a dedicated website that can be accessed by authorized personnel (e.g., an administrator using the administrator system 105) to perform configuration of the repository 102. When the website presented by the administrator interface 117 is accessed by a system such as the administrator system 105, a web-based user interface may be presented at the administrator system 105 (such as in a web browser). The administrator may use the web-based user interface to perform administrative tasks with respect to the repository 102.
[0039] Although referred to as an “administrator interface,” administrator interface 117 may be considered an administrative interface, except in a different format than management interface 116 . Administrator interface 117 or management interface 116 may be used to initiate configuration operations in repository 102 .
[0040] Storage repository 102 also includes a restricted transfer control engine 118 that controls whether transfer of storage cartridges 106 in storage repository 102 is permitted in response to a transfer storage cartridge command (120) received from host system 104 (or from another system such as administrator system 105) over network 103.
[0041] As used herein, an "engine" may refer to a hardware processing circuit that may include any one or some combination of a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit. Alternatively, an "engine" may refer to a combination of a hardware processing circuit and machine-readable instructions (software and / or firmware) that can be executed on the hardware processing circuit.
[0042] The storage library 102 includes a memory 122, which may be implemented using a memory device or multiple memory devices. The memory device may include a dynamic random access memory (DRAM) device, a static random access memory (SRAM) device, a flash memory device, or any other type of memory device.
[0043] Memory 122 may store information including indications 124-1 through 124-N associated with respective partitions 1 through N. Indications 124-1 through 124-N are restricted transport indications (RTIs) that are set during a configuration operation of storage repository 102. The configuration operation may be initiated by administrator system 105, by host system 104, or by another system.
[0044] In accordance with Figure 1 In the example of FIG, RTI 124-1 is associated with partition 1, so that any storage box 106-1 in partition 1 is a restricted transport storage box. Similarly, RTI 124-N is associated with partition N, so that any storage box 106-N in partition N is a restricted transport storage box.
[0045] A "restricted transport storage cassette" refers to a storage cassette whose transport within storage repository 102 (such as by transport device 110) in response to a command (eg, 120) from outside storage repository 102 is subject to restricted transport processing (discussed further below).
[0046] In other examples, instead of associating RTIs with corresponding partitions in the repository 102, RTIs may be associated with individual storage boxes (ie, one RTI per individual storage box) or may be associated with different subsets of storage boxes.
[0047] RTI may refer to any type of indicator (in the form of a flag, variable, parameter, or any other information element) that can be set to any of a plurality of different values (e.g., "0" and "1"). RTI corresponds to an indicator being set to a first value. If the indicator is set to a second value different from the first value, then RTI is not set for the corresponding storage box, partition, or other subset of storage boxes.
[0048] Figure 1 Also shown is an indication 126 stored in memory 122. Indication 126 is an indication of receipt of access secret information associated with a command (e.g., 120) to transport a storage cartridge. Indication 126 may be referred to as an access secret indication (ASI). Figure 1 Only one ASI is shown in FIG. 1 , but it should be noted that the memory 122 may store multiple ASIs indicating that access secret information is received from multiple external entities and / or for different partitions.
[0049] The ASI 126 may include access secret information itself, or the ASI 126 may include information indicating pre-authentication of the source of the command to deliver the storage box. In the latter example, the ASI 126 may be in the form of a token, session information (e.g., a session cache), etc. A token may refer to any information element that provides an indication of an event when set to a specific value, such as pre-authentication of the source of the command to deliver the storage box. Session information refers to information stored as part of a session established between an external entity and the storage repository 102. For example, when an external entity logs into the storage repository 102 through the management interface 116 based on the external entity's submission of credentials to the management interface 116, session information indicating that the external entity successfully logged in may be created. A successful login constitutes pre-authentication of the external entity, which may then issue a command to deliver the storage box (120).
[0050] If the received access secret information matches the access secret information stored for the storage box or for the partition containing the storage box, then ASI 126 is set. If the received access secret information matches the access secret information stored for the storage box or for the partition containing the storage box by the repository 102, then ASI 126 is set. For example, access secret information for a corresponding different partition or different storage box may be stored in the memory 122 (or another memory) for comparison with the received access secret information.
[0051] For example, ASI 126 may include an indicator that may be set to a first value to indicate that the received access secret information matches the access secret information stored by repository 102 for the storage cartridge or for the partition containing the storage cartridge, and may be set to a different second value to indicate that the received access secret information does not match the access secret information stored by repository 102 for the storage cartridge or for the partition containing the storage cartridge. As examples, the indicator may be in the form of a flag or parameter, or in the form of session information or a token.
[0052] The storage repository 102 may store a plurality of different access secret information for corresponding storage boxes or corresponding partitions. The plurality of access secret information may be provided to the storage repository 102 by the administrator system 105 , for example, via the administrator interface 117 .
[0053] The storage bank 102 also includes a controller 115 that controls operations within the storage bank 102. The controller 115 may include a hardware processing circuit that may include any one or some combination of a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit.
[0054] In some examples, the controller 115 may process any of the various commands received through the storage interface 114, and the controller 115 may perform corresponding actions in response to the commands. For example, the controller 115 may instruct the transport device 110 to transport the storage cartridge 106-i from the storage slot 108-i to the storage drive 112 and cause the storage cartridge 106-i to be loaded into the storage drive 112. As a further example, the controller 115 may cause the storage cartridge 106-i to be unloaded from the storage drive 112 and transported to the storage slot 108-i.
[0055] although Figure 1 The limited delivery control engine 118 is shown separate from the controller 115 , but in other examples, the limited delivery control engine 118 may be part of the controller 115 .
[0056] Restricted transport processing
[0057] Figure 2 is a flow chart of a restricted delivery process that may be performed by the restricted delivery control engine 118 according to some examples. The restricted delivery control engine 118 receives a request from a requester (eg, an external entity such as Figure 1 The host system 104 in the embodiment receives (at 202) a message received from a storage system (e.g., Figure 1 102) to remove the storage box from the storage slot ( Figure 1 108-1 or 108-N) to a storage drive (e.g., Figure 1 112) command (for example, Figure 1 The command may be received through the storage interface 114 or through the management interface 116.
[0058] The restricted transport control engine 118 determines (at 204) whether the storage cartridge is compatible with the restricted transport indication set by a configuration operation in the storage system (e.g., Figure 1 RTI 124-1 or 124-N) in.
[0059] In response to determining (at 204) that the storage cartridge is associated with a restricted delivery indication, the restricted delivery control engine 118 examines (at 206) the access secret information received from the requestor (eg, Figure 1 126).
[0060] If there is an indication that access secret information has been received from the requestor, the restricted delivery control engine 118 allows (at 208) processing of the command to deliver the storage cartridge.
[0061] On the other hand, if there is no indication that access to the secret information has been received from the requestor, the restricted delivery control engine 118 denies (at 210) processing of the command to deliver the storage cartridge.
[0062] In response to determining (at 204) that the storage cartridge is not associated with a restricted delivery indication, the restricted delivery control engine 118 allows (at 208) processing of the command to deliver the storage cartridge.
[0063] The restricted transport control engine 118 sends the control information ( Figure 1 119 in the control information) is provided to the controller 115. If the restricted delivery control engine 118 indicates a command to reject delivery in the control information, the controller 115 does not process the command to deliver the storage box. However, if the restricted delivery control engine 118 indicates a command to allow delivery in the control information, the controller 115 may process the command to deliver the storage box by controlling the delivery device 110. The control information may be in the form of a signal, a message, or any other type of information.
[0064] Combined with the following Figures 4 to 6 Further examples of limited delivery processing are discussed further.
[0065] Configure restricted transport storage box
[0066] Figure 3 is a flow chart of a process for configuring a restricted transport storage cassette. Figure 3The process includes initiating (at 302) a configuration operation in response to a command from administrator system 105, host system 104, or another system. The command may be received through administrator interface 117, management interface 116, or storage interface 114. In some examples, before initiating the configuration operation, an authentication operation may be performed to confirm that the source of the command is authorized to make the requested configuration change.
[0067] Figure 3 The process includes setting (at 304) a storage box as a restricted transport storage box in a configuration operation. Note that setting a storage box as a restricted transport storage box may involve individually setting a storage box as a restricted transport storage box, or may involve setting a group of storage boxes as restricted transport storage boxes (e.g., Figure 1 Part of the partition shown in ).
[0068] A variety of configuration techniques can be used to configure a storage box as a restricted transport storage box during a configuration operation. In some examples, the configuration operation to configure a storage box as a restricted transport storage box can use a command passed through the storage interface 114 of the storage library 102. The command can be issued from the administrator system 105 or from the host system 104. The storage box being configured as a restricted transport storage box can be indicated by setting a corresponding RTI 124-i in the memory 122.
[0069] As an example, a command to configure a storage cartridge as a restricted transport storage cartridge may be a configuration command for performing a configuration operation in the storage repository 102. It should be noted that the configuration command does not result in the transport of the storage cartridge in the storage repository 102, or in access to data in the storage cartridge in the storage repository 102, or in another operation in the storage repository 102 other than the configuration operation.
[0070] Configuration commands can be new SCSI commands or new NVMe TM Commands. A "new" SCSI command is one that is not specified by the current SCSI standard but may or may not be specified by future SCSI standards. Similarly, a "new" NVMe TM The command refers to the current NVMe TM The standard has not yet been specified, but the future of NVMe TM Commands that a standard may or may not specify.More generally, a “new” command refers to a command that is not yet specified by the current standard for the storage interface 114 but that a future standard for the storage interface 114 may or may not specify.
[0071] In a further example, a configuration command to configure a storage box as a restricted transport storage box may include an existing command that is extended to add a new information element (e.g., a parameter) that can be set to a specific value to indicate restricted transport mode. An "existing" SCSI command refers to a command that exists in the current SCSI standard. However, the new information element is not specified by the current SCSI standard and may or may not be specified by a future SCSI standard. Similarly, an "existing" NVMe TM The command refers to the current NVMe TM However, the new information elements are not specified by the current SCSI standard and may or may not be specified by future NVMe TM More generally, “existing” commands refer to commands that exist in the current standard for storage interface 114 . New information elements are not specified in the current standard for storage interface 114 , but may or may not be specified by a future standard for storage interface 114 .
[0072] An example of an existing SCSI configuration command with a new information element may be a SEND VOLUME TAG command. The SEND VOLUME TAG command associates a tag with the storage cartridge identified in the command. In some examples, the new information element added to the SEND VOLUME TAG command may be set to a value indicating that the storage cartridge is a restricted transport storage cartridge, which causes a corresponding RTI 124-i to be set in memory 122. In other examples, other existing SCSI configuration commands or other existing NVMe SDRAM commands that are extended with the new information element may be employed. TM Configuration command, this new information element is used to indicate that the storage box is a restricted transport storage box.
[0073] In a further example, instead of using a configuration command, the command to configure the storage box as a restricted transport storage box may include a storage box manipulation command (such as a command to transport the storage box). More generally, a "storage box manipulation command" may refer to any command that can cause an operation to be performed on the storage box (such as transport, read, write, etc.).
[0074] The storage box manipulation command that can be used to configure the storage box as a restricted transport storage box can be a new storage box manipulation command or an existing storage box manipulation command that is extended to add a new information element. For example, the existing storage box manipulation command can be a SCSI MOVE MEDIUM command, which is used to transport a storage box for loading or unloading relative to a storage drive. The SCSI MOVE MEDIUM command can be extended with a new information element to set the storage box being transported as a restricted transport storage box, which can be indicated by setting a corresponding RTI 124-i in the memory 122. In other examples, other existing SCSI storage box manipulation commands or other existing NVMe TM Storage box manipulation commands.
[0075] In an example, the host system 104 may determine that a particular storage cartridge is to be protected after a task is completed on the given storage cartridge (e.g., a write to the given storage cartridge is completed). The task includes submitting a SCSI MOVE COMMAND to move the given storage cartridge to a storage drive to perform the write. In the same SCSI MOVE COMMAND, the host system 104 may set a new information element to specify that the given storage cartridge is a restricted transport storage cartridge.
[0076] In another example, a combination of a configuration command and an existing storage cartridge manipulation command may be used to configure a storage cartridge as a restricted transport storage cartridge. For example, a configuration command may be issued to specify that a given storage cartridge is to be set as a restricted transport storage cartridge when it is transported from the storage drive in response to a subsequently issued storage cartridge manipulation command.
[0077] In a further example, the configuration operation of configuring a storage box as a restricted transport storage box may be configuring a partition in the storage library 102 as part of a restricted transport partition. A corresponding RTI 124-i may be set in the memory 122 for the restricted transport partition. Any storage box present in a storage slot of the restricted transport partition is considered a restricted transport storage box; in other words, a command to transport a storage box in the restricted transport partition will be processed by the restricted transport control engine 118 to determine whether the command is allowed or denied (such as based on the Figure 2 ).
[0078] In some examples, a partition can be set as a restricted delivery partition by an administrator at an administrator system 105, which can access the repository 102 through the administrator interface 117 of the repository 102. For example, the administrator system 105 can connect to the administrator interface 117 of the repository 102, and once connected, the administrator system 105 can present a user interface that allows the administrator at the administrator system 105 to perform configuration of the repository 102.
[0079] In other examples, a command to set a partition of the storage library 102 as a restricted transport partition may be provided via the storage interface 114. The command may include a new SCSI command, an existing SCSI command extended with a new information element, a new NVMe TM commands, existing NVMe extended with new information elements TM Commands, etc. In other examples, a command to set a partition of the repository 102 as a restricted shipping partition may be provided through the management interface 116 .
[0080] Restricted Delivery Processing – Further Examples
[0081] Figure 4 is a flow chart of a process 400 for performing restricted transport processing for a storage cassette, according to some examples. The process 400 assumes that the storage cassette is a restricted transport storage cassette (eg, RTI is set for the storage cassette).
[0082] Restricted Delivery Control Engine 118 ( Figure 1 ) receives (at 402) a storage cartridge delivery command including an information element carrying access secret information (eg, password, signature, certificate, etc.). The received storage cartridge delivery command is a command to deliver the storage cartridge.
[0083] The restricted delivery control engine 118 determines (at 404) whether the access secret information in the received command matches the stored access secret information, which may be stored, for example, in the memory 122 or another memory. If so, the restricted delivery control engine 118 allows (at 406) delivery of the storage cartridge in response to the received command. However, if the access secret information in the received command does not match the stored access secret information, the restricted delivery control engine 118 denies (at 408) delivery of the storage cartridge.
[0084] Figure 5 is a flow chart of a restricted transport processing process 500 according to a further example. The process 500 assumes that the storage cassette is a restricted transport storage cassette (eg, an RTI is set for the storage cassette).
[0085] Process 500 uses an out-of-band interface for the storage box to pass commands. The "out-of-band interface" is Figure 1 The out-of-band interface includes an interface separate from the storage interface 114, which is considered an in-band interface for transmitting storage commands and data. Figure 1 The out-of-band interface can be connected to a host system (e.g., Figure 1 104) different computers.
[0086] In such examples, authorization to perform the delivery of the storage cartridge is based on authentication in an out-of-band interface, such as management interface 116. This is similar to using Figure 4 This is in contrast to the illustrated authentication of the in-band interface of the storage library 102 (ie, storage interface 114), where access secret information is provided along with the command to deliver the storage cartridge.
[0087] In the restricted delivery process 500, the repository 102 accepts (at 502) a login from an external entity to the management interface 116. For example, the external entity may be the host system 104. In response to the external entity submitting login credentials (e.g., a user name and password or other credentials, such as a certificate or signature) to the management interface 116, a login session is successfully established with the management interface 116. In the restricted delivery process 500, the login credentials for the management interface 116 are access secret information.
[0088] The restricted transport control engine 118 receives (at 504) a storage cartridge transport command from an external entity to transport the storage cartridge.
[0089] The restricted transfer control engine 118 determines (at 506) whether the cartridge transfer command was received as part of a login session with the management interface 116, which provides implicit authorization for the cartridge transfer command to be granted. Figure 5 In the example, the session information of the login session is considered as ASI.
[0090] If the storage cartridge transfer command is received as part of a login session with the management interface 116, the restricted transfer control engine 118 allows (at 508) the transfer of the storage cartridge. If the storage cartridge transfer command is not received as part of a login session with the management interface 116, the restricted transfer control engine 118 denies (at 510) the transfer of the storage cartridge.
[0091] Figure 6 is a flow chart of a restricted transport processing process 600 according to a further example. The process 600 assumes that the storage cassette is a restricted transport storage cassette (eg, an RTI is set for the storage cassette).
[0092] and Figure 5 As is the case with the restricted delivery process 500, Figure 6 The restricted transport process 600 uses an out-of-band interface (e.g., management interface 116) to authenticate whether the requestor requesting a storage cartridge transport is authorized to do so. Figure 6 In the embodiment, instead of also using the out-of-band interface to receive the storage cartridge transport command, the in-band interface (eg, storage interface 114) is used to receive the storage cartridge transport command.
[0093] In the restricted delivery process 600, the repository 102 accepts (at 602) a login from an external entity to the management interface 116. For example, the external entity may be the host system 104. As a result of the external entity's successful login session with the management interface 116, the repository 102 stores (at 604) the ASI for the external entity (e.g., in a session cache).
[0094] Subsequently, the restricted transfer control engine 118 receives (at 606 ) a storage cartridge transfer command from an external entity through the storage interface 114 to transfer the storage cartridge.
[0095] The restricted delivery control engine 118 checks (at 608) the ASI (e.g., in the session cache) to determine whether the external entity is authorized to request the storage cartridge delivery. If the ASI is present, the restricted delivery control engine 118 allows (at 610) the storage cartridge delivery. If the ASI is not present, the restricted delivery control engine 118 denies (at 612) the storage cartridge delivery.
[0096] In an additional example, the restricted transport control engine 118 may perform a two-level check to determine whether to allow a storage box transport command. For example, the restricted transport control engine 118 may check at the first level that a login has been successfully established by the external entity with the management interface 116. The restricted transport control engine 118 may also check at the second level that the external entity has also provided separate access secret information for the storage box through the management interface 116 or through the storage interface 114. This separate access secret information may be for an individual storage box or for the partition in which the storage box resides. If both the first-level check and the second-level check are successful, the storage box transport command is allowed. If either the first-level check or the second-level check fails, the storage box transport command is denied.
[0097] Reporting restricted delivery status
[0098] After the storage cassette has been configured as a restricted transport storage cassette, a requester, such as host system 104, may request the status of the restricted transport storage cassette.
[0099] Figure 7is a flowchart of a storage cartridge status reporting procedure 700 according to some examples. The storage library 102 receives (at 702) a command related to storage cartridge status from a requestor (e.g., the host system 104 or the administrator system 105). The command can be received through any of the storage interface 114, the management interface 116, or the administrator interface 117. The command can be a command that specifically invokes status information for a storage cartridge or a group of storage cartridges (e.g., a partition). Alternatively, the command can be a command for a shipping storage cartridge that triggers a status report.
[0100] In response to the command related to storage cartridge status, the storage library 102 sends (at 704) status information for the storage cartridge. The status information can include restricted shipping information that indicates whether the storage cartridge is a restricted shipping storage cartridge. For example, the restricted shipping information can include an indicator that indicates the storage cartridge is a restricted shipping storage cartridge if set to a first value, and that indicates the storage cartridge is not a restricted shipping storage cartridge if set to a different second value.
[0101] In other examples, the status information can indicate whether a partition or another group of storage cartridges is a restricted shipping partition / group.
[0102] In some examples, the status information can include a SCSI READ ELEMENT STATUS message. The READ ELEMENT STATUS message has bytes that can be used to report additional information (examples of restricted shipping information described above), and the definition of the meaning of the additional information is customizable (such as by the manufacturer of the storage library 102).
[0103] Alternatively, the READ ELEMENT STATUS message includes a field that reports that the storage library cannot access a storage slot in the storage library. The field can be used alone or in conjunction with reporting in additional bytes of the READ ELEMENT STATUS message.
[0104] Additional Examples
[0105] Figure 8 is a block diagram of a non-transitory machine-readable or computer-readable storage medium 800 that stores machine-readable instructions that, when executed, cause a computer to perform various acts. The computer can include a processing resource (including one or more processors) of a storage system (e.g., the storage library 102 in Figure 1 or can be separate from the storage system.
[0106] The machine-readable instructions include storage cartridge transfer command receiving instructions 802 for receiving a command to transfer a storage cartridge from a physical storage slot to a storage drive in a storage system. In some examples, the command is received via a storage interface of the storage system. In other examples, the command is received via a management interface of the storage system.
[0107] The machine-readable instructions include restricted shipping indication determining instructions 804 for determining whether the storage cartridge is associated with a restricted shipping indication set by a configuration operation in the storage system.
[0108] The machine-readable instructions include access secret information receiving instructions 806 for checking an indication of received access secret information in response to determining that the storage box is associated with a restricted delivery indication. In some examples, the access secret information is included in the command. In other examples, the access secret information is used to gain access to a management interface; for example, the access secret information may include login information for logging into the management interface. In a further example, the indication of received access secret information includes information indicating pre-authentication of the source of the command (for example, the access secret information may be stored in a token or session information in response to the pre-authentication). For example, the session information is created in response to a requestor logging into the management interface of the storage system, and a command to deliver the storage box is received through the storage interface of the storage system. As another example, a token is received in association with the command, wherein the token is used to provide an indication that the source of the command previously submitted credentials authenticating the source.
[0109] The machine-readable instructions include cartridge delivery deny instructions 808 for denying processing of a command to deliver a cartridge in the absence of an indication of receipt of access secret information.
[0110] Figure 9 is a block diagram of a storage library 902 including physical storage slots 904 , storage drives 906 , and a transport device 908 for transporting storage cartridges between different locations in the storage library 902 .
[0111] The storage bank 902 also includes a processor 910 (or multiple processors). The processor may include a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit.
[0112] The repository 902 also includes a non-transitory storage medium 912 storing machine-readable instructions executable on the processor 910 to perform various tasks. The machine-readable instructions executable on a hardware processor may refer to instructions executable on a single hardware processor or instructions executable on multiple hardware processors.
[0113] The machine-readable instructions in the storage medium 912 include restricted delivery indication configuration instructions 914 for configuring a restricted delivery indication with a storage cartridge in a storage library during a configuration operation.
[0114] The machine-readable instructions in the storage medium 912 include storage cartridge transport command receiving instructions 916 for receiving a command to transport a storage cartridge from a physical storage slot to a storage drive.
[0115] The machine-readable instructions in the storage medium 912 include restricted delivery indication determining instructions 918 for determining whether the storage cartridge is associated with a restricted delivery indication set by a configuration operation.
[0116] The machine-readable instructions in the storage medium 912 include access secret information receiving instructions 920 for checking for an indication of received access secret information in response to determining that the storage cartridge is associated with a restricted delivery indication.
[0117] The machine-readable instructions in the storage medium 912 include cartridge delivery deny instructions 922 for denying processing of a command to deliver a cartridge in the absence of an indication of receipt of access secret information.
[0118] Figure 10 Is a storage system (such as Figure 1 Flowchart of process 1000 of repository 102).
[0119] Process 1000 includes receiving (at 1002) a command from a requestor to transport a storage cartridge from a physical storage slot to a storage drive in a storage system.
[0120] Process 1000 includes determining (at 1004) whether a storage cartridge is associated with a restricted transport indication set by a configuration operation in the storage system.
[0121] In response to determining that the storage cartridge is associated with a restricted delivery indication, process 1000 checks (at 1006) for an indication of receipt of access secret information from the requestor and denies (at 1008) processing of the command to deliver the storage cartridge in the absence of an indication of receipt of access secret information from the requestor.
[0122] In response to determining that the storage cartridge is not associated with a restricted delivery indication, process 1000 allows (at 1010) processing of a command to deliver the storage cartridge.
[0123] Storage media (e.g. Figure 8 800 or Figure 9904) may include any one or some combination of the following: semiconductor memory devices, such as dynamic or static random access memory (DRAM or SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory or other types of non-volatile memory devices; magnetic disks, such as fixed disks, floppy disks, and removable disks; another magnetic medium, including magnetic tape; optical media, such as compact disks (CDs) or digital video disks (DVDs); or another type of storage device. It should be noted that the instructions discussed above may be provided on a single computer-readable or machine-readable storage medium, or alternatively, may be provided on multiple computer-readable or machine-readable storage media distributed across a large system, possibly with multiple nodes. Such one or more computer-readable or machine-readable storage media are considered part of an article (or article of manufacture). An article or article of manufacture may refer to any manufactured single component or multiple components. The one or more storage media may be located in the machine that runs the machine-readable instructions, or at a remote site, from which the machine-readable instructions may be downloaded over a network for execution.
[0124] In the foregoing description, numerous details have been set forth to provide an understanding of the subject matter disclosed herein. However, embodiments may be practiced without some of these details. Other embodiments may include modifications and variations of the details discussed above. The appended claims are intended to cover such modifications and variations.
Claims
1. A non-transitory machine-readable storage medium comprising instructions that, when executed, cause a computer to: As part of a configuration operation, a configuration command is received that includes an information element set to a value indicating that a storage cartridge in the storage system has a restricted transport mode, wherein the configuration command is for configuring the storage cartridge, and the information element set to the value in the configuration command specifies that the storage cartridge is a restricted transport storage cartridge, transport of the restricted transport storage cartridge within the storage system in response to a command from outside the storage system is subject to restricted transport processing, and wherein the configuration command is a Small Computer System Interface (SCSI) configuration command or a high-speed non-volatile memory configuration command; responsive to the configuration command including the information element being set to the value specifying the storage cassette as the restricted delivery storage cassette, storing a restricted delivery indication in memory in association with the storage cassette; receiving a second command to transfer the storage cartridge from the physical storage slot to the storage drive; determining whether the storage cartridge is associated with the restricted delivery indication set in the memory by the configuration operation in response to the configuration command; and In response to determining that the storage cartridge is associated with the restricted delivery indication, checking for an indication of receipt of access secret information, and denying processing of the second command to deliver the storage cartridge in response to determining that the indication of receipt of the access secret information is absent.
2. The non-transitory machine-readable storage medium according to claim 1, wherein The configuration command does not result in delivery of the storage cartridge.
3. The non-transitory machine-readable storage medium of claim 1 , wherein: The configuration commands do not result in accessing data in the storage cartridge.
4. The non-transitory machine-readable storage medium of claim 1 , wherein: The restricted transport indication includes a flag set to a first value, and wherein the memory stores the flag set to a different second value indicating that another cassette is not a restricted transport cassette.
5. The non-transitory machine-readable storage medium of claim 1 , wherein: When executed, the instructions cause the computer to: receiving a command related to a status of the storage box; and In response to the command regarding the state of the storage cassette, a response including information indicating that the storage cassette is the restricted-transport storage cassette is transmitted.
6. The non-transitory machine-readable storage medium of claim 1, wherein: The access secret information is included in the second command.
7. The non-transitory machine-readable storage medium of claim 6, wherein: The second command is a SCSI command or a high-speed non-volatile memory command, and the access secret information is included in a field of the SCSI command or the high-speed non-volatile memory command.
8. The non-transitory machine-readable storage medium of claim 1, wherein: The second command is received through a management interface of the storage system.
9. The non-transitory machine-readable storage medium of claim 8, wherein: The access secret information is used to obtain access to the management interface.
10. The non-transitory machine-readable storage medium of claim 9, wherein: The access secret information includes login information of the management interface for logging into the management interface.
11. The non-transitory machine-readable storage medium of claim 1 , wherein: The indication of receipt of the access secret information includes information indicative of pre-authentication of a source of the second command.
12. The non-transitory machine-readable storage medium of claim 11, wherein: The information indicative of the pre-authentication includes session information, and wherein the instructions, when executed, cause the computer to: creating the session information in response to a requester logging into a management interface of the storage system; and The second command is received through a storage interface of the storage system, where the storage interface is separate from the management interface.
13. The non-transitory machine-readable storage medium of claim 11, wherein: The information indicative of the pre-authentication includes a token, and wherein the instructions, when executed, cause the computer to: The token is received in association with the second command, the token being used to provide an indication that the source of the second command previously submitted credentials authenticating the source.
14. The non-transitory machine-readable storage medium of claim 1, wherein: The access secret information is for a first partition of a plurality of partitions of the storage system comprising storage boxes, wherein each partition of the plurality of partitions comprises a subset of the storage boxes, and the access secret information for the first partition is different from another access secret information for another partition of the plurality of partitions.
15. The non-transitory machine-readable storage medium of claim 14, wherein: The second command is received through a management interface accessed using further secret access information.
16. The non-transitory machine-readable storage medium of claim 1, wherein: The configuration command is received at the storage system from a system separate from the storage system.
17. A storage library, comprising: physical storage slots; Storage drives; a conveying device for conveying storage boxes between different locations in the storage library; processor; and a non-transitory storage medium storing instructions executable on the processor to: In a configuration operation, a configuration command is received at the storage library from a system separate from the storage library, the configuration command including an information element set to a value specifying that a storage cartridge in the storage library is a restricted transport storage cartridge, transport of the restricted transport storage cartridge within the storage library in response to a command from outside the storage library being subject to restricted transport processing, wherein the configuration command is for configuring the storage cartridge and is a Small Computer System Interface (SCSI) configuration command or a high-speed non-volatile memory configuration command; responsive to the configuration command including the information element being set to the value specifying the storage cassette as the restricted delivery storage cassette, storing a restricted delivery indication in memory in association with the storage cassette; receiving a second command to transfer the storage cartridge from the physical storage slot to the storage drive; determining whether the storage cartridge is associated with the restricted delivery indication set in the memory by the configuration operation in response to the configuration command; and In response to determining that the storage cartridge is associated with the restricted delivery indication, checking for an indication of receipt of access secret information, and denying processing of the second command to deliver the storage cartridge in response to determining that the indication of receipt of the access secret information is absent.
18. The storage library according to claim 17, wherein: The configuration command does not result in the transport of the storage cartridge and does not result in access to data in the storage cartridge.
19. A method for a storage system, the storage system comprising a storage drive, the method comprising: receiving, at the storage system, from a system separate from the storage system, as part of a configuration operation, a configuration command including an information element set to a value specifying that a storage cartridge in the storage system is a restricted transport storage cartridge, transport of the restricted transport storage cartridge within the storage system in response to a command from outside the storage system being subject to restricted transport processing, wherein the configuration command is for configuring the storage cartridge and does not result in transport of the storage cartridge and does not result in access to data in the storage cartridge, and wherein the configuration command including the information element set to the value is a Small Computer System Interface (SCSI) configuration command or a high-speed non-volatile memory configuration command; responsive to the configuration command including the information element being set to the value specifying the storage cassette as the restricted delivery storage cassette, storing a restricted delivery indication in memory in association with the storage cassette; receiving a second command from a requestor to transfer the storage cartridge in the storage system from a physical storage slot to the storage drive; determining whether the storage cartridge is associated with the restricted delivery indication set in the memory by the configuration operation in response to the configuration command; responsive to determining that the storage cartridge is associated with the restricted delivery indication, checking for an indication of receipt of access secret information from the requestor, and responsive to determining that the indication of receipt of the access secret information from the requestor is absent, denying processing of the second command to deliver the storage cartridge; receiving a third command to transfer an additional storage cartridge from another physical storage slot to the storage drive; and In response to determining that the additional storage cartridge is not associated with a restricted delivery indication, processing of the third command to deliver the additional storage cartridge is permitted.
Citation Information
Patent Citations
Configuring a storage drive to communicate with encryption and key managers
CN101501698A
Systems and methods for NFC access control in a secure element centric nfc architecture
CN105493538A