WRITE PROTECTION FOR MEMORY CARTRIDGES

The storage controller in storage systems checks for pre-configured write protection thresholds to prevent unauthorized data modifications, addressing the vulnerability of storage cartridges to malware attacks and ensuring data integrity by allowing only authorized write operations.

DE102021106326B4Active Publication Date: 2025-07-31HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
DE102021106326
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-08-25
Filing Date
2021-03-16
Publication Date
2025-07-31
Estimated Expiration
2041-03-16

AI Technical Summary

Technical Problem

Existing storage systems lack effective mechanisms to prevent unauthorized data modification or deletion of data stored in storage cartridges, particularly in the context of malware attacks such as ransomware, which can encrypt data and make it unrecoverable without the encryption key.

Method used

A storage controller is implemented to check if a storage cartridge has previously written data exceeding a specified threshold, and if so, triggers write protection to prevent further data writing, erasure, or reformatting, using indicators set during configuration to ensure data integrity.

Benefits of technology

Ensures data protection by preventing unauthorized modifications to storage cartridges, safeguarding against malware attacks and maintaining data integrity by allowing only authorized write operations based on pre-configured thresholds.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A non-transitory, machine-readable storage medium (300) comprising instructions that, when executed, cause a controller for a storage system separate from a host system (104) to:check whether a memory cartridge in the storage system is associated with an indicator set in an electronic memory of the storage system during a configuration operation in the storage system for a partition of the storage system to indicate that write protection is enabled for a plurality of memory cartridges (106) mounted in the partition,wherein the plurality of memory cartridges (106) comprise the memory cartridge, the electronic memory of the storage system is separate from the memory cartridge, and wherein the checking comprises reading, by the controller, an indicator from the electronic memory of the storage system;andin response to a determination based on reading the indication from the electronic memory of the storage system that write protection for the plurality of memory cartridges (106) is enabled, enabling write protection for the plurality of memory cartridges (106) in the partition, including triggering write protection for the memory cartridge to prevent data from being written to the memory cartridge if the memory cartridge contains previously written data.;
Need to check novelty before this filing date? Find Prior Art

Description

background

[0001] Storage systems can store digital information in a tape cartridge. A tape drive is an electronic device that can read data from, write data to, and initialize a tape cartridge. A tape cartridge may contain and hold a tape reel and can be loaded into the tape drive to make the tape cartridge available for reading, writing, and / or initialization. The tape housed in the tape cartridge is in the form of an elongated storage medium that is movable over a tape head of a tape drive. The storage medium of a tape cartridge may comprise a magnetic storage medium or an optical storage medium.

[0002] US 6 611 394 B1 relates to a tape-shaped recording medium housed in a cassette to form a tape cassette, a tape drive for writing or reading data on the tape-shaped recording medium, and a method for distinguishing the type of recording medium loaded in the tape drive.

[0003] US 9 396 754 B1 describes a data storage library that essentially provides a WORM (Write Once and Read Many) conversion device integrated with a picker device. All of these devices are located within the data storage library. One embodiment of US 9 396 754 B1 provides that, upon receipt of a request to store data in a WORM arrangement on a tape cartridge in the data storage library, a tape cartridge selected from a working pool of tape cartridges can be converted into a WORM tape cartridge via the picker device during normal activity in which a picker device is used to pick the selected tape cartridge.

[0004] US 2010 / 0 031 054 A1 describes a tape cartridge containing a tape storage medium with stored encrypted data that can be decrypted using an encryption key. The tape cartridge also contains a central auxiliary memory with a moniker that identifies the encryption key. The tape cartridge also contains a threshold parameter stored in the additional media memory. The threshold parameter influences a moniker state control. The moniker state control includes an on state and an off state, with the off state preventing the moniker from identifying the encryption key.

[0005] US 2011 / 0 051 278 A1 describes that data overwriting protection of a rewritable non-WORM data storage cartridge is provided by a data storage drive that executes methods for protecting the cartridge from data overwriting, which are independent of the absence or non-availability of cartridge controls for data overwriting protection. Even with non-WORM cartridges, the drive responds to a data overwriting permit command to allow an immediately subsequent write command to write to the cartridge, even if the write command overwrites existing data. The overwrite protection methods and data overwriting methods can be configured and enabled for the data storage drive.

[0006] US 2019 / 0 347 020 A1 relates to an apparatus and method for configuring a data storage device as a WORM (Write Once Read Many) drive. In some embodiments of US 2019 / 0 347 020 A1, the storage device includes a rotatable disk having at least one data recording layer and a data converter selectively movable with respect to the rotatable disk. The data converter includes a write element configured to write data to the data recording layer and a read element configured to read data from the data recording layer. A control circuit is configured to physically disable the write element in response to a write element disable signal. Disabling the write element prevents further writing of data to the data recording layer.The read element remains active and can continue to read data from the data recording layer even after the write element is deactivated.

[0007] US 5 438 674 A relates to an optical disk system emulating a 3480 magnetic tape subsystem, comprising one or more magnetic tape drives, comprising a VMEGate channel processor for receiving CCW tape commands, a SCSI card for controlling SCSI optical disk drives, a serial I / O card for controlling optical disk jukebox media handlers for automatically loading and unloading optical disks with virtual tape data into the optical disk drives, a cache RAM for buffering data between the channel and the optical disk drives, control consoles for emulating the control panels of the 3480 magnetic tape subsystem, an SBC computer and a VME bus for centrally controlling the system, and floppy disk and hard disk drives for storing SBC emulation programs and disk directories to enable the system to organize virtual tape data in a system of pointers and user records of the virtual tapes,enabling a remappable mapping between magnetic tape drives and optical disk drives, disk directories with cross-references from virtual tape VSNs to optical disks for locating specific optical disks with requested VSNs, and the ability to make WORM optical media appear to the channel as a rewritable magnetic tape by converting tape commands into jukebox loads and optical drive seeks to improve performance.

[0008] US 5 953 174 A describes a magnetic tape drive with a write circuit for writing data onto a magnetic tape, a read circuit for reading the data written onto the magnetic tape, a cassette loading circuit for controlling a loading operation in which a magnetic tape cassette inserted into the drive is moved into a position in which the hub of the cassette is rotatable, and for controlling an unloading operation which is opposite to the loading operation, and a tape threading circuit for controlling a threading operation in which the magnetic tape is pulled out of the inserted cassette and then wound around a machine reel, and for controlling an unthreading operation which is opposite to the threading operation.

[0009] US 4 024 505 A describes a system by which an indefinite number of peripheral devices can be connected to a central processing unit (CPU) via a single socket. A cable connected to an interface unit (IU) of a first device is plugged into the CPU socket. Cables from subsequent IUs are plugged into sockets connected to previously plugged IUs. This connects the cables of all devices in series and the device IUs themselves in parallel. One type of IU is for a magnetic tape cartridge and includes a time-out circuit to determine when certain types of programming errors have occurred. For this and other error types, a binary digit is set in a status register. The status register is read under the program control of the CPU, thus providing the flexibility to halt operation or to bypass the faulty program section for unattended operation of the CPU.

[0010] US 2004 / 0 120 066 A1 describes a recording medium cartridge comprising a recording medium and a cartridge memory, which records a first CRC code generated from data of the recording medium in a non-rewritable state in the cartridge memory. A recording / reproducing device for recording / reproducing the recording medium cartridge is equipped with a CRC code generating device, a CRC code recording device, a CRC code comparing device, and an authentication determining device. The comparing device compares a fourth CRC code generated from the data recorded in the recording medium with the first CRC code corresponding to the data recorded in the cartridge memory. The authentication determining means determines the authentication of the data recorded in the recording medium based on a comparison result of the comparing means. Short description

[0011] A non-transitory, machine-readable storage medium according to claims 1 to 10, a controller according to claims 11 to 14, 17 and 18 and a method according to claims 15, 16 and 19 are disclosed. Brief description of the drawings

[0012] Some implementations of the present disclosure are described with reference to the following figures. Fig. is a block diagram of an arrangement with a memory library according to some examples. Fig. is a message flow diagram of a process according to some examples. Fig. is a block diagram of a storage medium that stores machine-readable instructions according to some examples. Fig. is a block diagram of a computer according to some examples. Fig. is a flowchart of a process according to some examples.

[0013] In the drawings, identical reference numbers indicate similar, but not necessarily identical, elements. The illustrations are not necessarily to scale, and the size of some parts may be exaggerated to better illustrate the example shown. Furthermore, the drawings provide examples and / or implementations consistent with the description; however, the description is not limited to the examples and / or implementations shown in the drawings. Detailed description

[0014] In this disclosure, the use of the term "a," "an," or "the" includes the plural forms unless the context clearly indicates otherwise. Likewise, the term "includes," "including," "comprises," "having," or "with," when used in this disclosure, specifies the presence of the specified elements but does not preclude the presence or addition of other elements.

[0015] A "tape library" can refer to a physical structure that can accommodate multiple tape cartridges. The tape cartridges can be physically stored in physical storage bays within the tape library. A physical storage bay is a receptacle or chamber into which a tape cartridge can be inserted and removed.

[0016] The tape library may also include a tape cartridge transport device (or multiple tape transport devices) and a tape drive (or multiple tape drives). A tape cartridge transport device may include a robot, a tape cartridge picker, a tape cartridge gripper, a tape cartridge carriage, or any other type of mechanism for transporting a tape cartridge. The tape cartridge transport device may physically transport a tape cartridge from a physical storage bay to a tape drive and vice versa.

[0017] A tape drive contains a motor for rotating a reel of a tape cartridge loaded into the tape drive. The rotation of the tape cartridge reel causes a tape to wind or unwind within the tape cartridge, causing the tape to move within the tape cartridge or into or out of the tape cartridge. The tape drive also contains a tape head with read and write elements for reading and writing data from a tape of the tape cartridge.

[0018] A tape library can receive commands from a user or a computing device to transport a tape cartridge from a storage slot and load the tape cartridge into a tape drive. The commands received by the tape library are processed by machine-readable instructions stored on machine-readable storage media and executed by a processing resource of the tape library.

[0019] A tape cartridge can be loaded into or unloaded from a tape drive. When a tape cartridge is loaded into a tape drive, a remote initiator (a user, a computer device, or another entity) can read and write to the tape in the tape cartridge. A remote initiator refers to an entity that is separate from the tape library but that may be able to access the tape library over a communications medium such as a wired network, a wireless network, or another type of communications medium.

[0020] In some examples, the tape cartridges in a tape library are used to store backup data of a host system. The host system for which the tape cartridges are to store backup data may include one or more computing devices. "Backup data" refers to data based on primary data in the host system, where the backup data may refer to a copy of the primary data or any other data calculated based on the primary data from which the primary data can be restored if the primary data is lost or corrupted for any reason. In other examples, tape cartridges in a tape library may be used to store archived data or other types of data.

[0021] A malware attack may attempt to remove or corrupt primary data stored on a host system. Furthermore, the malware attack may also attempt to remove or corrupt data stored on a backup system, such as a tape library. An example of such a malware attack is a ransomware attack, in which an unauthorized entity (such as a user, program, or machine) encrypts the data on a host system as well as on a backup storage system, such as a tape library. Encrypting the data on the host system and the tape library may use an encryption key. Without the encryption key, the encrypted data is unrecoverable by users of the host system.

[0022] Although some examples refer to a tape library, it should be understood that techniques or mechanisms according to some implementations of the present disclosure may be applied to other types of storage systems or storage pools that include storage cartridges that can be transported to storage drives for reading, writing, and initialization. "Transporting" a storage cartridge in a storage system refers to physically moving the storage cartridge between different physical locations in the storage system. An example of another type of storage system is a disk-based storage system or a solid-state storage system, in which a storage cartridge includes a disk-based storage cartridge or a solid-state drive (SSD), respectively. A disk-based storage cartridge stores data on a rotatable medium, such as a magnetic medium or an optical medium.An SSD contains integrated memory circuitry for storing data. A mechanism can be provided to define what is write-protected. For example, the mechanism can identify a specific memory cartridge or group of memory cartridges to be protected based on the memory cartridge's identifier(s).

[0023] According to some implementations of the present disclosure, a storage controller (e.g., a storage controller within a storage system or a storage controller external to the storage system) checks whether a storage cartridge within the storage system is connected to an indicator that was set during a configuration process (e.g., by an administrator using a management interface of the storage system to indicate that write protection is enabled for the storage cartridge). For example, in a storage library, such as a tape library, the storage controller may comprise a library controller.

[0024] As used herein, a "controller" may refer to hardware processing circuitry, which may include any one or a combination of a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or other hardware processing circuitry. Alternatively, a "controller" may refer to a combination of hardware processing circuitry and machine-readable instructions (software and / or firmware) executable on the hardware processing circuitry.

[0025] Note that the storage controller is not part of a host system that can request read and write operations from storage cartridges in the storage system. Also note that the "indicator set during a configuration operation" refers to an electronically set indicator (e.g., an indicator set in electronic memory during the configuration process), as opposed to a physical switch or tab on the storage cartridge that can be physically moved into position by a human to indicate write protection.

[0026] In response to detecting that the memory cartridge is connected to the display, the controller triggers write protection for the memory cartridge to prevent data from being written to the memory cartridge if the memory cartridge contains previously written data (e.g., an amount of data that exceeds a specified threshold, where the specified threshold can be zero or non-zero). Write protection provides protection against various types of write operations, such as a write operation that records data to the memory cartridge (as new data or to replace previously written data), a data erase operation (to delete the data stored on the memory cartridge), a cartridge reformat operation, a metadata write operation, such asa file mark, certain changes to the contents in a cassette memory of the storage cartridge (the cassette memory is separate from the main storage medium, such as the tape, the storage cartridge), and so on. Example of memory layout

[0027] Fig. is a block diagram of an example arrangement including a storage library 102 (e.g., a tape library or other type of storage library) accessible by a host system 104 (or one of multiple host systems 104). Communication between the host systems 104 and the storage library 102 may occur over a network 103, such as a local area network (LAN), a wide area network (WAN), a storage area network (SAN), the Internet, etc. The network 103 may include a wired network and / or a wireless network.

[0028] A host system 104 includes one (or more) computing devices capable of making requests to access data stored in storage cartridges of the storage library 102. For example, a host system 104 may access data in storage cartridges of the storage library 102 as part of a data backup operation in which primary data stored by the host system 104 (or another system) is copied to the storage library 102 for storage in one (or more) storage cartridges.

[0029] A host system 104 may also access data in the storage cartridge(s) of the storage library 102 by reading the data from the storage cartridge(s), for example, during a rebuild operation in which the data stored on the storage cartridge(s) is copied back to the host system 104 or another system. The rebuild operation may be used to restore corrupted or missing primary data.

[0030] In other examples, access to data stored in the storage cartridge(s) of the storage library 102 may be part of other types of operations by the host system(s) 104.

[0031] In the example of Fig. The memory cartridges are divided into multiple partitions 1 to N (where N ≥ 2). In other examples, the memory cartridges in the memory library 102 are not divided into multiple partitions. A "partition" refers to a subset of memory cartridges in the memory library 102 that are either physically or logically separated from another subset of memory cartridges in the memory library 102. The memory cartridges in the different partitions may be accessed by different host systems, or may be used to store different types of data, or for any other purpose.

[0032] In the example of Fig. The memory cartridges 106-1 are removably mounted in the physical memory slots (or more simply "memory slots") 108-1 of partition 1. Similarly, the memory cartridges 106-N are removably mounted in the memory slots 108-N of partition N.

[0033] Note that a storage cartridge 106-i (i = 1 to N) may be removed from a corresponding storage slot 108-i to be transported by a transport device 110 to another location in the storage library 102, e.g., to a storage drive 112-i in partition i or to another storage slot in partition i. Each partition i may contain a single storage drive 112-i or multiple storage drives.

[0034] Although in Fig. While only one transport device 110 is shown, in other examples, the storage library 102 may include multiple transport devices. A "transport device" may refer to any mechanism that can physically transport a storage cartridge between different locations within the storage library 102. Examples of transport devices include pickers, robots, grippers, carts, and so on.

[0035] In examples according to Fig. The storage library 102 includes a storage interface 114 and a management interface 116 separate from the storage interface 114. The storage interface 114 is used to communicate data and control information between the storage library 102 and a host system 104. The data communicated via the storage interface 114 includes write data transferred from a host system 104 to the storage library 102 for storage in a storage cartridge or read data retrieved from a storage cartridge and transferred to a host system 104.

[0036] Control information that may be communicated via storage interface 114 may include commands received from a host system 104 to perform a data access operation within storage library 102, such as a storage cartridge transport operation, a write operation, or a read operation. Additionally, the commands may include commands for determining a status of storage library 102 (or a portion of storage library 102).

[0037] In some examples, the storage interface 114 is a Small Computer System Interface (SCSI) through which the storage library 102 is capable of receiving SCSI commands from a host system 104 and through which write or read data is exchanged.

[0038] In other examples, the storage interface 114 includes a NON-VOLATILE MEMORY EXPRESS (NVMe™) interface over which NVMe™ commands and data can be exchanged.

[0039] In further examples, the storage interface 114 may conform to another protocol, whether standardized, proprietary, or open source.

[0040] The management interface 116 of the storage library 102 is separate from the storage interface 114 and provides a separate communication path between an external entity and the storage library 102. An "external entity" is an entity (e.g., a program, a machine, a human, etc.) that is external to the storage library 102. The external entity may include, for example, a host system 104, an administrator system 105 (e.g., a computer system connected to an administrator for the storage library 102), etc.

[0041] The management interface 116 is used to perform various management tasks related to the storage library 102, including configuring the storage library 102, monitoring the storage library 102, and so on. An example of the management interface 116 is a Representational State Transfer (REST) ​​application programming interface (API), which can be used to provide web services (referred to as RESTful web services). A REST API supports various routines (also referred to as methods) and rules that define how an external entity should interact with the storage library 102 via the management interface 116.

[0042] In further examples, the storage library 102 may also include an administrator interface 117, which in some examples may be referred to as a remote management interface (RMI). The administrator interface 117 may be in the form of a dedicated website that authorized individuals (e.g., an administrator using the administrator system 105) may access to perform configurations of the storage library 102. When the website presented by the administrator interface 117 is accessed from a system such as the administrator system 105, a web-based user interface may be presented at the administrator system 105, e.g., in a web browser. An administrator may use the web-based user interface to perform management tasks related to the storage library 102.

[0043] Although referred to as the "administrator interface," the administrator interface 117 can be considered a management interface, just in a different form than the management interface 116. Either the administrator interface 117 or the management interface 116 can be used to initiate a configuration operation in the storage library 102.

[0044] The storage library 102 also includes a write-protect controller 118 according to some implementations of the present disclosure. The write-protect controller 118 is used to set an indicator (e.g., one of 124-1 to 124-N) that controls whether or not write protection should be provided for a storage cartridge.

[0045] Memory library 102 includes memory 122, which may be implemented with one or more memory devices. A memory device may include dynamic random access memory (DRAM), static random access memory (SRAM), flash memory, or another type of memory device.

[0046] Memory 122 can store information, including indicia 124-1 through 124-N associated with partitions 1 through N, respectively. Indicia 124-1 through 124-N are write protection indicators (WPIs) set by write protection controller 118 during a configuration process of storage library 102. The configuration process can be initiated by administrator system 105 or by another system.

[0047] In the examples according to Fig. The WPI 124-1 is connected to Partition 1, so that all memory cartridges 106-1 in Partition 1 are read-only memory cartridges. Similarly, the WPI 124-N is assigned to Partition N, so that all memory cartridges 106-N in Partition N are read-only memory cartridges.

[0048] A “write-protected memory cartridge” refers to a memory cartridge that is write-protected such that a storage drive is configured by the storage library 102 to prevent writing to the memory cartridge when the memory cartridge stores previously written data.

[0049] In other examples, instead of assigning WPIs to the respective partitions in the storage library 102, WPIs may be assigned to individual storage cartridges (i.e., one WPI per individual storage cartridge) or may be assigned to another subset of storage cartridges.

[0050] A WPI can refer to any type of indicator (in the form of a flag, a variable, a parameter, or other information element) that can be set to one of several different values ​​(e.g., "0" and "1"). A WPI corresponds to setting the indicator to a first value. If the indicator is set to a second value that differs from the first value, then the WPI is not set for the corresponding memory cartridge, partition, or other subset of memory cartridges.

[0051] The storage library 102 also includes a library controller 115 that controls operations within the storage library 102. In some examples, the library controller 115 may process various commands received via the storage interface 114, and the library controller 115 performs appropriate actions in response to the commands. For example, the library controller 115 may command the transport device 110 to transport a storage cartridge 106-i from a storage slot 108-i to a storage drive 112 and cause the storage cartridge 106-i to be loaded into the storage drive 112. As another example, the library controller 115 may cause a storage cartridge 106-i to be unloaded from a storage drive 112 and transported to a storage slot 108-i.

[0052] In examples where the write-protect controller 118 is separate from the library controller 115, the write-protect controller 118 and the library controller 115 may communicate with each other via a communication link 119.

[0053] In other examples, the write protection controller 118 may be part of the library controller 115.

[0054] Fig. is a flowchart of a process that occurs between the different Fig. shown units. In some examples, an administrator or other user at the administrator system 105 may initiate a configuration process to configure write protection in the storage library 102. For example, a user interface may be presented by the administrator system 105, which user interface may be used by the user at the administrator system 105 to initiate the write protection configuration process. In some examples, the write protection configuration process may be performed via the administrator interface 117 of the storage library 102 ( Fig. ).

[0055] As an example, the user can log in to the storage library 102 via the administrator interface 117 on the administrator system 105. The user can submit user credentials (e.g., an administrator login) to successfully log in to the administrator interface. After successfully logging in, the user can initiate a write-protect configuration process.

[0056] Although reference is made to a human initiating the configuration of the write-protect mode, in other examples, a program or machine may initiate the configuration of the write-protect mode, provided the program and machine have the appropriate permission and can be authenticated.

[0057] Although some examples refer to the administrator system 105 initiating the write-protect mode configuration, in other examples, a different system may be used to initiate the write-protect configuration of the storage library 102.

[0058] The administrator system 105 sends (at 202) an indication to configure a write-protect mode to the administrator interface 117 of the storage library 102. The indication to configure the write-protect mode may indicate that write-protect mode should be enabled for a partition, a single storage cartridge, or another subset of storage cartridges. In some cases, the indication to configure the write-protect mode may indicate that write-protect mode should be enabled for multiple partitions.

[0059] The write-protection mode configuration indication may be in the form of a message, information item, or other type of information indicating that write-protection mode configuration is requested. The write-protection mode configuration indication is received by the write-protection controller 118 in the storage library 102 via the administrator interface 117.

[0060] In response to the indication to configure the write protection mode, the write protection controller 118 sets (at 204) a WPI (e.g., one of the WPIs 124-1 to 124-N in Fig. ). The set WPI can be for a partition, a single memory cartridge, or another subset of memory cartridges. The set WPI is stored in a memory (e.g., 122 in Fig. ) of the memory library 102.

[0061] At a later time, a host system 104 sends (at 206) a move command (e.g., a SCSI MOVE COMMAND, an NVMe™ command to move a storage cartridge, etc.) to the storage library 102, which is received by the library controller 115 in the storage library 102. The move command is intended to request a transport of a storage cartridge 106 from a storage slot in the storage library 102 to a storage drive 112. The storage drive 112 of Fig. is one of the Fig. shown storage drives 112-1 to 112-N.

[0062] In response to the move command, library controller 115 checks (at 208) whether the WPI is set for storage cartridge 106. Note that the WPI may be individually linked to storage cartridge 106, linked to a partition to which storage cartridge 106 belongs, or linked to another subset of storage cartridges.

[0063] Library controller 115 may access the WPI in memory 122 to check whether the WPI is set. In examples where write-protect controller 118 is separate from library controller 115 in storage library 102, library controller 115 may communicate with write-protect controller 118 to retrieve the WPI from memory 122.

[0064] In some examples, in response to determining that the WPI is set, the library controller 115 causes the partial loading (at 214) of the storage cartridge 106 into the storage drive 112. In such examples, the storage cartridge 106 may have a partially loaded position and a fully loaded position. In the partially loaded position, a reader in the storage drive 112 is capable of reading a cartridge memory 210 that is part of the storage cartridge 106. The cartridge memory 210, in some examples, may be a radio frequency identification (RFID) chip. The information stored in memory of the RFID chip may be wirelessly read by an RFID reader. In other examples, the cartridge memory 210 may be implemented with a different type of storage device.

[0065] The cartridge memory 210 is separate from a main storage medium 212 (e.g., a tape storage medium) of the storage cartridge 106. The main storage medium 212 is used to store data that is written in response to write commands from the host system 104.

[0066] In some examples, cartridge memory 210 may store written data information, which may indicate an amount of data previously written to a main storage medium 212 of storage cartridge 106. The reader of storage cartridge 106 may read the written data, which is then sent (at 216) to library controller 115. In further examples, the written data information may be read when storage cartridge 106 is located outside of storage drive 112, which is possible in examples where cartridge memory 210 is located within an RFID chip.

[0067] In other examples, the written data may be stored in a specific section of the main storage medium 212 instead of the cartridge memory 210, which may be an area of ​​the main storage medium 212 used to store metadata for the main storage medium 212. In such examples, the storage cartridge 214 would be fully loaded into the storage drive 112 to read the written data from the designated section of the main storage medium 212. The storage drive 112 would not permit any write operations to the storage cartridge 214 unless explicitly permitted.

[0068] In response to receiving the data that was written (received at 216), the library controller 115 determines (at 218) whether the amount of previously written data stored in the memory cartridge 106 exceeds a certain threshold value (which may be a zero value or a non-zero value).

[0069] If the WPI for the memory cartridge 106 is set and the amount of previously written data in the memory cartridge 106 is greater than or equal to the specified threshold, then the library controller 118 determines that the write protection should be set for the memory cartridge 106. Conversely, if either the WPI is not set or the amount of previously written data in the memory cartridge 106 is less than the threshold, then the library controller 115 determines that the write protection should not be set for the memory cartridge 106 and instead proceeds with the normal transport process of loading the memory cartridge 106 without setting the write protection for the memory cartridge 106.

[0070] In response to determining (at 218) that the amount of previously written data stored in the storage cartridge 106 exceeds a certain threshold, the library controller 115 sends (at 222) configuration information to the storage drive 112. The configuration information may include an indication that the write-protect mode has been triggered in response to the library controller 115 determining that write protection should be triggered. Alternatively, the configuration information may include an indication that write protection should not be triggered in response to the library controller 115 determining that write protection for the storage cartridge 106 should not be triggered.

[0071] In examples where the storage cartridge 106 is partially loaded into the storage drive 106 to read the cartridge memory 210, the library controller 115 causes the storage cartridge 106 to be fully loaded (at 224) into the storage drive 106.

[0072] After complete loading, if the configuration information indicates that write protection is triggered, the storage drive 112 prevents (at 226) data from being written to the storage cartridge 106 in response to a write command received from the host system 104. The write command may be a command to record data to the storage cartridge 106, an erase command to erase data from the storage cartridge, a reformat command to reformat the storage cartridge, a metadata write command to write metadata (e.g., a file mark) to the storage cartridge, a command to modify certain contents of the cartridge memory 210, etc. Thus, preventing data from being written to the storage cartridge 106 may include preventing any type of modification of the data of the storage cartridge 106 in response to any of the possible types of write commands mentioned above.However, if the configuration information indicates that the write protection has not been triggered, then the storage drive 112 allows (at 226) the write operation requested by the write command to continue writing data to the storage cartridge 106.

[0073] In some examples, as described above, setting the WPI (at 204) involves writing a value by the write protection controller 118 to the memory 122 of the memory library 102 ( Fig. ).

[0074] In other examples, instead of or in addition to writing the value to memory 122 of storage library 102 to set the WPI, write protection controller 118 may write a value to a memory (e.g., cartridge memory 210 or the designated portion of main storage medium 212) of storage cartridge 106 to indicate that write protection for the storage cartridge should be enabled.

[0075] In some examples, the write-protection indicator written to the memory (e.g., 210 or 212) of the storage cartridge 106 may be accessible to the host system 104. As a result, the host system 104 may be able to erase or modify the write-protection indicator written to the memory of the storage cartridge 106. In such examples, the write-protection controller 118 may implement a technique to protect the write-protection indication written to the memory of the storage cartridge 106. For example, the write-protection controller 118 may read the write-protection indication from the memory of the storage cartridge 106 when the storage cartridge 106 is initially loaded into the storage drive 112, write a corresponding write-protection indication to a memory (e.g., 122) of the storage library 102, and check the write-protection indication in the memory of the storage cartridge 106 when the storage cartridge 106 is unloaded.If the write-protection indicator in the memory of the storage cartridge 106 does not match the write-protection indicator stored in the memory of the storage library 102, the write-protection controller 118 may rewrite the write-protection indicator to the memory of the storage cartridge 106. Another example of protecting the write-protection indication is that the write-protection set for the storage drive 112 also applies to the portion of the memory of the storage cartridge 106 in which the write-protection indication is stored.

[0076] In other examples, other protection mechanisms may be used to protect the write-protect indicator in the memory of the memory cartridge 106 from unauthorized access or modification.

[0077] Fig. is a block diagram of a non-transitory machine-readable or computer-readable storage medium 300 on which machine-readable instructions are stored that, when executed, direct a controller (e.g., 115 and / or 118 in Fig. ) (which is for a storage system separate from a host system) to perform various tasks.

[0078] The machine-readable instructions may include instructions for checking the write protection indicator 302 to verify whether a memory cartridge in the storage system (e.g., the storage library 102 of Fig. ) is associated with an indication (e.g., the WPI discussed above) that was set in an electronic memory (e.g., memory 122 of storage library 102) during a configuration operation in the storage system to indicate that write protection for the memory cartridge is enabled.

[0079] In some examples, the configuration process responds to access by an entity (e.g., the administrator system 105 in Fig. ) via a management interface (e.g. the administrator interface 117 in Fig. ) of the storage system. The management interface is separated from a storage interface (e.g. 114 in Fig. ) of the storage system.

[0080] The machine-readable instructions may further include instructions 304 for triggering write protection for the memory cartridge in response to determining that the memory cartridge is connected to the display, to prevent data from being written to the memory cartridge if the memory cartridge contains previously written data.

[0081] In some examples, the controller loads the additional storage cartridge into a storage drive and allows data to be written to the additional storage cartridge if the additional storage cartridge does not store more than a specified amount (zero or more) of data. In some examples, the controller receives information from the storage drive indicating that the additional storage cartridge does not store more than the specified amount of data.

[0082] In some examples, the controller disables a write-protect mode for the memory cartridge during a write operation to write the previously written data to the memory cartridge. This allows the write operation (e.g., a backup operation, an archive operation, etc.) to continue with respect to the memory cartridge. After the write operation is complete, the controller enables the write-protect mode in response to the memory cartridge being unloaded from a storage drive in the storage system for more than a specified period of time. If the memory cartridge is unloaded from the storage drive for more than the specified period of time, an indication is provided that writing of data to the memory cartridge is complete and the memory cartridge has been moved to a storage bay for safekeeping.

[0083] In other examples, the memory cartridge is unloaded from the storage drive but then reloaded into the storage drive before the specified time period has elapsed. In such examples, the write-protect mode is not set by the controller. This can be used in a scenario where additional data is to be appended to data already written to the memory cartridge (e.g., to continue a backup). When the host system detects that the write operation is complete (e.g., the backup operation is complete), the host system does not request that the memory cartridge be returned to the storage drive, allowing the specified time period to expire and the write-protect mode to be set.

[0084] In some examples, after triggering write protection for the memory cartridge, the controller disables the write protection after a specified period of time (for example, six months or another period of time). The expiration of the specified period might correspond, for example, to a data retention policy of a company or other entity. The data retention policy might specify that the company's or other entity's data must be retained for the specified period of time, after which the data can be deleted. The write protection can be disabled after a specified period of time so that the memory cartridge can be used for a subsequent write operation.

[0085] Fig. 4 is a block diagram of a controller 400 according to some examples. The controller 400 includes a processor 402 (or multiple processors). A processor may include a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or other hardware processing circuitry.

[0086] The controller 400 also includes a storage medium 404 that stores machine-readable instructions executable on the processor 402 to perform various tasks. Machine-readable instructions executable on a processor may refer to instructions executable on a single processor or to instructions executable on multiple processors.

[0087] The machine-readable instructions in storage medium 404 include write-protect mode checking instructions 406 to check whether a write-protect mode is active for a storage cartridge in a storage system.

[0088] The machine-readable instructions also include data amount determination instructions 408 and write protection activation instructions 410 that are executed in response to determining that the write protection mode is active for the memory cartridge.

[0089] The data amount determination instructions 408 determine whether a particular amount of data (e.g., greater than zero or some other threshold) is stored in the memory cartridge.

[0090] In response to determining that the specified amount of data is stored in the memory cartridge, the write protection enable instructions 410 configure a storage drive to enable write protection to prevent data from being written to the memory cartridge.

[0091] In some examples, the machine-readable instructions read information in a memory (e.g., cartridge memory or a specific portion of the main storage medium) of the storage cartridge to determine whether the specified amount of data has been previously written to the storage cartridge.

[0092] Fig. is a flowchart of a process 500 according to some implementations of the present disclosure. Process 500 may be performed, for example, by write-protect controller 118.

[0093] Process 500 includes checking (at 502) whether a write-protect mode is active for a storage cartridge in a storage system.

[0094] Process 500 performs the following tasks in response to determining that the write-protect mode is active for the memory cartridge. Process 500 receives (504) information from a storage drive, wherein the information is read by the storage drive from a memory of the memory cartridge.

[0095] Process 500 determines (at 506) based on the information whether a particular amount of data is stored in the storage cartridge. In response to determining that the specified amount of data is stored in the storage cartridge, process 500 configures (at 508) the storage drive to enable write protection to prevent data from being written to the storage cartridge. In response to determining that the specified amount of data is not stored on the storage cartridge, process 500 permits (at 510) the storage drive to write data to the storage cartridge.

[0096] A storage medium (e.g., 300 in Fig. in Fig.) may include any one or a combination of the following elements: a semiconductor memory device, such as dynamic or static random access memory (DRAM or SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory or other type of non-volatile memory device; a magnetic disk, such as a hard disk, a floppy disk, and a removable disk; other magnetic medium, including tape; an optical medium, such as a compact disk (CD) or digital video disk (DVD); or another type of storage device.Note that the instructions discussed above may be provided on a single computer- or machine-readable storage medium, or alternatively, on multiple computer- or machine-readable storage media distributed throughout a large system with possibly multiple nodes. Such computer- or machine-readable storage medium or media are considered part of an article (or article of manufacture). An article or article of manufacture may refer to each individual component or components manufactured. The storage medium or media may be located either in the machine in which the machine-readable instructions are executed or at a remote location from which machine-readable instructions may be downloaded over a network for execution.

[0097] In the foregoing description, numerous details are set forth to provide an understanding of the subject matter disclosed herein. However, implementations may be made without some of these details. Other implementations may include modifications and variations of the details described above. The appended claims are intended to cover such modifications and variations.

Claims

[1] A non-transitory, machine-readable storage medium (300) comprising instructions that, when executed, cause a controller for a storage system separate from a host system (104) to: to check whether a memory cartridge in the storage system is assigned to an indicator set in an electronic memory of the storage system during a configuration process in the storage system for a partition of the storage system to indicate that write protection is activated for a plurality of memory cartridges (106) mounted in the partition, wherein the plurality of memory cartridges (106) comprises the memory cartridge, the electronic memory of the memory system is separate from the memory cartridge, and wherein checking comprises reading an indication from the electronic memory of the memory system by the controller; and in response to a determination based on reading the indication from the electronic memory of the storage system that write protection for the plurality of memory cartridges (106) is enabled, enabling write protection for the plurality of memory cartridges (106) in the partition, including triggering write protection for the memory cartridge to prevent data from being written to the memory cartridge if the memory cartridge contains previously written data. [2] The non-transitory, machine-readable storage medium (300) of claim 1, wherein the configuration process responds to access by an entity via a management interface (116) of the storage system, the management interface (116) being separate from a second interface of the storage system, the second interface being for communication with the host system (104). [3] The non-transitory machine-readable storage medium (300) of claim 1, wherein the instructions, when executed, cause the controller to: loading a further memory cartridge of the plurality of memory cartridges (106) mounted in the partition into a storage drive (112), wherein the write protection for the further memory cartridge is activated based on the display set in the electronic memory; and to enable data to be written to the additional memory cartridge if the additional memory cartridge does not store more than a certain amount of data. [4] The non-transitory machine-readable storage medium (300) of claim 3, wherein the instructions, when executed, cause the controller to: receive information from the storage drive (112) indicating that the further storage cartridge does not store more than the specified amount of data, wherein enabling writing of data to the further storage cartridge is based on the information and comprises configuring the storage drive (112) to disable write protection for the further storage cartridge. [5] The non-transitory machine-readable storage medium (300) of claim 1, wherein the instructions, when executed, cause the controller to: receive a command to transport the memory cartridge from a memory slot (108-1 - 108-N) in the storage system to a storage drive (112) in the storage system, wherein reading of the display from the electronic memory separate from the memory cartridge is performed in response to the transport command. [6] The non-transitory, machine-readable storage medium (300) of claim 1, wherein the instructions, when executed, cause the controller to: in response to detecting the display set in the electronic memory, cause a partial loading of the memory cartridge in a storage drive (112); while the memory cartridge is partially loaded into the storage drive (112), reading information in a cartridge memory (210) of the memory cartridge; to determine, based on the information read from the cartridge memory (210), whether an amount of data stored in the memory cartridge exceeds a threshold value; and in response to determining, based on the information read from the cartridge memory (210) while the storage cartridge is partially loaded into the storage drive (112), that the amount of data stored in the storage cartridge exceeds the threshold, triggering write protection for the storage cartridge. [7] The non-transitory machine-readable storage medium (300) of claim 1, wherein the instructions, when executed, cause the controller to: deactivate a write-protect mode for the memory cartridge during a write operation for writing the previously written data to the memory cartridge when the memory cartridge is loaded into a storage drive (112) in the storage system; and activate the write-protect mode in response to the memory cartridge being unloaded from the storage drive (112) for more than a predetermined period of time. [8] The non-transitory machine-readable storage medium (300) of claim 1, wherein the instructions, when executed, cause the controller to: to determine a presence of the previously written data in the memory cartridge based on reading information in a memory of the memory cartridge, wherein the triggering of the write protection is based on the information indicating the presence of previously written data in the memory cartridge. [9] The non-transitory machine-readable storage medium (300) of claim 1, wherein the instructions, when executed, cause the controller to: write a value to a memory location on the memory cartridge, where the value indicates that the memory cartridge is write-protected. [10] The non-transitory, machine-readable storage medium (300) of claim 1, wherein the instructions, when executed, cause the controller to: After the write protection for the memory cartridge has been triggered, the write protection is deactivated after a specified period of time. [11] A controller for a storage system separate from a host system (104), comprising: a processor; and a non-transitory storage medium that stores instructions executable on the processor to: Checking whether a memory cartridge in the storage system is associated with an indicator set in an electronic memory of the storage system during a configuration process in the storage system for a partition of the storage system to indicate that write protection is enabled for a plurality of memory cartridges (106) mounted in the partition, wherein the plurality of memory cartridges (106) includes the memory cartridge, the electronic memory of the storage system is separate from the memory cartridge, and wherein the checking comprises reading an indicator from the electronic memory of the storage system by the controller; and in response to a determination, based on reading the indication from the electronic memory of the storage system, that write protection for the plurality of memory cartridges (106) is enabled, enabling write protection for the plurality of memory cartridges in the partition, including triggering write protection for the memory cartridge to prevent data from being written to the memory cartridge if the memory cartridge contains previously written data. [12] The controller of claim 11, wherein the instructions are executable on the processor to: Reading information in a memory of the memory cartridge to determine (408) an amount of data previously written to the memory cartridge; and Triggering (410) the write protection for the memory cartridge based on a comparison of the determined data amount with a threshold data amount. [13] The controller of claim 11, wherein the instructions are executable on the processor to: in response to determining that write protection is enabled for another memory cartridge of the plurality of memory cartridges (106) and determining that no threshold amount of data is stored in the memory cartridge, permitting writing of data to the memory cartridge. [14] The controller of claim 11, wherein the instructions are executable on the processor to: loading another memory cartridge of the plurality of memory cartridges (106) in the partition into a storage drive (112); and Enabling writing of data to the additional storage cartridge in response to determining that write protection is enabled for the plurality of storage cartridges (106) in the partition and the additional storage cartridge does not store more than a threshold amount of data. [15] A method of a controller for a storage system separate from a host system (104), comprising: Checking by the controller whether a memory cartridge in the storage system is associated with an indicator set in an electronic memory of the storage system during a configuration process in the storage system for a partition of the storage system to indicate that write protection is enabled for a plurality of memory cartridges (106) mounted in the partition, wherein the plurality of memory cartridges (106) includes the memory cartridge, the electronic memory of the storage system is separate from the memory cartridge, and wherein the checking comprises reading an indicator from the electronic memory of the storage system by the controller; and in response to a determination, based on reading the indication from the electronic memory of the storage system, that write protection for the plurality of memory cartridges (106) is enabled, enabling write protection for the plurality of memory cartridges (106) in the partition by the controller, including triggering write protection for the memory cartridge to prevent data from being written to the memory cartridge if the memory cartridge already contains previously written data. [16] The method of claim 15, further comprising: loading another memory cartridge of the plurality of memory cartridges (106) in the partition into a storage drive (112); and Enabling writing of data to the additional storage cartridge in response to determining that write protection is enabled for the plurality of storage cartridges (106) in the partition and the additional storage cartridge does not store more than a threshold amount of data. [17] The controller of claim 11, wherein the instructions are executable on the processor to: Receiving a command to transport the memory cartridge from a memory slot (108-1 - 108-N) in the storage system to a storage drive (112) in the storage system, wherein the reading of the display from the electronic memory separate from the memory cartridge occurs in response to the transport command. [18] The controller of claim 11, wherein the instructions are executable on the processor to: in response to detecting the display set in the electronic memory, causing a partial loading of the memory cartridge into a storage drive (112); while the memory cartridge is partially loaded into the storage drive (112), reading information in a cartridge memory (210) of the memory cartridge; Determining, based on the information read from the cartridge memory (210), whether an amount of data stored in the memory cartridge exceeds a threshold amount of data; and in response to determining, based on the information read from the cartridge memory while the storage cartridge is partially loaded into the storage drive (112), that the amount of data stored in the storage cartridge exceeds the threshold data amount, triggering write protection for the storage cartridge. [19] A method according to claim 15, comprising: Receiving, by the controller, a command to transport the memory cartridge from a memory slot (108-1 - 108-N) in the storage system to a storage drive (112) in the storage system, wherein reading the indication from the electronic memory separate from the memory cartridge occurs in response to the transport command.

Citation Information

Patent Citations

  • Recording medium cartridge and recording / reproducing apparatus therefor

    US20040120066A1

  • Encryption moniker in medium auxiliary memory

    US20100031054A1

  • Data storage drive overwrite protection of non-worm cartridges

    US20110051278A1

  • Write once read many (WORM) drive for security or large storage needs

    US20190347020A1

  • Interface system for coupling an indeterminate number of peripheral devices to a central processing unit

    US4024505A