Storage device and network storage system

The storage device with a file processing device that performs snapshot operations based on confidential signals addresses the issue of unreliable snapshot file creation for security folders, ensuring data integrity and security.

JP7673488B2Active Publication Date: 2025-05-09MURATA MASCH LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2021085980
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-05-21
Publication Date
2025-05-09
Estimated Expiration
2041-05-21

AI Technical Summary

Technical Problem

Existing storage devices fail to reliably create snapshot files for security folders at specific timings, as the snapshot function is only updated when files are visualized.

Method used

A storage device equipped with a file processing device that includes a confidential unit, a signal communication unit, and a snapshot unit. The snapshot unit performs snapshot operations based on confidential signals indicating visualization or invisibility of the confidential folder, ensuring snapshot files are created at relevant times.

Benefits of technology

This solution allows for reliable creation of snapshot files for security folders, ensuring data integrity and security by capturing folder states during visualization and invisibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007673488000001
    Figure 0007673488000001
  • Figure 0007673488000002
    Figure 0007673488000002
  • Figure 0007673488000003
    Figure 0007673488000003
Patent Text Reader

Abstract

To surely perform a snapshot of a concealed folder.SOLUTION: A storage device 110 comprises a storage device 111 for storing files, and a file processor 112 for processing the files. The file processor 112 comprises: a concealing unit 113 which processes a concealed folder being a folder which can be made visible / invisible; a signal communication unit 114 which acquires a concealment-related signal indicating visibility / invisibility; and a snapshot unit 115 which, in response to acquisition of the concealment-related signal, performs a snapshot operation for generating a snapshot file in the concealed folder corresponding to the concealment-related signal.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a storage device including a storage device that stores files grouped as folders, and a file processing device that processes the files and folders on the storage device, and to a network storage system including the storage device. [Background technology]

[0002] Patent Document 1 discloses a security folder function in a network storage device (NAS (Network Attached Storage)) that creates a secret folder that can be made visible only to a user who has predetermined key data.

[0003] Patent Document 2 discloses a technology for creating a snapshot of a folder at a specific timing. A snapshot records the entire image of a target at a specific timing. This makes it easy to understand the state to be restored if a failure occurs after the snapshot, and is effective for restoring data. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2019-121306 A [Patent Document 2] JP 2007-249380 A Summary of the Invention [Problem to be solved by the invention]

[0005] However, since the function of the security folder is to update a file only when the file is made visible, there are cases where a snapshot of the security folder is not taken at a specific time.

[0006] The present invention has been made in consideration of the above-mentioned problems, and has an object to provide a storage device and a network storage system that can reliably create snapshot files even when a security folder function is provided. [Means for solving the problem]

[0007] In order to achieve the above-mentioned object, a storage device according to one aspect of the present invention is a storage device comprising: a storage device that stores files grouped as a folder; and a file processing device that processes the files and the folders on the storage device, wherein the file processing device comprises: a concealment unit that processes a concealment folder, which is a folder that can be made visible and invisible; a signal communication unit that acquires a concealment-related signal indicating either the visualization of the concealment folder or the invisibility of the concealment folder; and a snapshot unit that, when the signal communication unit acquires at least one of a concealment-related signal indicating the visualization and a concealment-related signal indicating the invisibility, executes a snapshot operation to create a snapshot file in the concealment folder corresponding to the concealment-related signal.

[0008] In order to achieve the above-mentioned object, another network storage system of the present invention is a network storage system including a storage device that stores files grouped as a folder, and a file processing device that processes the files and the folder on the storage device, and a terminal device connected to the storage device via a network, wherein the file processing device includes a concealment unit that processes a concealment folder, which is a folder that can be made visible and invisible, a signal communication unit that acquires a concealment-related signal indicating either the visualization of the concealment folder or the invisibility of the concealment folder, and a snapshot unit that, when the signal communication unit acquires at least one of a concealment-related signal indicating the visualization and a concealment-related signal indicating the invisibility, executes a snapshot operation to create a snapshot file in the concealment folder corresponding to the concealment-related signal, and the terminal device includes a signal transmission unit that transmits the concealment-related signal. Effect of the Invention

[0009] By executing a snapshot operation at least one of the times when the hidden folder is made visible and when it is made invisible, it is possible to reliably create a snapshot file of the hidden folder. [Brief description of the drawings]

[0010] [Figure 1] FIG. 1 illustrates a network storage system. [Diagram 2] FIG. 2 is a block diagram showing the functional configuration of the storage apparatus. [Diagram 3] FIG. 4 is a sequence diagram showing the operation of the network storage system. [Figure 4] FIG. 11 is a diagram showing an example of a displayed menu. [Diagram 5] FIG. 11 is a block diagram showing another example of a storage device. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0011] Hereinafter, an embodiment of a storage device and a network storage system according to the present invention will be described with reference to the drawings. Note that the following embodiment is an example for explaining the present invention, and is not intended to limit the present invention. For example, the shapes, structures, materials, components, relative positional relationships, connection states, numerical values, mathematical expressions, contents of each step in the method, and the order of each step shown in the following embodiment are examples, and may include contents not described below. In addition, geometric expressions such as parallel and orthogonal may be used, but these expressions do not indicate mathematical strictness, and include errors, deviations, etc. that are substantially acceptable. In addition, expressions such as simultaneous and identical also include a substantially acceptable range.

[0012] In addition, the drawings are schematic diagrams in which emphasis, omissions, or ratios have been appropriately adjusted in order to explain the present invention, and the shapes, positional relationships, and ratios are different from the actual ones.

[0013] In addition, in the following, a plurality of inventions may be collectively described as one embodiment, and some of the contents described below are described as optional components related to the present invention.

[0014] 1 is a diagram showing a network storage system. The network storage system 100 comprises a storage device 110 connected to a network 200, and a terminal device 150. In this embodiment, the network storage system 100 is a system in which a plurality of terminal devices are connected to the network 200, and a case in which one of the plurality of terminal devices, the terminal device 150, accesses the storage device 110 will be described.

[0015] The type of network 200 is not particularly limited, and in this embodiment, a wired LAN (Local Area Network) that performs communication based on a private IP address (local IP address) is exemplified as the network. Specifically, network 200 is a network that complies with IEEE (The Institute of Electrical and Electronics Engineers) 802.3. Note that network 200 is not limited to this, and may be a wireless network, a network that combines wireless and wired networks, etc. Furthermore, network 200 may be a WAN (Wide Area Network) provided by a communication carrier that allows communication based on a global IP address, the so-called Internet, etc., or a network that combines a WAN and a LAN.

[0016] 2 is a block diagram showing the functional configuration of a storage device. Storage device 110 is a device that can store data as files managed by a file system and store files by grouping them into folders (sometimes called directories), and includes a storage device 111 and a file processing device 112. In this embodiment, storage device 110 is a so-called network storage device (NAS (Network Attached Storage)) that can store files received via network 200 and transmit the stored files via the network.

[0017] The storage device 111 is a device that can store files in a non-volatile manner and can freely read out the stored files, and examples of the storage device 111 include a hard disk drive (HDD) and a solid state drive (SSD).

[0018] The file processing device 112 is a device that controls writing, reading, erasing, etc. of files to the storage device 111. In the case of this embodiment, the file processing device 112 realizes a function of obtaining a file via the network 200 and transmitting the file via the network 200 by using a PHY chip or the like. The file processing device 112 includes a processor, and realizes a so-called file system by having the processor execute a program. The file processing device 112 further includes a concealment unit 113, a signal communication unit 114, and a snapshot unit 115 as processing units realized by having the processor execute a program.

[0019] The concealment unit 113 processes a concealment folder, which is a folder stored in the storage device 111 and can be made visible or invisible. A concealment folder in an invisible state is a folder that cannot be accessed by processing using a normal file system. The method of creating a concealment folder is not particularly limited, but in the case of the present embodiment, the concealment unit 113 makes the concealment folder invisible by successively changing the path of the concealment folder, and makes the concealment folder visible by notifying the changed path when a predetermined condition is satisfied. In addition, examples of the method of making a folder visible or invisible include a method of adding a predetermined symbol to the folder name, and a method of setting a rule in the file system that a predetermined folder name is a concealment folder.

[0020] In this embodiment, the path means a network path that indicates the location of the resource on the network. The path of the secret folder includes the share name of the folder. For example, the network path is determined based on the Universal Naming Convention (UNC).

[0021] The concealment unit 113 makes the secret folder visible or invisible according to the contents of the concealment-related signal indicating either the visualization of the secret folder or the invisibility of the secret folder. For example, when the concealment-related signal includes key data and the key data matches the key data associated with the secret folder, the concealment unit 113 makes the secret folder visible by notifying the terminal device 150 of the path of the secret folder. Also, when the concealment-related signal includes information indicating invisibility, the concealment unit 113 makes the secret folder invisible by changing the path of the secret folder. In the case of this embodiment, when the signal communication unit 114 acquires a concealment-related signal indicating visualization, the concealment unit 113 changes the path of the corresponding secret folder and transmits the changed path to the terminal device 150 that transmitted the concealment-related signal, thereby attempting visualization.

[0022] When a plurality of secret folders are stored in the storage device 111, a key database in which secret folders are associated with key data is stored in the storage device 111. When a secret-related signal is received, the key data is acquired from the secret-related signal, and when a secret folder corresponding to the key data exists in the key database, the corresponding secret folder may be visualized by notifying the terminal device 150 that transmitted the secret-related signal of the path to the secret folder. When secret folders are common folders, a plurality of different key data may be associated with one secret folder in the key database.

[0023] When the signal communication unit 114 acquires at least one of a confidentiality-related signal indicating visualization and a confidentiality-related signal indicating invisibility, the snapshot unit 115 executes a snapshot operation for creating a snapshot file in a confidential folder corresponding to the confidentiality-related signal. The snapshot operation is an operation for creating, as a snapshot file, a file including a difference between a file in a confidential folder when a snapshot operation is performed and a file in the confidential folder when a snapshot operation was performed previously on the same confidential folder. The snapshot unit 115 saves the created snapshot file in the storage device 111.

[0024] In the present embodiment, the snapshot unit 115 executes the snapshot operation in both cases where the confidentiality-related signal indicates visualization and where the confidentiality-related signal indicates invisibility. This makes it possible to create an appropriate snapshot file even if no snapshot file was created during the previous invisibility.

[0025] The snapshot unit 115 stores the created snapshot file in a secret folder that is the target of the snapshot operation. As a result, if the secret folder in which the snapshot operation is performed is made invisible, the snapshot file is also made invisible, and security is maintained. The snapshot unit 115 may also give a read-only attribute to the snapshot file to be created. As a result, it is possible to prevent the snapshot file from being unintentionally altered. The snapshot unit 115 may also create an individual folder corresponding to the snapshot file created in the secret folder in which the snapshot operation is performed, and store the snapshot file in the individual folder. The creation date and time of the snapshot file can be set as the individual folder name, which makes it possible to easily manage the snapshot file. Furthermore, a dedicated folder for storing the snapshot file in the secret folder may be created, and the snapshot file or the snapshot file stored in the individual folder may be stored in the dedicated folder.

[0026] When the signal communication unit 114 performs a snapshot operation by acquiring a concealment-related signal indicating invisibility, the snapshot unit 115 performs the snapshot operation and stores a snapshot file after the concealment unit 113 makes the corresponding concealment folder invisible. As a result, for the user who sent the concealment-related signal indicating invisibility, the operation related to the snapshot is performed in the background, which contributes to improving user convenience.

[0027] Note that, when a snapshot operation is executed and no difference exists, a snapshot file indicating that no difference exists may be created, but in the case of this embodiment, when no difference exists, the snapshot unit 115 does not create a snapshot file. This eliminates the need to store unnecessary files, and facilitates management of snapshot files.

[0028] The terminal device 150 is a device connected to the storage device 110 via a network. The terminal device 150 includes a signal transmission unit 151 as a processing unit realized by causing a processor to execute a program. The type of the terminal device 150 is not particularly limited, and examples of the terminal device 150 include a desktop computer, a laptop computer, a smartphone, and a tablet terminal. The terminal device 150 and the storage device 110 may be connected via a wireless LAN or the like, or may be directly connected via a USB (Universal Serial Bus) or the like.

[0029] The signal transmission unit 151 transmits a confidentiality-related signal. Specifically, based on information input by a user of the terminal device 150 via an interface, the signal transmission unit 151 transmits a confidentiality-related signal indicating visualization and a confidentiality-related signal indicating invisibility to the storage device 110. A specific method of transmitting the confidentiality-related signal will be described later.

[0030] Next, an example of the operation of the network storage system 100 will be described. Fig. 3 is a sequence diagram showing the operation of the network storage system. As a premise, the secret folder is in an invisible state (S1). In addition, the user performs user authentication to the storage device 110 using the terminal device 150, and folders, files, etc. other than the secret folder are accessible according to the login authority.

[0031] Based on a menu (see FIG. 4) displayed on the display device by causing the processor of the terminal device 150 to execute a program, the user selects, for example, visualization of the confidential folder 1 (S2). The above user operation causes the signal transmission unit 151 of the terminal device 150 to transmit a confidentiality-related signal indicating visualization to the storage device 110 (S3). Note that the signal transmission unit 151 may also transmit the confidentiality-related signal by displaying a dialogue on the display device of the terminal device 150 and having the user input key data, a password, etc. into the dialogue.

[0032] Here, it is assumed that when the terminal device 150 creates a secret folder in advance in the storage device 110, the user inputs key data corresponding to the secret folder, and a key database in which the secret folder and the key data are associated with each other is stored in the storage device 111. A similar key database is also stored in the terminal device 150, and the signal transmission unit 151 of the terminal device 150 can transmit a secret-related signal including the corresponding key data simply by the user specifying the secret folder that the user wishes to view.

[0033] Next, the concealment unit 113 that has acquired the concealment-related signal indicating visualization changes the path of the corresponding concealment folder (S4). The snapshot unit 115 executes a snapshot operation, and if there is a difference, creates a snapshot file and stores it in the concealment folder (S5).

[0034] Next, the concealment unit 113 transmits the changed path of the concealed folder to the terminal device 150 via the signal communication unit 114 (S6). The terminal device 150 that has acquired the path can view the concealed folder (S7: visualization). For example, the concealed folder can be viewed by applying the acquired path to a file explorer that is included in the OS (operating system) of the terminal device 150. Then, the files in the concealed folder can be operated based on a normal file system (S8).

[0035] When the file operation is completed, the user causes the terminal device 150 to display a menu (see FIG. 4) and selects invisibility (S9). The above user operation causes the signal transmission unit 151 of the terminal device 150 to transmit a confidentiality-related signal indicating invisibility to the storage device 110 (S10).

[0036] The concealment unit 113, which has received the concealment-related signal indicating that the folder is not made visible, changes the path of the made-visible concealment folder (S11). The snapshot unit 115 executes a snapshot operation, and if there is a difference, creates a snapshot file and stores it in the concealment folder after the path has been changed (S12).

[0037] According to the above network storage system 100, for a made-visible secret file, snapshot operations are executed after making it visible and after making it invisible, regardless of whether changes have been made to the folders in the secret file. This makes it possible to reliably create snapshot files for changes to files in a secret folder, and to perform fine-grained rollbacks as necessary.

[0038] The present invention is not limited to the above-described embodiment. For example, the components described in this specification may be combined in any manner, or some of the components may be removed to create another embodiment of the present invention. In addition, the present invention also includes modifications that are made to the above-described embodiment by those skilled in the art without departing from the spirit of the present invention, i.e., the meaning of the words in the claims.

[0039] For example, in the above embodiment, the storage device 110 and the terminal device 150 are connected to the network 200, but the storage device 110 is not limited to this. For example, as shown in FIG. 5, the storage device 110 may have the functions of the terminal device 150. In this case, the storage device 110 may be regarded as a computer. Specifically, the computer as the storage device 110 may include a storage device 111 and a processor, and may realize the concealment unit 113, the snapshot unit 115, the signal communication unit 114, and the signal transmission unit 151 by causing the processor to execute a program.

[0040] Also, the hidden folder may be made visible or invisible using a method other than changing the path. For example, the hidden folder may be made visible or invisible using the file system specifications of the OS used, or the hidden folder may be made visible or invisible by encrypting the file.

[0041] Furthermore, when the storage device 110 and the terminal device 150 are connected to a network, the path indicating the secret folder may include the IP address of the terminal device 150 that transmitted the secret-related signal indicating visualization. This makes it impossible for other terminal devices to view the visualized secret folder even if they use the notified path.

[0042] Also, a confidentiality-related signal indicating invisibility may be transmitted to the storage device 110 in conjunction with logout, sleep, etc. of the terminal device 150. This can increase the security of the confidential folder.

[0043] Although the network is a LAN in the above description, the network is not limited to this. The network may be any computer network, such as a WAN (Wide Area Network) or the Internet.

[0044] The storage device 110 may also be a multi-function peripheral, a router, a file server, or the like. [Explanation of symbols]

[0045] 100 Network Storage System 110 Storage device 111 Storage device 112 File Processing Device 113 Confidential Department 114 Signal and Communication Department 115 Snapshot section 150 Terminal Equipment 151 Signal transmitter 200 Network

Claims

1. A storage device comprising: a storage device that stores files grouped as folders; and a file processing device that processes the files and the folders on the storage device, The file processing device includes: a concealment unit for processing a concealment folder, which is a folder that can be made visible and invisible; a signal communication unit that acquires a confidentiality-related signal indicating either visualization of the confidential folder or invisibility of the confidential folder; a snapshot unit that, when the signal communication unit receives at least one of a confidentiality-related signal indicating visualization and a confidentiality-related signal indicating invisibility, executes a snapshot operation for creating a snapshot file in a confidentiality folder corresponding to the confidentiality-related signal. Storage device.

2. The snapshot unit includes: Performing a snapshot operation when the confidentiality-related signal indicates visibility and when the confidentiality-related signal indicates invisibility The storage device according to claim 1.

3. The snapshot unit includes: Store the snapshot file created in the hidden folder where the snapshot operation is performed. The storage device according to claim 1 or 2.

4. The snapshot unit includes: When the signal communication unit receives a confidentiality-related signal indicating invisibility, the confidentiality unit stores a snapshot file after invisibility of the corresponding confidential folder. The storage device according to claim 1 .

5. The snapshot unit includes: Give the snapshot file read-only attribute The storage device according to claim 1 .

6. The concealment unit is A key database in which secret folders and key data are associated with each other is obtained from the storage device, and it is determined whether or not the key data included in the secret-related signal matches the key data associated with the secret folder, and if they match, the secret folder corresponding to the key data is visualized. The storage device according to claim 1 .

7. The concealment unit is When the signal communication unit receives a confidentiality-related signal indicating visualization, the signal communication unit changes a path of the corresponding confidential folder, and transmits the changed path to the terminal device that transmitted the confidentiality-related signal. The storage device according to claim 1 .

8. A network storage system including a storage device including a storage device that stores files grouped as a folder, and a file processing device that processes the files and the folders on the storage device, and a terminal device connected to the storage device via a network, The file processing device includes: a concealment unit for processing a concealment folder, which is a folder that can be made visible and invisible; a signal communication unit that acquires a confidentiality-related signal indicating either visualization of the confidential folder or invisibility of the confidential folder; a snapshot unit that, when the signal communication unit receives at least one of a confidentiality-related signal indicating visualization and a confidentiality-related signal indicating invisibility, executes a snapshot operation for creating a snapshot file in a confidentiality folder corresponding to the confidentiality-related signal, The terminal device A signal transmitting unit for transmitting a confidentiality-related signal is provided. Network storage system.

Citation Information

Patent Citations

  • Information processor, snapshot preparation of setting content and management method

    JP2007249380A

  • Search index generation device and search index construction method and search index construction program

    JP2014032692A

  • Storage device, data sharing system, and data sharing method

    JP2019121306A