Application-Driven Compute in Programmable SSDs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based computing systems face limitations due to outdated hardware and firmware, which hinder the deployment of innovative software and expose data to unauthorized access, especially when dealing with data-intensive operations and security breaches.
Innovation Solution
A computing system with a compute controller and storage controller that operates in multiple modes, allowing for application-driven arbitrary compute within storage devices, including programmable SSDs with cryptographic components to perform operations on encrypted data without decrypting it, thus enhancing security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in clear text form for easy access and processing, then data processing speed and ease of operation are improved, but data security deteriorates due to unauthorized access risks
Solution Approach 1:
The patent introduces an encryption layer as an intermediary between the storage medium and the processing systems. Data is encrypted before storage and decrypted only when needed for processing, allowing clear text processing when needed while maintaining security during storage and transmission. The encryption/decryption mechanism acts as a mediator that enables both security and processing ease at different stages.
2Device complexity
If compute operations are performed outside storage devices in traditional cloud computing architecture, then device complexity is reduced, but productivity deteriorates due to data transfer latency and energy consumption
Solution Approach 1:
The patent merges compute operations with storage devices by integrating processing units directly into the SSD architecture. This allows data processing to occur at the storage location without requiring data to be transferred to external compute resources, thereby eliminating transfer latency and reducing energy consumption while maintaining manageable device complexity through modular integration.
3Stability of the object's composition
If hardware refresh cycles are extended to three to five years for SSDs and firmware, then loss of substance is reduced and stability is improved, but adaptability deteriorates as operators cannot deploy innovative software
Solution Approach 1:
The patent introduces dynamic programmability into storage devices through integrated compute units that can execute different software routines. While the underlying hardware remains stable over the three to five year refresh cycle, the system can dynamically load and execute updated software routines to provide new functionality, effectively decoupling hardware stability from software adaptability.
4Ease of operation
If data is decrypted for processing operations, then ease of operation is improved for data manipulation, but security deteriorates as unencrypted data becomes vulnerable to breaches
Solution Approach 1:
The encryption layer serves as a secure intermediary that allows data to be decrypted only within the controlled environment of the storage device for processing. The encrypted data remains protected during storage and transmission, while the decryption mechanism enables easy data manipulation when needed, with the understanding that data should not leave the secure storage environment in unencrypted form.
Data Source
AI summary
Systems and methods that allow secure application-driven arbitrary compute in storage devices in a cloud-based computing system are provided. A computing system including a compute controller configured to: (1) provide access to host compute resources, and (2) operate in at least one of a first mode or a second mode is provided. The computing system may further include a storage controller configured to provide access to storage systems including storage components, at least one compute component, and at least one cryptographic component. In the first mode, the host compute resources may be configured to execute at least a first operation on at least a first set of data stored in at least one of the storage components. In the second mode, the at least one compute component may be configured to execute at least a second operation on at least a second set of data.


