Asymmetric Storage Volume Data Encryption Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies for managing asymmetric storage volumes, which include a combination of storage devices with and without device-based encryption, fail to ensure that all data is encrypted, leading to potential plaintext storage on devices without encryption capabilities, compromising security.

Innovation Solution

A storage control module (SCM) is implemented to identify and relocate data from storage devices without encryption to those with encryption capabilities, ensuring that all data is encrypted and securely stored, while also obfuscating or erasing data from non-encrypted devices to maintain security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If storage devices without device-based encryption are aggregated into the array, then storage capacity and performance are improved, but data security deteriorates due to plaintext storage

Engineering Contradiction:
Improvestorage capacityVSAvoiddata security
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary encryption layer at the host software level that mediates between the storage devices and the data. This software-based encryption mechanism bridges the gap by providing encryption capabilities to the entire array, including devices without native encryption support, thus maintaining security while allowing diverse device aggregation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal encryption approach where the host software provides encryption functionality across all storage devices in the array, regardless of their native capabilities. This multi-functional solution allows both encrypted and non-encrypted devices to be managed uniformly under a single encryption framework

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If storage devices with different features are aggregated, then adaptability and versatility are improved, but device complexity increases due to managing heterogeneous features

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The storage control module implements a universal interface and management mechanism that works across all storage devices regardless of their specific features. This allows heterogeneous devices to be managed through a common control plane, reducing the complexity of managing diverse storage devices with different capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If software-based encryption is implemented across the array, then data security is improved, but processing speed deteriorates due to software encryption overhead

Engineering Contradiction:
Improvedata securityVSAvoidprocessing speed
Core Design Contradiction:
Object-affected harmful factorsVSSpeed

Solution Approach 1:

The patent implements preliminary encryption where data is encrypted before being written to storage devices without native encryption capabilities. The host software performs encryption in advance during the write operation, ensuring security is established beforehand rather than adding decryption overhead during read operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates encrypted copies of data and stores them on devices without native encryption support. The host software generates encrypted versions of the data and writes these copies to the appropriate devices, allowing the original data to remain on devices with encryption capabilities while maintaining security on non-encrypted devices

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10540505B2Technologies for protecting data in an asymmetric storage volume
Publication Date: 2020.01.21 SK HYNIX NAND PRODUCT SOLUTIONS CORP
  • US10540505B2 patent drawing
  • US10540505B2 patent drawing
  • US10540505B2 patent drawing

AI summary

Technologies for protecting data in an asymmetric volume (ASV) that includes a first storage device that supports device-based encryption and a second storage device that does not support device-based encryption. In embodiments the technologies enable disparate capabilities of the storage devices in an ASV to be exposed to a user. When a complete copy of targeted data identified by a user input for encrypted storage is not present on the first storage device, at least a portion of the targeted data stored on the second storage device is rewritten to the first storage device. When a complete copy of the targeted data is stored on the first storage device, one or more security operations are performed to obfuscate or erase any portion of the targeted data stored on the second storage device.