Authorization Management Unit for Secure I/O Command Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing devices lack effective mechanisms to prevent unauthorized access to information storage devices, particularly over networks, which can lead to data destruction or theft.

Innovation Solution

A computing device that determines the necessity of authorization information for I/O requests, acquires and inserts authorization information into storage control commands, and communicates with an external server to verify access permissions, ensuring secure storage operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authorization information is manually managed by applications, then flexibility and ease of operation are maintained, but security against unauthorized access is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authorization information management unit as an intermediary component between applications and storage devices. This unit automatically acquires, manages, and inserts authorization information into I/O commands, preventing unauthorized access while relieving applications of the burden of manual authorization management. The intermediary handles the complexity of security protocols centrally, maintaining both security and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authorization information management unit operates autonomously to acquire authorization information from servers, manage it in memory, and insert it into I/O commands without requiring application intervention. The system performs self-service by automatically determining when authorization is needed, managing the authorization lifecycle, and ensuring security compliance without external manual management.

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional access control methods are used, then system simplicity is maintained, but they are insufficient for preventing unauthorized network access to storage devices

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidoperation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by acquiring authorization information before executing I/O operations. The authorization information management unit proactively obtains authorization tokens from servers and stores them in memory in advance, so that when I/O commands are generated, the appropriate authorization information is already available and can be automatically inserted, ensuring secure access without complicating the operational flow.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If manual authorization management is implemented, then operational flexibility is maintained, but productivity is reduced due to additional management overhead

Engineering Contradiction:
Improvestorage operation efficiencyVSAvoidauthorization management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The authorization information management unit operates autonomously to acquire authorization information from servers, manage it in memory, and insert it into I/O commands without requiring application intervention. The system performs self-service by automatically determining when authorization is needed, managing the authorization lifecycle, and ensuring security compliance without external manual management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11899960B2Computing device and control method for transmitting I/O command to storage device
Publication Date: 2024.02.13 KIOXIA CORP
  • US11899960B2 patent drawing
  • US11899960B2 patent drawing
  • US11899960B2 patent drawing

AI summary

According to one embodiment, a computing device executes an application including processing of inputting information from a nonvolatile memory unit and outputting information to the nonvolatile memory unit. The computing device includes a processing unit. The processing unit executes processing of receiving an I/O request to the nonvolatile memory unit from the application and generating one or more control commands for controlling the nonvolatile memory unit based on the I/O request. The processing unit executes processing of acquiring authorization information from a server. The processing unit executes processing of inserting or associating the acquired authorization information into or with the I/O request or the one or more control commands.