Backward Attestation Module for Distributed Data Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed data storage systems face operational complexity, initialization delays, and security risks due to the scaling of multiple data storage devices, which jeopardize data access performance and integrity.

Innovation Solution

Implementing a backward attestation module that verifies the authenticity of data storage devices and network controllers sequentially, disconnecting them from the network to ensure secure initialization and prevent third-party attacks without degrading system performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If multiple data storage devices are scaled to provide large volumes of data storage, then data capacity and access speed are improved, but operational complexity and security risks increase

Engineering Contradiction:
Improvedata capacityVSAvoidoperational complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The system segments the distributed storage network into discrete compute devices and storage devices, each with assigned roles. Compute devices are excluded from data encryption/decryption operations, while storage devices perform these operations locally. This segmentation reduces operational complexity by distributing security functions to appropriate components rather than requiring complex coordination across all devices.

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If multiple data storage devices are scaled to provide large volumes of data storage, then data capacity and access speed are improved, but security risks and initialization delays increase

Engineering Contradiction:
Improvedata capacityVSAvoidsecurity risks
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system performs preliminary security evaluations and authenticity verifications during the initialization phase, before devices begin processing data access requests. The attestation module verifies the authenticity of storage devices and network controllers during initialization, ensuring security credentials are validated in advance. This preliminary action prevents security risks during operational data access while maintaining the benefits of device scaling.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security evaluations are conducted on data storage devices and network controllers, then system security and data integrity are improved, but initialization time and processing delays increase

Engineering Contradiction:
Improvesystem securityVSAvoidinitialization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security evaluations and authenticity verifications are conducted during the initialization phase of the distributed storage network, before devices begin processing data access requests. The attestation module performs these security checks in advance, ensuring that security credentials are validated beforehand. This preliminary action allows the system to maintain high security standards while minimizing delays during operational data access, as the security verification overhead is incurred only during initialization rather than with each data operation.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If data storage devices are connected to the distributed data storage network, then data access functionality is improved, but vulnerability to third-party attacks increases

Engineering Contradiction:
Improvedata access functionalityVSAvoidthird-party attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by conducting authenticity verifications and security evaluations through the attestation module before devices are fully integrated into the network for data access operations. This preliminary verification establishes security credentials and authenticates devices in advance, creating a defensive barrier against third-party attacks. The network controller is verified as authentic before allowing it to mediate data access requests, preventing unauthorized or compromised devices from gaining network access.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11698975B2Distributed data storage system with backward attestation
Publication Date: 2023.07.11 SEAGATE TECH LLC
  • US11698975B2 patent drawing
  • US11698975B2 patent drawing
  • US11698975B2 patent drawing

AI summary

A distributed data storage system can have an attestation module that is connected to the data storage device to disconnect the device from a distributed data storage network or prevent the data storage device from being initialized into the distributed data storage network. A first security evaluation of the data storage device can be conducted with the attestation module to verify an authenticity of the data storage device. The attestation module may then disconnect the network controller from the distributed data storage network and verify an authenticity of the network controller to allow the network controller and data storage device to service a data access request from a host of the distributed data storage network.