Cache Data Protection Directives for Storage Controller Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber resiliency measures for enterprise data lack effective techniques to detect and prevent malicious and unauthorized access, particularly in storage systems, leading to potential data compromise and propagation of threats.
Innovation Solution
A system and method for generating data protection directives that are incorporated into storage controller metadata to manage access to cache data, enabling the storage controller to identify and respond to potentially malicious access requests, thereby preventing data corruption and unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data protection directives are embedded in storage controller metadata to control access to cache data, then data security against malicious attacks is improved, but system complexity increases
Solution Approach 1:
The patent segments data protection functionality into discrete directives that are embedded in metadata for different data subsets. Each directive contains specific access control rules that can be independently applied to different portions of cached data, allowing granular security control without requiring system-wide complexity increases.
Solution Approach 2:
The patent introduces data protection directives as an intermediary layer between the storage controller and cached data. These directives act as metadata that mediate access requests by providing rule-based control, enabling security enforcement without requiring complex integration into the core storage controller architecture.
2Reliability
If data protection directives are implemented in storage controller metadata, then detection and response to malicious access is improved, but processing overhead increases
Solution Approach 1:
The patent implements preliminary action by pre-establishing data protection directives in metadata before malicious access attempts occur. These directives contain pre-defined rules for detecting and responding to various types of access requests, allowing the storage controller to quickly evaluate access requests against predetermined criteria rather than performing complex analysis in real-time.
Solution Approach 2:
The patent changes parameters by representing security rules in a standardized directive format with specific fields for access request types and protective actions. This parameterized approach allows efficient storage and quick retrieval of protection rules, reducing processing overhead compared to unstructured security policies.
3Reliability
If comprehensive data protection directives are applied to all data subsets, then security coverage is improved, but performance impact increases
Solution Approach 1:
The patent applies local quality by allowing data protection directives to be selectively applied to specific data subsets rather than uniformly to all cached data. Different portions of cached data can have different protection levels and access control rules, enabling comprehensive security coverage where needed while maintaining optimal performance for data that requires less stringent protection.
Data Source
AI summary
Provided are a computer program product, system, and method for generating data protection directives to provide to a storage controller to control access to data in cache. A data protection directive is generated for a data subset indicating access request type and a protective action with respect to the access request type for the data subset. The data protection directive is transmitted to the storage controller. The storage controller includes the data protection directive in metadata for the data subset. The data protection directive causes the storage controller to perform the protective action in response to an access request of the access request type to a portion of the data subset.


