Chip-Based Security for I/O Packets in Storage Arrays
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security approaches for Storage Area Networks (SAN) are inadequate in preventing unauthorized access, data modification, and denial of service attacks, as they rely on password mechanisms, Access Control Lists, Public Key Infrastructures, and LUN masking, which can lead to data loss and inappropriate resource usage.
Innovation Solution
Implementing a chip-based security system that uses dynamic secret keys for encrypting I/O packets, authenticating users through a non-volatile memory, and converting secret keys into private keys for secure access, preventing unauthorized access and data breaches, and providing an additional security layer during disaster recovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If password mechanisms are used for SAN management access, then ease of operation is improved, but security reliability deteriorates due to unauthorized access risks
Solution Approach 1:
The patent replaces software-based password authentication mechanisms with hardware-based security processing circuits embedded in storage array controllers. This substitution moves security functionality from the software layer to dedicated hardware, providing cryptographic operations and authentication verification that are resistant to software attacks and cannot be easily compromised.
Solution Approach 2:
The patent introduces security processing circuits as an intermediary layer between the host system and storage array. This intermediary performs authentication verification of I/O packets using embedded authentication information, blocking unauthorized access before it reaches the storage resources while allowing legitimate operations to proceed normally.
2Reliability
If Access Control Lists are implemented to control host access, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent extracts authentication verification functionality from the main storage array controller logic and places it in dedicated security processing circuits. These separate circuits contain embedded authentication information and handle verification independently, simplifying the main controller while providing robust security through specialized hardware components.
3Reliability
If encryption engines are used to scramble data, then security reliability is improved, but use of energy and computational resources increases
Solution Approach 1:
The patent performs authentication verification of I/O packets at the earliest possible point in the data path, before data reaches the storage array. The security processing circuits verify authentication information in embedded hardware, blocking unauthorized packets immediately without requiring full decryption or processing of data contents, thereby reducing overall energy consumption.
Data Source
AI summary
An apparatus comprising a controller circuit and an array. The controller circuit may be configured to read/write data in response to one or more input/output requests. The array may be configured to present/receive data to/from the controller circuit in response to the input/output requests. The data may be only transmitted to/from the array after a successful authentication between (i) a first code embedded within each of the input/output requests and (ii) a second code stored on a non-volatile memory within the controller circuit.


