Chip-Based Security for I/O Packets in Storage Arrays

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security approaches for Storage Area Networks (SAN) are inadequate in preventing unauthorized access, data modification, and denial of service attacks, as they rely on password mechanisms, Access Control Lists, Public Key Infrastructures, and LUN masking, which can lead to data loss and inappropriate resource usage.

Innovation Solution

Implementing a chip-based security system that uses dynamic secret keys for encrypting I/O packets, authenticating users through a non-volatile memory, and converting secret keys into private keys for secure access, preventing unauthorized access and data breaches, and providing an additional security layer during disaster recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password mechanisms are used for SAN management access, then ease of operation is improved, but security reliability deteriorates due to unauthorized access risks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based password authentication mechanisms with hardware-based security processing circuits embedded in storage array controllers. This substitution moves security functionality from the software layer to dedicated hardware, providing cryptographic operations and authentication verification that are resistant to software attacks and cannot be easily compromised.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces security processing circuits as an intermediary layer between the host system and storage array. This intermediary performs authentication verification of I/O packets using embedded authentication information, blocking unauthorized access before it reaches the storage resources while allowing legitimate operations to proceed normally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Access Control Lists are implemented to control host access, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts authentication verification functionality from the main storage array controller logic and places it in dedicated security processing circuits. These separate circuits contain embedded authentication information and handle verification independently, simplifying the main controller while providing robust security through specialized hardware components.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If encryption engines are used to scramble data, then security reliability is improved, but use of energy and computational resources increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiduse of energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs authentication verification of I/O packets at the earliest possible point in the data path, before data reaches the storage array. The security processing circuits verify authentication information in embedded hardware, blocking unauthorized packets immediately without requiring full decryption or processing of data contents, thereby reducing overall energy consumption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8677461B2Method to provide chip based security for I/O packets in an array using dynamic topology
Publication Date: 2014.03.18 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8677461B2 patent drawing
  • US8677461B2 patent drawing
  • US8677461B2 patent drawing

AI summary

An apparatus comprising a controller circuit and an array. The controller circuit may be configured to read/write data in response to one or more input/output requests. The array may be configured to present/receive data to/from the controller circuit in response to the input/output requests. The data may be only transmitted to/from the array after a successful authentication between (i) a first code embedded within each of the input/output requests and (ii) a second code stored on a non-volatile memory within the controller circuit.