Cloud Manager Security Verification for Storage Controllers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, customers face challenges in ensuring the integrity and confidentiality of their data due to unauthorized access and tampering of storage controllers, which can compromise the quality of service and lack of remote verification capabilities.

Innovation Solution

A method and system that provides security as a service in cloud storage environments by using a cloud manager to store and manage security levels of access for storage controllers, enabling customers to access and verify the authenticity of these controllers through secure microcontrollers and authentication protocols, and generating invoices based on requested security services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If role-based access control is implemented to structure security permissions, then security management becomes more organized, but unauthorized users can still access customer data on storage controllers

Engineering Contradiction:
Improvesecurity management structureVSAvoidunauthorized data access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud manager as an intermediary component that sits between customers and storage controllers. The cloud manager receives security information from storage controllers and selectively provides it to customers based on their authorization levels. This intermediary mechanism enables customers to verify storage controller integrity without granting them direct access to the controllers, thus resolving the contradiction between structured security management and preventing unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If customers are given direct access to verify storage controller integrity, then verification capability is improved, but system security and controller stability are compromised

Engineering Contradiction:
Improveverification capabilityVSAvoidsystem security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements a copying mechanism where the cloud manager creates and provides copies of security information (such as cryptographic signatures, hash values, and verification data) from storage controllers to customers. Instead of giving customers direct access to the actual storage controllers, they receive replicated security metadata that enables verification without compromising the original system's security or stability.

Inventive Principle:
Principle #26Copying

3Loss of information

If comprehensive security information is provided to all customers, then transparency and trust are improved, but system complexity and access control difficulty increase

Engineering Contradiction:
Improveinformation transparencyVSAvoidaccess control management
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies local quality by providing different levels and types of security information to different customers based on their specific authorization levels and needs. The cloud manager selectively filters and customizes security information delivery, ensuring each customer receives appropriate transparency without overwhelming the system with uniform comprehensive access controls for all users.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8676710B2Providing security in a cloud storage environment
Publication Date: 2014.03.18 NETAPP INC
  • US8676710B2 patent drawing
  • US8676710B2 patent drawing
  • US8676710B2 patent drawing

AI summary

A method of providing security as a service in a cloud storage environment includes storing, through a cloud manager of the cloud storage environment, a security level of access of a storage controller associated with a customer of the security as a service, and receiving a request from the customer to access security information of the storage controller associated therewith. The method also includes providing, through the cloud manager, security information of the storage controller associated with the customer in accordance with the request and the stored security level of access of the storage controller associated with the customer.