Cloud-Based NAS Access Management via Local Code

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network-attached storage (NAS) systems face challenges in managing access between clients and NAS devices on local networks, particularly in simplifying the connection process without requiring users to provide authentication credentials or determine the NAS device's IP address, and in centralizing access management.

Innovation Solution

A cloud-based access management system generates and verifies a local code for NAS devices, allowing clients to connect securely without needing to know the NAS device's IP address, using a cloud service to manage authentication and authorization, thereby simplifying the connection process and ensuring only authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a cloud-based access management system is implemented, then access management is centralized and simplified, but system complexity increases

Engineering Contradiction:
Improveconnection processVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

A cloud-based access management system acts as an intermediary between clients and NAS devices. The cloud service generates and verifies local codes, managing authentication and authorization centrally. This mediator simplifies the connection process for users while handling the complexity of access management remotely, resolving the contradiction between ease of operation and system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If manual authentication credentials are required, then security is maintained, but ease of operation decreases

Engineering Contradiction:
Improveconnection processVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Authentication credentials and local codes are pre-configured and stored in the cloud-based access management system before clients need to connect to NAS devices. When a client needs access, the cloud service automatically provides the pre-prepared local code without requiring manual authentication. This preliminary setup maintains security while dramatically simplifying the connection process for users.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If NAS devices store access permissions locally, then access control is maintained, but device complexity and infrastructure burden increase

Engineering Contradiction:
ImproveNAS device infrastructureVSAvoidaccess control
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The access permission management functionality is extracted from individual NAS devices and centralized in the cloud-based access management system. The cloud service stores and manages all access permissions, authentication credentials, and local codes. NAS devices no longer need to store or manage access control data locally, reducing their infrastructure burden while maintaining reliable access control through the centralized cloud system.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10560528B2Cloud-based management of access to a data storage system on a local network
Publication Date: 2020.02.11 SANDISK TECHNOLOGIES LLC
  • US10560528B2 patent drawing
  • US10560528B2 patent drawing
  • US10560528B2 patent drawing

AI summary

Systems and methods are disclosed for managing access between a data storage server and a client that are on the same local network. Access is managed using a cloud service that is remote from both the data storage server and the client requesting access to the server. The cloud-based management of local connections described herein simplifies the process of connecting to a data storage server on a local network from a client program or device. Connections are authorized based on the use of a local code. The local code is generated by the cloud service and includes a concatenation of a device identifier associated with the data storage server and a time-varying value, such as a timestamp.