Device-Capability-Based Locking Key Management for Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional locking key management systems in information handling systems face challenges in managing different locking key policies for various storage devices with unique capabilities, such as RAID controllers and NVDIMMs, leading to inefficiencies in securing and accessing data.
Innovation Solution
A device-capability-based locking key management system that identifies and creates key management sub-clients for each storage device, allowing for customized key management profiles to communicate with a key management system, ensuring appropriate locking key policies are applied based on device capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single locking key management system is used for all storage devices, then system simplicity is maintained, but it cannot accommodate different locking key policies required by diverse storage devices with unique capabilities
Solution Approach 1:
The key management system is segmented into multiple key management sub-clients, each responsible for specific storage devices with particular capabilities. Each sub-client implements locking key policies tailored to its assigned devices, allowing the system to handle diverse storage device requirements without requiring a completely different approach for each device type.
Solution Approach 2:
Different key management policies are applied locally to different storage devices based on their specific capabilities. Rather than using a uniform policy across all devices, the system configures appropriate locking key management approaches for each device type (e.g., RAID controllers, NVDIMMs, HBAs), ensuring each device receives the specific treatment it requires.
2Reliability
If device-specific key management policies are implemented for each storage device, then data security is enhanced, but system complexity increases
Solution Approach 1:
The system divides key management responsibilities into separate sub-clients, each handling specific device types with their own security policies. This segmentation allows comprehensive security coverage for each device type while distributing the complexity across multiple manageable components rather than one monolithic complex system.
Solution Approach 2:
The key management system is designed with multi-functionality to handle various storage device types through a unified architecture. The system can universally manage different device types (RAID, NVDIMM, HBA, etc.) by dynamically selecting and applying appropriate key management policies, thus providing both security and ease of management.
3Adaptability or versatility
If conventional locking key management is used, then ease of operation is maintained, but it fails to meet unique requirements of different storage devices
Solution Approach 1:
The key management system provides a universal interface that automatically adapts to different storage device types. Users interact with a single system that handles various device types through appropriate sub-clients, maintaining ease of operation while accommodating device-specific requirements through automated policy selection and application.
Solution Approach 2:
The key management system automatically identifies storage device types and selects appropriate key management policies without requiring manual configuration for each device. The system self-configures by detecting device capabilities and applying the correct locking key management approach, reducing operational complexity while meeting device-specific needs.
Data Source
AI summary
A device-capability-based locking key management system includes a key management system coupled to a server device via a network. The server device includes storage devices coupled to a remote access controller device. The remote access controller device identifies each of the storage devices, and then identifies a key management profile for each of the storage devices. A first key management profile identified for at least one first storage device is different from a second key management profile identified for at least one second storage device. The remote access controller device then uses the respective key management profile identified for each of the storage devices to create a respective key management sub-client for each of the storage devices, and each respective key management sub-client communicates with the key management system to provide a locking key for its respective storage device.


