Secure Distributed RAID Storage via NAT and Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Secure storage of sensitive data is challenging due to the need for controlled and trusted physical locations, while also requiring economically advantageous storage solutions.
Innovation Solution
A method involving a RAID controller that determines how to store data across multiple drives, assigns non-routable IP addresses, and uses a NAT system to translate these addresses into routable ones for storage across geographically dispersed locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored in facilities controlled by data owners or within trusted secure physical locations, then security is improved, but storage cost increases and economic advantage is reduced
Solution Approach 1:
The patent segments data into multiple fragments and distributes them across multiple geographically dispersed storage locations. Each fragment is stored in a separate facility with its own security credentials, allowing the system to achieve secure distributed storage without requiring all data to be held in a single expensive secure facility. This segmentation enables cost-effective storage while maintaining security through cryptographic fragment distribution.
Solution Approach 2:
The patent introduces an access management system as an intermediary that coordinates between the RAID controller and NAT system. This intermediary manages security credentials, validates access requests, and ensures that fragmented data can only be reconstructed with proper authorization. The intermediary layer enables secure distributed storage by mediating access control across multiple locations without requiring direct trust between all parties.
2Adaptability or versatility
If data is distributed across multiple geographically dispersed storage locations, then storage flexibility and economic advantage are improved, but access control complexity increases
Solution Approach 1:
The access management system serves multiple functions: it manages security credentials for distributed storage locations, validates access requests from users, coordinates with the NAT system for network address translation, and maintains access logs. This multi-functional intermediary simplifies the overall system by consolidating access control logic in a single component rather than requiring complex distributed access control across all storage locations.
Solution Approach 2:
The system implements feedback mechanisms where the access management system continuously monitors access requests, validates credentials against stored security policies, and provides real-time authorization decisions. The NAT system also provides feedback by translating addresses bidirectionally, enabling the system to track and control data access flows. This feedback loop maintains access control integrity while enabling flexible distributed storage.
3Reliability
If non-routable IP addresses are used for storage drives on a local area network, then local network security is improved, but remote accessibility deteriorates
Solution Approach 1:
The NAT system acts as an intermediary between the internal LAN with non-routable IP addresses and the external WAN with routable IP addresses. It translates internal non-routable addresses to external routable addresses for outgoing data transmissions and translates incoming external requests to the appropriate internal addresses. This intermediary enables remote accessibility while preserving the security benefits of using non-routable IP addresses on the internal network.
Solution Approach 2:
Instead of making internal non-routable IP addresses directly accessible from the external network (which would compromise security), the system inverts the approach by having external users connect to a public-facing NAT gateway and then translating their requests inward to the appropriate non-routable addresses. This inversion maintains security by keeping internal addresses hidden while enabling external access through the translation layer.
Data Source
AI summary
Systems and methods for securely and remotely storing data in a remote, distributed redundant array of independent drives (RAID) is provided. RAID storage is accomplished through a series of mapped drives, non-routable Internet protocol (IP) addresses, and routable IP addresses. In addition, authorization to access a RAID controller, network address translation (NAT) system, and domain name system (DNS) system may all be separated, increasing security and allowing storage to be securely distributed among a variety of dispersed storage locations.


