Secure Distributed RAID Storage via NAT and Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure storage of sensitive data is challenging due to the need for controlled and trusted physical locations, while also requiring economically advantageous storage solutions.

Innovation Solution

A method involving a RAID controller that determines how to store data across multiple drives, assigns non-routable IP addresses, and uses a NAT system to translate these addresses into routable ones for storage across geographically dispersed locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored in facilities controlled by data owners or within trusted secure physical locations, then security is improved, but storage cost increases and economic advantage is reduced

Engineering Contradiction:
Improvedata securityVSAvoidstorage cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments data into multiple fragments and distributes them across multiple geographically dispersed storage locations. Each fragment is stored in a separate facility with its own security credentials, allowing the system to achieve secure distributed storage without requiring all data to be held in a single expensive secure facility. This segmentation enables cost-effective storage while maintaining security through cryptographic fragment distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an access management system as an intermediary that coordinates between the RAID controller and NAT system. This intermediary manages security credentials, validates access requests, and ensures that fragmented data can only be reconstructed with proper authorization. The intermediary layer enables secure distributed storage by mediating access control across multiple locations without requiring direct trust between all parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data is distributed across multiple geographically dispersed storage locations, then storage flexibility and economic advantage are improved, but access control complexity increases

Engineering Contradiction:
Improvestorage flexibilityVSAvoidaccess control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access management system serves multiple functions: it manages security credentials for distributed storage locations, validates access requests from users, coordinates with the NAT system for network address translation, and maintains access logs. This multi-functional intermediary simplifies the overall system by consolidating access control logic in a single component rather than requiring complex distributed access control across all storage locations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms where the access management system continuously monitors access requests, validates credentials against stored security policies, and provides real-time authorization decisions. The NAT system also provides feedback by translating addresses bidirectionally, enabling the system to track and control data access flows. This feedback loop maintains access control integrity while enabling flexible distributed storage.

Inventive Principle:
Principle #23Feedback

3Reliability

If non-routable IP addresses are used for storage drives on a local area network, then local network security is improved, but remote accessibility deteriorates

Engineering Contradiction:
Improvelocal network securityVSAvoidremote accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The NAT system acts as an intermediary between the internal LAN with non-routable IP addresses and the external WAN with routable IP addresses. It translates internal non-routable addresses to external routable addresses for outgoing data transmissions and translates incoming external requests to the appropriate internal addresses. This intermediary enables remote accessibility while preserving the security benefits of using non-routable IP addresses on the internal network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of making internal non-routable IP addresses directly accessible from the external network (which would compromise security), the system inverts the approach by having external users connect to a public-facing NAT gateway and then translating their requests inward to the appropriate non-routable addresses. This inversion maintains security by keeping internal addresses hidden while enabling external access through the translation layer.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS20250036322A1Secure, distributed raid storage systems and methods
Publication Date: 2025.01.30 CENTURYLINK INTELLECTUAL PROPERTY LLC
  • US20250036322A1 patent drawing
  • US20250036322A1 patent drawing
  • US20250036322A1 patent drawing

AI summary

Systems and methods for securely and remotely storing data in a remote, distributed redundant array of independent drives (RAID) is provided. RAID storage is accomplished through a series of mapped drives, non-routable Internet protocol (IP) addresses, and routable IP addresses. In addition, authorization to access a RAID controller, network address translation (NAT) system, and domain name system (DNS) system may all be separated, increasing security and allowing storage to be securely distributed among a variety of dispersed storage locations.