DSD Controller Host Classification for Rogue Access Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data storage devices (DSDs) operating in multi-host environments face challenges in securing user data against unauthorized access by rogue hosts, while ensuring integrity of service and accessibility for authorized hosts.
Innovation Solution
A method executed by a DSD controller to determine a host type, detect access activities, process these activities to determine a security threat level by weighting access activity parameters with impact weights dynamically determined based on the host type, and control access activities to safeguard the DSD against rogue hosts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data storage devices implement security measures to protect against unauthorized access by rogue hosts, then data security is improved, but service accessibility and integrity for authorized hosts may deteriorate
Solution Approach 1:
The system performs preliminary classification of hosts into types (e.g., authorized vs. rogue) before security decisions are made. By pre-establishing host type categories and their expected access patterns, the system can quickly determine appropriate security measures without interfering with legitimate access, thus maintaining both data security and service accessibility.
Solution Approach 2:
The security system applies different access control policies and monitoring strictness levels to different host types. Authorized hosts receive standard access with normal security checks, while suspicious or rogue hosts trigger enhanced security measures. This localized application of security quality ensures that legitimate services remain accessible while protecting against threats.
2Reliability
If data storage devices implement comprehensive access monitoring and security threat detection, then protection against rogue hosts is improved, but device complexity increases
Solution Approach 1:
The security system is segmented into distinct functional modules: host type classification module, access activity detection module, security threat level determination module, and access control module. Each module performs a specific function independently, making the overall complex system manageable and maintainable while providing comprehensive protection against rogue hosts.
Solution Approach 2:
The controller acts as an intermediary between the storage device and multiple hosts, mediating all access requests. The controller implements the security logic and decision-making processes, isolating the complexity from the storage device itself and allowing the security system to be implemented without modifying the fundamental storage architecture.
3Measurement precision
If data storage devices use dynamic impact weights based on host type for security threat assessment, then security threat detection accuracy is improved, but computational requirements increase
Solution Approach 1:
Impact weights for different access activities are pre-calculated and stored based on host type classifications. When a host is classified, its corresponding pre-determined impact weights are immediately applied to access activities without requiring real-time computation. This preliminary preparation maintains high detection accuracy while minimizing computational energy consumption during actual security assessment.
Data Source
AI summary
A method for securing a data storage device (DSD) against rogue behaviour by a host, the method executed by a controller of the DSD and comprising: determining a host type of the host; detecting one or more access activities performed by the host on the DSD; processing the one or more access activities to determine a security threat level of the host, wherein the security threat level is determined by weighting one or more corresponding access activity parameters by one or more impact weights; and in response to determining that the security threat level of the host is greater than or equal to a rogue host threat level, controlling the access activities performable by the host on the DSD to safeguard the DSD against the host, wherein the one or more impact weights are dynamically determined based on the host type.


