Dual Storage Controllers Cross-Verify Firmware for Failover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Storage systems require continuous operation with minimal reboot capability and robust security measures to maintain data integrity and security levels, especially in the face of potential software tampering, while ensuring high I/O performance.

Innovation Solution

A dual-controller storage system where each controller includes a management controller and a disk controller, with each verifying its own software and the software of the other controller, allowing for seamless failover and continuous operation even if one controller fails, and implementing tampering checks to prevent unauthorized software modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If storage systems implement strict security measures and continuous operation requirements, then reliability and security levels are improved, but system complexity and operational flexibility worsen

Engineering Contradiction:
Improvesystem reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage system is divided into multiple independent storage controllers, each with its own management controller and disk controllers. This segmentation allows individual controllers to operate independently, improving system reliability while distributing complexity across multiple manageable units rather than a single complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements beforehand cushioning by having multiple storage controllers configured in advance, where if one controller fails, the other controllers can continue operating. This pre-prepared redundancy cushioning ensures continuous operation without requiring system shutdowns, thereby improving reliability while managing complexity through planned redundancy.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Object-affected harmful factors

If storage systems implement firmware tampering prevention functions, then security levels are improved, but device complexity and operational flexibility worsen

Engineering Contradiction:
Improvesoftware tamperingVSAvoidcontroller complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

Each storage controller is segmented into independent management controller and disk controller units, each capable of performing its own firmware tampering prevention functions. This segmentation distributes the security complexity across multiple independent units rather than concentrating it in a single complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The management controller performs self-service by verifying the firmware of its own disk controllers and the firmware of other storage controllers' disk controllers. This self-verification mechanism ensures security while keeping each controller unit relatively simple and independent.

Inventive Principle:
Principle #25Self-service

3Productivity

If storage systems minimize reboot capability to maintain continuous operation, then productivity is improved, but reliability worsens when failures occur

Engineering Contradiction:
Improvecontinuous operation capabilityVSAvoidfailure recovery capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements beforehand cushioning by configuring multiple storage controllers in advance, where if one controller fails, the other controllers can continue operating without requiring system reboot. This pre-prepared redundancy cushioning ensures both continuous operation (productivity) and failure tolerance (reliability).

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

When a storage controller fails, the system automatically discards the failed controller from operation and recovers by having the remaining controllers continue serving data requests. This mechanism maintains continuous operation while recovering from failures without requiring system reboot.

Inventive Principle:
Principle #34Discarding and recovering

4Reliability

If storage systems implement dual-controller architecture with cross-verification, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoidcontroller architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The dual-controller architecture is segmented into independent management controller and disk controller units. Each controller unit maintains a standardized structure, which simplifies the overall architecture despite the increased number of components. The segmentation allows for modular complexity management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each storage controller is designed with universal functionality, where the management controller can verify firmware in its own disk controllers and other storage controllers' disk controllers. This multi-functionality is implemented through standardized interfaces and protocols, which manages the complexity by using uniform design patterns across all controllers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12066913B2Storage system having multiple management controllers for detecting a failure
Publication Date: 2024.08.20 HITACHI VANTARA LTD
  • US12066913B2 patent drawing
  • US12066913B2 patent drawing
  • US12066913B2 patent drawing

AI summary

A first storage controller includes a first input and output controller performs input and output processing on host data, and a first management controller. A second storage controller includes a second input and output controller performs input and output processing on host data, and a second management controller. The first management controller is configured to verify software to be executed by the first management controller and software to be executed by the first input and output controller. The second management controller is configured to verify software to be executed by the second management controller and software to be executed by the second input and output controller. The first management controller is configured to verify the software to be executed by the second input and output controller in place of the second management controller when a failure is detected from the second management controller.