Dynamic Encryption Key Allocation in Computer Storage Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In storage systems with encryption functions, the varying load states of controllers and storage apparatuses lead to degraded access performance during encryption and decryption processing, as each device requires different encryption keys and processing loads change dynamically.

Innovation Solution

A computer system dynamically manages encryption keys to ensure that either the controller or the storage apparatus holds the same encryption key, allowing the system to dynamically change which device enables the encryption function based on load states during I/O requests, thereby optimizing processing loads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption processing is executed on both controller and storage apparatus with different encryption keys, then security is improved, but access performance is degraded due to processing loads

Engineering Contradiction:
ImprovesecurityVSAvoidaccess performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the encryption function into the storage apparatus, allowing the controller to store data in plaintext while the storage apparatus performs encryption/decryption. This combines the strengths of both devices by leveraging the storage apparatus's dedicated encryption capability, improving access performance while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent dynamically switches between two encryption architectures: one where the controller performs encryption and another where the storage apparatus performs encryption. This dynamic adaptation allows the system to optimize performance based on real-time load conditions, resolving the contradiction between security and access performance.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If encryption function is enabled on both controller and storage apparatus, then encryption flexibility is improved, but processing load increases causing performance degradation

Engineering Contradiction:
Improveencryption flexibilityVSAvoidprocessing performance
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The storage apparatus is designed with multi-functionality, serving both as a storage device and an encryption device. This universal design allows the system to maintain encryption flexibility while concentrating processing capabilities in one device, avoiding the performance degradation that would result from both devices performing encryption simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If different encryption keys are used by controller and storage apparatus, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key management complexity from the controller and consolidates it in the storage apparatus. By having the storage apparatus hold and manage the encryption keys exclusively, the system maintains strong security while simplifying the overall key management architecture, as only one device needs to handle key security and distribution.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10929030B2Computer and control method
Publication Date: 2021.02.23 HITACHI VANTARA LTD
  • US10929030B2 patent drawing
  • US10929030B2 patent drawing
  • US10929030B2 patent drawing

AI summary

A computer comprises a controller and a storage apparatus which is configured to provide a storage area for storing data. The controller and the storage apparatus have a function of achieving encryption and decryption of data through use of an encryption key. The computer is configured to: execute encryption key setting processing for setting the encryption key in the controller and the storage apparatus so that the controller holds the same encryption key as the encryption key of the storage apparatus; and determine whether to enable the function of any one of the controller and the storage apparatus, based on load states of the controller and the storage apparatus when an I/O request is received.