Hidden Compute Functions in Storage Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current distributed processing techniques in computer networks often require returning processing results to the initiating client or remote entities, compromising security and efficiency, especially when performing 'hidden' computational functions that need to remain local for security and volumetric reasons.

Innovation Solution

Implementing a hidden compute functionality (HCF) within a target device, such as a storage device, which executes commands from a client device, accumulates output data in a local cache, and stores it in non-volatile memory without transferring it outside a defined retention boundary, using standards like NVMe and CXL for enhanced processing and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If processing results are returned to the initiating client or remote entities in distributed processing, then the client can access and use the results, but security is compromised and unauthorized access becomes possible

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to results
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the processing results from the distributed processing system and retains them locally at the target device, separating the results from the client device. This extraction prevents unauthorized access while maintaining security, as the results never leave the secure environment of the target device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a retention boundary as an intermediary mechanism that controls access to processing results. This boundary acts as a mediator between the target device and external entities, allowing the system to maintain security while still enabling authorized access through controlled interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If processing results are transferred outside the target device, then clients can access results, but data volume increases and security boundaries are compromised

Engineering Contradiction:
ImprovesecurityVSAvoiddata volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the necessary verification information (such as hashes or checksums) from the full processing results, rather than transferring the complete data set. This extraction reduces data volume significantly while maintaining security, as the extracted verification data is sufficient to confirm result integrity without exposing sensitive information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates simplified copies of the processing results in the form of verification data (hashes, checksums, or digests) that can be transferred and verified without transferring the full result set. These copies serve as proxies that maintain security while enabling verification of processing outcomes.

Inventive Principle:
Principle #26Copying

3Reliability

If hidden compute functions are performed locally without returning results, then security is improved and data remains local, but the client cannot access or verify the results

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to processing results
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent creates verification copies (hashes, checksums, or digests) of the processing results that can be transferred to the client device for verification purposes. These copies enable the client to verify that processing was performed correctly and that results have not been tampered with, without exposing the actual sensitive result data.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements a feedback mechanism where verification data is returned to the client device to confirm successful processing. This feedback allows the client to verify that hidden compute functions were executed correctly and that results are available, maintaining trust in the system without compromising security.

Inventive Principle:
Principle #23Feedback

4Reliability

If processing results are stored in local cache and non-volatile memory, then security is improved and access control is enhanced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the target device's memory system multi-functional by using it both for storing processing results and for maintaining security boundaries. The local cache and non-volatile memory serve dual purposes: they store results securely and simultaneously enforce the retention boundary that prevents unauthorized access, reducing the need for separate security infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables the target device to self-manage security by maintaining results locally without requiring external security infrastructure. The device autonomously enforces retention boundaries and controls access to its own processing results, reducing system complexity by eliminating the need for external security management systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12079355B2Performing remote hidden compute functions in one or more processing devices
Publication Date: 2024.09.03 SEAGATE TECH LLC
  • US12079355B2 patent drawing
  • US12079355B2 patent drawing
  • US12079355B2 patent drawing

AI summary

Apparatus and method for executing hidden computational functions in a distributed data processing environment. In some embodiments, a trust boundary includes a target device such as a storage device, and a source device such as a client device in a computer network. A storage device processor executes a hidden command function (HCF) routine to accumulate HCF output data in a local cache responsive to an HCF command received from the client device over a data interface. The processor further establishes a smaller retention boundary within the trust boundary that includes the storage device and excludes the client device. The HCF output data are stored locally in a non-volatile memory (NVM) of the storage device while not transferring any portion of the HCF output data outside the retention boundary, including to the client device. The HCF routine can update a block-chain ledger or take some other form to provide data security.