Hidden Compute Functions in Storage Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current distributed processing techniques in computer networks often require returning processing results to the initiating client or remote entities, compromising security and efficiency, especially when performing 'hidden' computational functions that need to remain local for security and volumetric reasons.
Innovation Solution
Implementing a hidden compute functionality (HCF) within a target device, such as a storage device, which executes commands from a client device, accumulates output data in a local cache, and stores it in non-volatile memory without transferring it outside a defined retention boundary, using standards like NVMe and CXL for enhanced processing and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If processing results are returned to the initiating client or remote entities in distributed processing, then the client can access and use the results, but security is compromised and unauthorized access becomes possible
Solution Approach 1:
The patent extracts the processing results from the distributed processing system and retains them locally at the target device, separating the results from the client device. This extraction prevents unauthorized access while maintaining security, as the results never leave the secure environment of the target device.
Solution Approach 2:
The patent introduces a retention boundary as an intermediary mechanism that controls access to processing results. This boundary acts as a mediator between the target device and external entities, allowing the system to maintain security while still enabling authorized access through controlled interfaces.
2Reliability
If processing results are transferred outside the target device, then clients can access results, but data volume increases and security boundaries are compromised
Solution Approach 1:
The patent extracts only the necessary verification information (such as hashes or checksums) from the full processing results, rather than transferring the complete data set. This extraction reduces data volume significantly while maintaining security, as the extracted verification data is sufficient to confirm result integrity without exposing sensitive information.
Solution Approach 2:
The patent creates simplified copies of the processing results in the form of verification data (hashes, checksums, or digests) that can be transferred and verified without transferring the full result set. These copies serve as proxies that maintain security while enabling verification of processing outcomes.
3Reliability
If hidden compute functions are performed locally without returning results, then security is improved and data remains local, but the client cannot access or verify the results
Solution Approach 1:
The patent creates verification copies (hashes, checksums, or digests) of the processing results that can be transferred to the client device for verification purposes. These copies enable the client to verify that processing was performed correctly and that results have not been tampered with, without exposing the actual sensitive result data.
Solution Approach 2:
The patent implements a feedback mechanism where verification data is returned to the client device to confirm successful processing. This feedback allows the client to verify that hidden compute functions were executed correctly and that results are available, maintaining trust in the system without compromising security.
4Reliability
If processing results are stored in local cache and non-volatile memory, then security is improved and access control is enhanced, but system complexity increases
Solution Approach 1:
The patent makes the target device's memory system multi-functional by using it both for storing processing results and for maintaining security boundaries. The local cache and non-volatile memory serve dual purposes: they store results securely and simultaneously enforce the retention boundary that prevents unauthorized access, reducing the need for separate security infrastructure.
Solution Approach 2:
The patent enables the target device to self-manage security by maintaining results locally without requiring external security infrastructure. The device autonomously enforces retention boundaries and controls access to its own processing results, reducing system complexity by eliminating the need for external security management systems.
Data Source
AI summary
Apparatus and method for executing hidden computational functions in a distributed data processing environment. In some embodiments, a trust boundary includes a target device such as a storage device, and a source device such as a client device in a computer network. A storage device processor executes a hidden command function (HCF) routine to accumulate HCF output data in a local cache responsive to an HCF command received from the client device over a data interface. The processor further establishes a smaller retention boundary within the trust boundary that includes the storage device and excludes the client device. The HCF output data are stored locally in a non-volatile memory (NVM) of the storage device while not transferring any portion of the HCF output data outside the retention boundary, including to the client device. The HCF routine can update a block-chain ledger or take some other form to provide data security.


