Storage Device HMB Security Policy Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage devices lack an efficient method to detect and respond to abnormal operations in host memory buffers (HMBs), leading to potential security vulnerabilities and performance degradation.

Innovation Solution

A storage device with a controller that detects abnormal operations in the HMB, updates the security policy accordingly, and manages the HMB by dividing it into regions with varying security levels, ensuring appropriate security policies are applied to each region.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a host memory buffer (HMB) is used for data processing, then productivity is improved, but reliability deteriorates due to potential abnormal operations and security vulnerabilities

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidsystem reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The HMB is divided into multiple regions (first region, second region, third region) with different security policies applied to each. This segmentation allows the system to maintain high productivity by utilizing the HMB while improving reliability through differentiated security protection levels for different data types and access scenarios.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security policy is dynamically updated based on detected abnormal operations. When an abnormal operation is detected in the HMB, the controller updates the security policy for the affected region, transitioning from a static security approach to a dynamic one that adapts to runtime conditions, thereby maintaining reliability while preserving productivity.

Inventive Principle:
Principle #15Dynamics

2Reliability

If a uniform security policy is applied to the entire HMB, then reliability is improved, but device complexity increases and productivity decreases

Engineering Contradiction:
Improvedata securityVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Different security policies are applied to different regions of the HMB based on local requirements. The first region has a first security policy, the second region has a second security policy, and the third region has a third security policy. This local quality approach improves reliability through targeted security while reducing overall device complexity compared to a uniform high-security policy.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of applying maximum security to the entire HMB, the system applies appropriate security levels only where needed in specific regions. This partial action approach maintains necessary reliability while minimizing the complexity overhead associated with comprehensive security management.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security policies are dynamically updated in response to abnormal operations, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoidcontroller complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The controller includes an abnormality detector that continuously monitors HMB operations and provides feedback to the HMB manager. When abnormal operations are detected, the system updates security policies for affected regions. This feedback mechanism improves reliability by responding to actual threats while keeping controller complexity manageable through targeted updates rather than system-wide changes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12271605B2Storage device and operation method thereof
Publication Date: 2025.04.08 SAMSUNG ELECTRONICS CO LTD
  • US12271605B2 patent drawing
  • US12271605B2 patent drawing
  • US12271605B2 patent drawing

AI summary

A storage device and an operation method of a storage device is provided. An operation method of a storage device includes: detecting an abnormal operation of a host memory buffer (HMB) positioned outside a storage device during data processing; and when the abnormal operation is detected, updating, by the storage device, a security policy applied when writing data to or reading data from the HMB.