Storage Device HMB Security Policy Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage devices lack an efficient method to detect and respond to abnormal operations in host memory buffers (HMBs), leading to potential security vulnerabilities and performance degradation.
Innovation Solution
A storage device with a controller that detects abnormal operations in the HMB, updates the security policy accordingly, and manages the HMB by dividing it into regions with varying security levels, ensuring appropriate security policies are applied to each region.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a host memory buffer (HMB) is used for data processing, then productivity is improved, but reliability deteriorates due to potential abnormal operations and security vulnerabilities
Solution Approach 1:
The HMB is divided into multiple regions (first region, second region, third region) with different security policies applied to each. This segmentation allows the system to maintain high productivity by utilizing the HMB while improving reliability through differentiated security protection levels for different data types and access scenarios.
Solution Approach 2:
The security policy is dynamically updated based on detected abnormal operations. When an abnormal operation is detected in the HMB, the controller updates the security policy for the affected region, transitioning from a static security approach to a dynamic one that adapts to runtime conditions, thereby maintaining reliability while preserving productivity.
2Reliability
If a uniform security policy is applied to the entire HMB, then reliability is improved, but device complexity increases and productivity decreases
Solution Approach 1:
Different security policies are applied to different regions of the HMB based on local requirements. The first region has a first security policy, the second region has a second security policy, and the third region has a third security policy. This local quality approach improves reliability through targeted security while reducing overall device complexity compared to a uniform high-security policy.
Solution Approach 2:
Instead of applying maximum security to the entire HMB, the system applies appropriate security levels only where needed in specific regions. This partial action approach maintains necessary reliability while minimizing the complexity overhead associated with comprehensive security management.
3Reliability
If security policies are dynamically updated in response to abnormal operations, then reliability is improved, but device complexity increases
Solution Approach 1:
The controller includes an abnormality detector that continuously monitors HMB operations and provides feedback to the HMB manager. When abnormal operations are detected, the system updates security policies for affected regions. This feedback mechanism improves reliability by responding to actual threats while keeping controller complexity manageable through targeted updates rather than system-wide changes.
Data Source
AI summary
A storage device and an operation method of a storage device is provided. An operation method of a storage device includes: detecting an abnormal operation of a host memory buffer (HMB) positioned outside a storage device during data processing; and when the abnormal operation is detected, updating, by the storage device, a security policy applied when writing data to or reading data from the HMB.


