Hardware Resource Manager Conditional Key Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage systems lack effective mechanisms to securely manage and purge security keys in storage devices, particularly when communication with a key management service is lost, risking data access by unauthorized entities.

Innovation Solution

Implementing a hardware resource manager that utilizes key storage and purge policies, including synchronized and countdown timers, to determine when to store or delete security keys based on communication integrity with the key management service, and monitoring network changes to ensure secure data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If security keys are stored locally in the hardware resource manager, then data access speed and availability are improved, but security risk increases when communication with the key management service is lost

Engineering Contradiction:
Improvedata access speedVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by storing security keys locally in advance when communication with the key management service is available, enabling fast data access. The hardware resource manager proactively retrieves and stores keys before communication failures occur, preparing the system for rapid operation while maintaining security through conditional storage policies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the hardware resource manager continuously monitors communication status with the key management service and adjusts key storage behavior accordingly. When communication is lost, the system receives feedback about the failure state and automatically purges stored keys after a predetermined period, balancing accessibility with security through ongoing status monitoring and adaptive response.

Inventive Principle:
Principle #23Feedback

2Reliability

If security keys are purged immediately upon communication loss, then security risk is reduced, but system response time increases and data availability decreases

Engineering Contradiction:
Improvesecurity riskVSAvoidsystem response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system prepares for future security requirements by establishing a predetermined time period in advance that defines when key purging will occur after communication loss. This preliminary timing configuration allows the system to maintain keys temporarily for operational continuity while automatically enforcing security policies after the predetermined period expires, balancing immediate security needs with operational requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts its security behavior based on the duration of communication loss. Rather than immediate purging, the hardware resource manager monitors the elapsed time since communication failure and dynamically decides when to purge keys based on the predetermined time period. This dynamic approach allows flexible response timing that adapts to different communication failure scenarios while maintaining security.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the hardware resource manager continuously monitors communication status, then security control is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs periodic action by monitoring communication status at regular intervals rather than continuously. The hardware resource manager checks communication availability periodically to determine whether to store or purge security keys, reducing the computational burden while maintaining effective security control. This periodic monitoring approach balances security requirements with system resource consumption and complexity.

Inventive Principle:
Principle #19Periodic action

4Reliability

If key storage policies are implemented, then data security is improved, but ease of operation decreases due to additional management requirements

Engineering Contradiction:
Improvedata securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The hardware resource manager performs self-service by automatically managing key storage and purging based on predefined policies without requiring manual intervention. The system autonomously monitors communication status, retrieves keys from the key management service, stores them locally when appropriate, and purges them after the predetermined period, eliminating the need for user involvement in security management while maintaining strong data protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12026291B2Method and system for a conditional key storage in a hardware resource manager
Publication Date: 2024.07.02 DELL PROD LP
  • US12026291B2 patent drawing
  • US12026291B2 patent drawing
  • US12026291B2 patent drawing

AI summary

A method for managing a storage system includes initiating, by a hardware resource manager, a boot-up of a storage controller managing the storage system comprising a plurality of storage devices, making a determination, by the storage controller, that the storage controller is in a secured mode, based on the determination: identifying a security state of each of the plurality of storage devices, determining that a storage device of the plurality of storage devices is in an unsecured state, and based on the unsecured state, sending, by the storage controller, a security operation request for securing the storage device, obtaining a secure state response from the hardware resource manager corresponding to securing the storage device, and based on the secure state response, resuming operation of the storage controller based on the secure mode.