I/O Control Part Token Authentication for Storage Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information processing systems face challenges in effectively managing and securing input/output (I/O) requests from compute nodes to prevent data falsification and leaks, especially in hybrid and multi-cloud environments where traditional gateway and firewall configurations are insufficient.
Innovation Solution
An information processing system with an I/O control part that authenticates compute nodes and generates tokens for access control, ensuring that only authorized I/O requests are processed by storage nodes, thereby enhancing security and management efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional gateway and firewall configurations are used to secure I/O requests, then network access control is provided, but security against malware infiltration and unauthorized access is insufficient
Solution Approach 1:
The patent introduces an I/O control part as an intermediary component between compute nodes and storage nodes. This mediator authenticates I/O requests by verifying authentication information (ID and token) before allowing access to storage resources, providing enhanced security beyond traditional network-level gateway and firewall configurations.
2Reliability
If each resource verifies I/O requests independently, then access control is distributed, but information management becomes difficult
Solution Approach 1:
The patent implements a universal authentication mechanism where the I/O control part handles authentication for all storage nodes centrally. Instead of each storage node independently verifying requests, the I/O control part authenticates compute nodes and issues tokens that are recognized across the system, simplifying information management while maintaining distributed access control.
3Reliability
If rigorous authentication of compute nodes and storage nodes is implemented, then security against unauthorized access is improved, but system complexity increases
Solution Approach 1:
The patent implements preliminary authentication where compute nodes are authenticated by the I/O control part before accessing storage resources. The authentication information (ID and token) is verified in advance, and authenticated nodes receive authorization to access specific storage nodes. This preliminary verification simplifies the overall system by establishing trust beforehand rather than requiring continuous complex verification during operations.
Data Source
AI summary
The storage part receives an I/O request including the ID of software, information regarding a storage area to and from which the software performs input and output, and a token. The storage part checks the I/O request against the software ID, the information regarding the storage area, and the token received from an I/O control part so as to determine whether access to the storage part is allowed. Upon determination that the access to the storage part is allowed, the storage part processes the I/O request.


