Multi-Path Encryption for File Data Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage systems lack the ability to differentiate between file data and other types of data for encryption and decryption, leading to inefficient use of resources and limited user control over which data is encrypted.

Innovation Solution

Implementing a multi-path layer in host devices with MPIO drivers that include path selection logic and encryption/decryption logic to identify and encrypt only file data, allowing users to select specific file types for encryption and decryption, while using DIF/DIX features to manage encryption status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all data is encrypted without differentiation, then security is improved, but computational resources are wasted and performance deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating encryption treatment for different types of data. File data is identified through index nodes and encrypted selectively, while non-file data remains unencrypted. This localized application of encryption to only where needed (file data) maintains security requirements while avoiding the performance penalty of encrypting all data uniformly.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments data into file data and non-file data based on index node analysis. By dividing the data stream and applying encryption only to the file data segment, the system achieves selective security that prevents resource waste on non-sensitive data while maintaining protection where required.

Inventive Principle:
Principle #1Segmentation

2Loss of energy

If file data is identified and encrypted selectively, then computational resource efficiency is improved, but device complexity increases

Engineering Contradiction:
Improvecomputational resource efficiencyVSAvoidmulti-path layer complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary multi-path layer with file system interface that acts as a mediator between the host and storage system. This intermediary contains the encryption logic and index node analysis capabilities, isolating the complexity from the core storage operations while enabling selective encryption. The intermediary handles the complexity of file identification and encryption management without requiring changes to the underlying storage infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If encryption functionality is added to multi-path layer, then user control over encrypted data is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveuser control over encryptionVSAvoidoperation simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the multi-path layer to automatically identify file data through index nodes and perform encryption without requiring explicit user intervention for each operation. The system autonomously determines which data requires encryption based on file system metadata, providing user control through configuration options while maintaining operational simplicity through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11755222B2File based encryption for multi-pathing devices
Publication Date: 2023.09.12 EMC IP HLDG CO LLC
  • US11755222B2 patent drawing
  • US11755222B2 patent drawing
  • US11755222B2 patent drawing

AI summary

An apparatus comprises a processing device configured to control delivery of input-output operations from a host device to a storage system over selected ones of a plurality of paths through a network. The processing device is further configured to identify whether operational information of the host device corresponding to a given write input-output operation comprises one or more index nodes, and to analyze the one or more index nodes responsive to a positive identification. The processing device is also configured to determine whether one or more portions of data corresponding to the given write input-output operation comprise file data based on the analysis of the one or more index nodes, to encrypt at least part of the file data responsive to an affirmative determination, and to deliver the given write input-output operation comprising the encrypted file data to the storage system.