Multi-Tenant Storage Control for Data Retention and Secure Erasure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the number of tenants (virtual machines) in data centers increases, existing storage devices struggle to meet the diverse processing conditions and data requirements of each tenant, leading to inefficiencies in data retention and erasure, especially during interruptions or power outages.

Innovation Solution

A storage device with a storage controller and non-volatile memory that includes an encryption/decryption engine and ECC engine, capable of performing encryption, decryption, error detection, and correction based on specific commands from virtual machines, ensuring data retention or erasure according to tenant requirements, even during interruptions or power outages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a storage device serves multiple tenants with diverse processing conditions, then the number of serviceable tenants increases, but the difficulty of meeting individual processing conditions for each tenant increases

Engineering Contradiction:
Improveability to serve multiple tenantsVSAvoidcomplexity of meeting individual processing conditions
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The storage device divides the storage space into multiple logical units (logical volumes) that can be independently assigned to different tenants. Each tenant receives dedicated logical volumes with customized parameters (capacity, I/O limits, retention policies), allowing individual processing conditions to be met without affecting other tenants. The storage controller manages these segmented units through virtualization layers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The storage device implements dynamic parameter adjustment capabilities where processing conditions for each tenant can be modified in real-time without physical reconfiguration. The storage controller allows administrators to dynamically change I/O limits, capacity allocations, and retention policies for each tenant's logical volumes, enabling flexible adaptation to diverse and changing requirements.

Inventive Principle:
Principle #15Dynamics

2Reliability

If data retention is ensured during interruptions or power outages, then data reliability improves, but the risk of retaining unwanted or obsolete data increases

Engineering Contradiction:
Improvedata retention reliabilityVSAvoidretention of unwanted data
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The storage device implements preliminary erasure actions through background processes that proactively identify and erase obsolete, obsolete, or unwanted data before interruptions or power outages occur. Garbage collection mechanisms and retention policy enforcement routines continuously scan and remove data that exceeds retention criteria, ensuring that only authorized and current data remains in storage media.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The storage controller implements feedback mechanisms that monitor data age, access patterns, and retention policy compliance in real-time. When data meets erasure criteria (age thresholds, access inactivity, policy violations), the system automatically triggers erasure operations and provides status feedback to tenants and administrators, ensuring unwanted data is removed while maintaining reliability for authorized data.

Inventive Principle:
Principle #23Feedback

3Reliability

If encryption is performed for each tenant's data, then data security improves, but the processing time and computational resources increase

Engineering Contradiction:
Improvedata securityVSAvoidencryption processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The storage device implements encryption at the media level rather than at the tenant or file level, combining security operations into a single hardware-based layer. The storage controller uses dedicated encryption engines that operate transparently on all data regardless of tenant ownership, eliminating the need for separate encryption processes for each tenant and reducing overall processing time while maintaining strong security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The storage device implements self-service encryption where the storage controller automatically manages key generation, distribution, and rotation without requiring tenant intervention or additional processing steps. Encryption and decryption operations are performed automatically by the storage controller's hardware modules as data moves through the system, making security transparent to tenants and eliminating manual overhead.

Inventive Principle:
Principle #25Self-service

4Reliability

If error correction is enhanced for each tenant's data, then data reliability improves, but the storage capacity available for actual data decreases

Engineering Contradiction:
Improveerror correction capabilityVSAvoidavailable storage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The storage device implements variable ECC strength parameters that can be adjusted based on data criticality and tenant requirements. The storage controller allows configuration of different ECC code rates and correction capabilities for different logical volumes or data types, enabling optimization between reliability and capacity. Critical data receives stronger ECC protection with higher overhead, while less critical data uses lighter protection schemes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12045472B2Storage device supporting multi-tenant operation and methods of operating same
Publication Date: 2024.07.23 SAMSUNG ELECTRONICS CO LTD
  • US12045472B2 patent drawing
  • US12045472B2 patent drawing
  • US12045472B2 patent drawing

AI summary

A storage device includes a storage controller, which is configured to receive a command generated by a first virtual machine, from a host, and a non-volatile memory device, which is configured to store first data for the command. The command includes one of a retain command, which is generated to command the storage controller to retain the first data in the non-volatile memory device, or an erase command, which is generated to command the storage controller to erase the first data from the non-volatile memory device, when access between the first virtual machine and the storage controller at least temporarily interrupted.