Multi-Tenant Storage Recovery with Ransomware Write Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage devices in multi-tenancy environments are vulnerable to ransomware attacks, which encrypt data and render it inaccessible without decryption keys, posing significant financial and operational risks.
Innovation Solution
A storage device with a write protector that detects ransomware attacks, updates tenant status based on detection results, writes recovery information in non-volatile memory, and performs data recovery using address links to original data, enabling read-only mode when necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a storage device allows multiple tenants to share storage resources, then storage utilization and resource efficiency are improved, but the system becomes more vulnerable to ransomware attacks that can affect multiple tenants
Solution Approach 1:
The storage device is divided into multiple isolated storage spaces, each assigned to a different tenant. Each storage space is independently managed with separate encryption keys and access controls, preventing ransomware from propagating across all tenant data while maintaining efficient resource sharing at the physical level
Solution Approach 2:
A controller acts as an intermediary between tenants and storage media, implementing multi-tenancy management, access control, and ransomware detection mechanisms. The controller monitors write operations, detects ransomware behavior patterns, and coordinates recovery operations without requiring direct tenant access to physical storage
2Reliability
If the storage device monitors and detects ransomware attacks in real-time, then data protection capability is improved, but system complexity and processing overhead increase
Solution Approach 1:
The storage device autonomously detects ransomware attacks by monitoring write operation patterns and automatically initiates recovery procedures without requiring external intervention. The system self-manages tenant status tracking, recovery information storage, and coordinated recovery execution, reducing the need for complex external management infrastructure
Solution Approach 2:
The system continuously monitors write operations and provides feedback on detected patterns to the controller, which adjusts its response based on the severity and type of detected threats. The feedback mechanism enables dynamic adjustment of protection measures while maintaining manageable system complexity through standardized response protocols
3Reliability
If the storage device stores recovery information for each tenant, then data recovery capability is improved, but storage space consumption increases
Solution Approach 1:
Recovery information is stored in a dedicated recovery region of the storage device rather than duplicating full data copies. The recovery information contains essential data for restoration (such as pre-encryption snapshots or recovery keys) in a compressed format, significantly reducing storage space requirements while maintaining effective recovery capability across multiple tenants
4Reliability
If the storage device performs data recovery operations, then data integrity is improved, but processing time and system performance during recovery increase
Solution Approach 1:
Recovery information is prepared and stored in advance before ransomware attacks occur, during normal write operations. When an attack is detected, the pre-prepared recovery information is immediately deployed, eliminating the need for time-consuming data reconstruction and significantly reducing recovery time while ensuring data integrity
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed is an operation method of a storage device, which includes detecting a ransomware attack on one or more tenants executed in a host, updating a tenant status table including a status of each of the one or more tenants based on a result of the detection, writing recovery information for data recovery in a non-volatile memory depending on whether a status value of a tenant corresponding to the write request from among the one or more tenants is a status value corresponding to a warning status from among a plurality of status values, when a write request is received from the host, and performing the data recovery depending on the recovery information, when a recovery signal is received from the host.