Network-Ready Storage with Cryptographic Access Control and Direct Data Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network-attached storage devices inefficiently process data messages through a central processing unit (CPU), leading to bottlenecks in processing power and communication bandwidth, which limits the scalability of storage capacity.

Innovation Solution

Implementing separate processing paths for control and data messages, where control messages are routed through a processing device and data messages are directly communicated between a storage client and storage device without CPU intervention, reducing the CPU's workload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data messages are processed through a central processing unit (CPU), then control and security functions can be maintained, but processing power and communication bandwidth are bottlenecked, limiting scalability

Engineering Contradiction:
Improvecontrol and security functionsVSAvoidprocessing power and communication bandwidth
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the processing paths into two separate channels: a control path that routes through the CPU for authentication and security management, and a data path that bypasses the CPU for direct storage operations. This segmentation allows the system to maintain secure control functions while eliminating the CPU bottleneck that limited data processing throughput and scalability.

Inventive Principle:
Principle #1Segmentation

2Productivity

If a separate processing path for data messages is implemented, then processing power and scalability are improved, but device complexity increases

Engineering Contradiction:
Improveprocessing power and scalabilityVSAvoidprocessing path structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a storage controller as an intermediary component that manages the separation of control and data paths. The controller handles CPU-bound control operations (authentication, access control) while enabling direct data path communication between storage clients and storage devices, thereby achieving improved scalability without requiring complex distributed system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Use of energy by moving object

If CPU workload is reduced by bypassing data messages, then power consumption decreases, but control and security management becomes more challenging

Engineering Contradiction:
Improvepower consumptionVSAvoidcontrol and security management
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The patent extracts CPU-intensive control and security functions (authentication, access control decisions) from the data processing path and places them in a separate control path. This extraction allows the data path to operate independently with minimal power consumption while the control path handles security management through dedicated CPU resources, making the system more energy-efficient without compromising security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12379867B2Network-ready storage products with cryptography based access control
Publication Date: 2025.08.05 MICRON TECHNOLOGY INC
  • US12379867B2 patent drawing
  • US12379867B2 patent drawing
  • US12379867B2 patent drawing

AI summary

A storage product manufactured as a computer component and configured to have: a secure memory region to store cryptographic keys; a network interface; a local storage device having a storage capacity accessible via the network interface; and a host interface to be connected to a local host system. The local host system can control access, made via the network interface, to the storage capacity without receiving a portion of storage access messages received in the network interface. The storage product includes an access controller configured to determine whether a message, received in the network interface from the computer network or in the host interface from the local host system, has a valid verification code according to the cryptographic keys; and if not, the message can be rejected, deleted, discarded, or ignored without further processing.