Ransomware-aware SSD Data Retention via Idle Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage systems, particularly solid-state drives (SSDs), are inadequate in defending against evolving ransomware attacks that exploit flash properties and limited storage capacity, leading to data loss and inability to retain stale data for extended periods, which compromises security and performance.
Innovation Solution
The development of ransomware-aware SSDs (RSSDs) that utilize Non-Volatile Memory Express (NVMe) over Ethernet to expand storage capacity securely, enhance trim command security, and enable post-attack analysis by transferring data to remote servers during idle periods, ensuring data retention and recovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SSDs retain stale data locally to defend against ransomware, then data recovery capability is improved, but storage capacity is consumed and data retention time is limited
Solution Approach 1:
The patent extends data retention from a single-location (local SSD) to a multi-dimensional architecture by introducing remote storage servers connected via network. This allows stale data to be retained in both local and remote dimensions simultaneously, overcoming the storage capacity limitation of local SSDs while maintaining fast local access for active data.
Solution Approach 2:
The patent segments the storage system into multiple independent components: local SSD for active data and remote storage servers for archival stale data. This segmentation allows the system to maintain high storage capacity for recovery by distributing data across multiple remote servers, while the local SSD remains available for performance-critical operations.
2Reliability
If SSDs retain stale data for extended periods, then ransomware defense capability is improved, but performance is degraded due to storage management overhead
Solution Approach 1:
The patent extracts the burden of long-term stale data retention from the local SSD and relocates it to remote storage servers. This extraction allows the local SSD to focus on performance-critical active data operations while remote servers handle the time-consuming tasks of long-term data archival and management, thus maintaining high performance while extending data retention periods.
3Duration of action of stationary object
If SSDs expand storage capacity locally to retain more stale data, then data retention time is extended, but device complexity and cost increase
Solution Approach 1:
The patent introduces network infrastructure and remote storage servers as intermediaries between the local SSD and the archival storage requirement. Instead of directly expanding local SSD capacity (which increases device complexity), the system uses network-mediated remote storage to extend data retention time, keeping the local SSD simple and cost-effective while achieving extended retention through external resources.
4Device complexity
If conventional SSDs are used, then device simplicity is maintained, but security against evolving ransomware attacks is insufficient
Solution Approach 1:
The patent implements preliminary action by proactively transferring and retaining stale data copies to remote storage servers before ransomware attacks occur. This pre-positioning of data backups ensures that even if the local SSD is compromised, the data can be recovered from remote servers, thus enhancing security without significantly complicating the device architecture.
Data Source
AI summary
An example embodiment may involve a storage device comprising one or more processors, memory, a host interface connectable to a host device, a network interface connectable to a backup device, and program instructions, stored in the memory, that upon execution by the one or more processors cause the storage device to perform operations comprising: causing data received, by way of the host interface, to be stored in a page of the memory; after storing the data, marking the page as invalid due to input/output operations of the memory; determining a predicted idle time period within which the memory is not expected to be engaged in further input/output operations; determining that a duration of the predicted idle time period exceeds a threshold length; and during the predicted idle time period, transmitting, by way of the network interface, the data to the backup device.


