External Security Device for SAN Covert Channel Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Covert channels and covert timing channels pose significant security threats in Storage Area Networks by allowing sensitive information to be leaked, as they are difficult to detect and prevent, compromising the security of highly sensitive information.

Innovation Solution

Implementing read and write assurance devices in the communication paths between high and low-level devices to block, audit, and reduce covert channels, while also performing data duplication to mitigate traffic analysis threats, using external security devices that interpose between client devices and storage devices to ensure secure operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple devices are connected to the same storage in a Storage Area Network, then storage sharing and accessibility are improved, but security risks and the potential for covert information leakage increase

Engineering Contradiction:
Improvestorage sharingVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an external security device as an intermediary between client devices and storage devices in the SAN. This security device intercepts and monitors all access requests, blocking covert channels while allowing legitimate storage sharing operations to proceed. The intermediary position enables the system to maintain both accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the SAN into trusted and untrusted zones by placing security devices at strategic points in the communication path. This segmentation isolates the storage infrastructure from potential covert channel attacks while preserving the ability of multiple devices to share storage resources securely.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security systems are implemented to prevent covert channels, then information security is improved, but system complexity and detection difficulty increase

Engineering Contradiction:
Improveinformation securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The external security device serves as a specialized intermediary that handles the complexity of covert channel detection and prevention. Rather than making each SAN component complex, the patent centralizes security functions in dedicated security devices that monitor and control access requests, simplifying the overall system architecture while improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security devices implement feedback mechanisms by monitoring access patterns and blocking suspicious operations. The system provides feedback to administrators about blocked covert channels and maintains audit logs, enabling continuous improvement of security policies without increasing operational complexity for end users.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If covert channels are allowed to operate, then device functionality and flexibility are maintained, but information leakage and security breaches occur

Engineering Contradiction:
Improvedevice functionalityVSAvoidinformation leakage
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent converts the harmful effect of covert channels into a beneficial security feature. By monitoring and blocking covert channel attempts, the security devices actually improve system security while maintaining legitimate functionality. The blocked covert channels provide information about potential threats, allowing the system to strengthen its defenses.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The external security device acts as an intermediary that filters access requests, allowing legitimate device functionality to operate while blocking covert information leakage channels. The security device understands the difference between normal operational traffic and covert channel attempts, preserving adaptability while preventing harm.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If read assurance devices block write requests from higher level devices, then covert channel prevention is improved, but legitimate write operations may be restricted

Engineering Contradiction:
Improvecovert channel blockingVSAvoidwrite operation access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The read assurance device serves as an intermediary that intelligently evaluates write requests before blocking them. It distinguishes between legitimate write operations that are part of normal storage management and covert channel attempts, allowing legitimate operations to proceed while blocking security threats. This maintains ease of operation for authorized users while improving covert channel prevention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device applies different levels of scrutiny to different types of access requests. Legitimate write operations from authorized devices are processed normally, while suspicious requests that exhibit covert channel characteristics are blocked. This localized quality control maintains operational ease for legitimate users while preventing security breaches.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8832842B1Storage area network external security device
Publication Date: 2014.09.09 STORAGE TECHNOLOGY CORPORATION
  • US8832842B1 patent drawing
  • US8832842B1 patent drawing
  • US8832842B1 patent drawing

AI summary

An external security device is provided in the communication path between devices of different security levels. A higher security device needs only to trust the security of the external device, rather than relying on operating system and file system software that cannot be assured. The external security device blocks access requests that may be using covert channels, but returns status information that indicates that the request is successful. The external security device may then audit access requests to provide a higher level of accountability. The external security device also handles data duplication to prevent or significantly reduce the threat of traffic analysis.