Secure Application Execution in Computational Storage Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computational storage devices face increased security risks due to the introduction of executable programs, which can compromise the integrity of the device and its components.

Innovation Solution

A method and system for managing program slots in computational storage devices, where a controller receives commands to reserve and load applications, stores associations between program slots and applications, and enforces execution based on permissions and privileges, ensuring secure execution and data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If executable programs are introduced to computational storage device, then computation functions are enhanced, but security risk increases

Engineering Contradiction:
Improvecomputation functionVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the computational storage device into multiple isolated program slots, each capable of running separate applications. This segmentation allows multiple computation functions to coexist while limiting the impact of security breaches to individual slots rather than the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a controller as an intermediary layer between the host device and the processing device. The controller manages program loading, execution, and slot reservation, acting as a security gatekeeper that validates and controls access to computational resources, thereby reducing direct security exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If program slots are reserved to specific applications, then device integrity is maintained, but flexibility to load different applications is reduced

Engineering Contradiction:
Improvedevice integrityVSAvoidapplication loading flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic slot reservation where program slots can be reserved for specific applications when needed, but the reservation status can be changed or released. This allows the system to maintain integrity through reservations when required while preserving flexibility to reconfigure or load different applications when reservations are released or expired.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12254191B2Secure applications in computational storage devices
Publication Date: 2025.03.18 SAMSUNG ELECTRONICS CO LTD
  • US12254191B2 patent drawing
  • US12254191B2 patent drawing
  • US12254191B2 patent drawing

AI summary

A method includes receiving, at a controller of a storage device, a command reserving a program slot of a processing device of the storage device to an application. The method further includes storing, by the controller of the storage device, an association between the program slot and the application. The method further includes receiving, at the controller of the storage device, a request to load the application into the execution slot. The method further includes loading, by the controller of the storage device, the application into the program slot based on the association and the request. The method further includes executing, at the processing device of the storage device, the application in the program slot.