Secure Storage Appliance Cryptographic Splitting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems face vulnerabilities such as unauthorized access and data loss risks due to network vulnerabilities and physical storage limitations, particularly in centralized data centers that require robust security measures for data integrity and recovery.
Innovation Solution
A secure storage appliance that manages I/O requests by splitting and encrypting data at a block level, distributing it across multiple physical storage devices, and using a state-based processing system to ensure data security and availability, thereby enhancing access control and data integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored in a centralized data storage system with traditional security measures (encryption and access control), then data security and accessibility are maintained, but the system remains vulnerable to unauthorized access through physical disk theft or network exploitation, and data loss risks from corruption or catastrophic events
Solution Approach 1:
The patent divides data into multiple fragments (shares) and distributes them across multiple physical storage devices. Each fragment alone is useless for reconstructing the original data, providing security against physical disk theft and network exploitation. This segmentation approach directly addresses the vulnerability to unauthorized access while maintaining data accessibility through distributed storage.
Solution Approach 2:
The patent introduces a secure storage appliance as an intermediary device that performs cryptographic splitting of data before storage and reconstitution during retrieval. This intermediary layer adds security processing without requiring changes to the underlying storage infrastructure, effectively mediating between the data and the storage system to protect against various threats.
2Ease of operation
If traditional encryption methods are used to secure data at rest, then data confidentiality is protected, but the system lacks efficient mechanisms for data deletion and recovery, and cannot provide granular security control for different data portions
Solution Approach 1:
By dividing data into multiple shares stored on different physical devices, the patent enables granular control where deletion of specific data portions can be achieved by removing or corrupting only the necessary shares. This segmentation provides efficient data deletion mechanisms while maintaining data integrity through the requirement of multiple shares for successful reconstruction.
Solution Approach 2:
The patent implements state-based processing that tracks the status of data blocks through various stages (received, processed, stored, retrieved). This state management enables efficient data recovery by tracking which shares are available and their processing status, allowing the system to recover data using available shares without requiring complete re-processing of all data.
3Reliability
If data is distributed across multiple physical storage devices for security and redundancy, then data availability and security are improved, but the system complexity increases and processing overhead for data operations increases
Solution Approach 1:
The secure storage appliance serves multiple functions: it performs cryptographic splitting of data, manages distribution across multiple storage devices, tracks state of data blocks, and handles reconstitution during retrieval. This multi-functional approach consolidates complex operations into a single management interface, reducing overall system complexity while maintaining data availability across distributed devices.
Solution Approach 2:
The system implements automatic state tracking and resource management where the secure storage appliance autonomously manages the lifecycle of data blocks through various processing states. This self-service capability reduces the need for manual intervention and complex coordination between multiple storage devices, simplifying the distributed system while maintaining high availability.
4Reliability
If cryptographic splitting is performed on all data blocks, then data security is maximized, but the processing time and computational resources required increase significantly
Solution Approach 1:
The patent implements selective cryptographic splitting where not all data blocks require the full cryptographic processing. The state-based system identifies which blocks need security processing and which can be handled more efficiently. This partial application of cryptographic splitting maintains data security for sensitive blocks while preserving processing throughput for less sensitive operations.
Solution Approach 2:
The system performs preliminary state assignment to data blocks upon receipt, categorizing them before full processing. This preliminary action allows the system to prepare security processing in advance for blocks that require it, while maintaining a pipeline that can process multiple blocks concurrently. The state-based approach enables overlapping of security processing with other operations, reducing overall processing time while maintaining security.
Data Source
AI summary
Methods and systems for managing I/O requests in a secure storage appliance are disclosed. One method includes receiving a plurality of I/O requests at the secure storage appliance, each I/O request associated with a block of data and a volume, each volume associated with a plurality of shares stored on a plurality of physical storage devices. The method further includes storing a plurality of blocks of data in buffers of the secure storage appliance, each of the blocks of data associated with one or more of the plurality of I/O requests. The method also includes associating a state with each of the blocks of data, the state selected from a plurality of states associated with processing of an I/O request. The method includes determining the availability of a resource in the secure storage appliance, the resource used to process an I/O request of a buffer, and, upon determining that the resource is available, applying the resource to a block of data in the buffer and updating the state associated with the block of data.


