Secure Logical Storage Partition Access via Network Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current networked systems face challenges in providing secure and efficient access to logical storage partitions, as traditional methods often result in poor performance, inadequate data segregation, and complex management, leading to high costs and security vulnerabilities.
Innovation Solution
A system and method that automatically associate secure logical storage partitions with uniquely identified servers in a network, using network isolation to restrict access, thereby providing secure and efficient access while simplifying storage management and reducing costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If application layer approaches are used to improve data security in storage pools, then data security is enhanced, but system complexity and management burden increase
Solution Approach 1:
The patent introduces a storage virtualization layer as an intermediary between clients and physical storage devices. This virtualization layer abstracts storage resources and provides security through logical isolation rather than application-layer software, reducing system complexity while maintaining data security.
Solution Approach 2:
The patent replaces application-layer software security mechanisms with hardware-based virtualization and network isolation mechanisms. By using virtualized storage controllers and isolated network paths, security is enforced at the infrastructure level rather than through software applications, simplifying the overall system.
2Reliability
If exclusive storage devices are assigned to each customer for data security, then data security is improved, but resource utilization deteriorates
Solution Approach 1:
The patent segments storage resources into virtualized storage pools that can be dynamically allocated to multiple customers. Logical isolation through virtualization ensures data security while allowing multiple customers to share physical storage resources, improving utilization without compromising security.
Solution Approach 2:
The patent creates universal storage pools that can serve multiple customers simultaneously through virtualization. The same physical storage infrastructure can be shared across different customers with logical isolation, making the storage system multi-functional rather than dedicated to single customers.
3Reliability
If comprehensive access control lists are used on servers for security, then data security is improved, but application performance deteriorates
Solution Approach 1:
The patent introduces a virtualization layer as an intermediary that handles access control and security enforcement separately from application operations. This allows applications to access storage through optimized paths while security policies are enforced at the virtualization layer, maintaining both security and performance.
Solution Approach 2:
The patent moves security enforcement from the application layer to the infrastructure layer (storage virtualization and network isolation). By adding this new dimension of security at the hardware/virtualization level, application performance is not impacted by access control operations.
4Adaptability or versatility
If physical re-configuration is performed for redeployment of storage devices, then resource flexibility is improved, but cost and time increase
Solution Approach 1:
The patent implements dynamic resource allocation through storage virtualization, allowing storage resources to be reassigned and reconfigured through software without physical changes. This enables flexible resource management where storage can be dynamically allocated to different customers based on demand without time-consuming physical reconfiguration.
Solution Approach 2:
The patent replaces physical reconfiguration mechanisms with virtualization-based resource allocation. Instead of physically moving or reconfiguring storage devices, the system uses virtualized storage pools and software-controlled allocation, eliminating the need for physical reconfiguration while maintaining resource flexibility.
Data Source
AI summary
A method for providing secure access to network secure logical storage partitions is disclosed. The method comprises automatically associating at least one of a plurality of secure logical storage partitions in a storage device in a network with at least one of a plurality of uniquely identified servers in a cell in the network in response to a request for storage over the network. The method also comprises automatically associating the cell with at least one client using network isolation of the cell, and using network isolation of the storage device to restrict access to at least one of the plurality of secure logical storage partitions to the one of the plurality of uniquely identified servers in the cell. In a particular embodiment, the method also comprises determining whether storage capacity is available for the at least one client in response to the request, and automatically creating the cell if the cell does not already exist.


