Secure Logical Storage Partition Access via Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current networked systems face challenges in providing secure and efficient access to logical storage partitions, as traditional methods often result in poor performance, inadequate data segregation, and complex management, leading to high costs and security vulnerabilities.

Innovation Solution

A system and method that automatically associate secure logical storage partitions with uniquely identified servers in a network, using network isolation to restrict access, thereby providing secure and efficient access while simplifying storage management and reducing costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application layer approaches are used to improve data security in storage pools, then data security is enhanced, but system complexity and management burden increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a storage virtualization layer as an intermediary between clients and physical storage devices. This virtualization layer abstracts storage resources and provides security through logical isolation rather than application-layer software, reducing system complexity while maintaining data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces application-layer software security mechanisms with hardware-based virtualization and network isolation mechanisms. By using virtualized storage controllers and isolated network paths, security is enforced at the infrastructure level rather than through software applications, simplifying the overall system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If exclusive storage devices are assigned to each customer for data security, then data security is improved, but resource utilization deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments storage resources into virtualized storage pools that can be dynamically allocated to multiple customers. Logical isolation through virtualization ensures data security while allowing multiple customers to share physical storage resources, improving utilization without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal storage pools that can serve multiple customers simultaneously through virtualization. The same physical storage infrastructure can be shared across different customers with logical isolation, making the storage system multi-functional rather than dedicated to single customers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive access control lists are used on servers for security, then data security is improved, but application performance deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidapplication performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a virtualization layer as an intermediary that handles access control and security enforcement separately from application operations. This allows applications to access storage through optimized paths while security policies are enforced at the virtualization layer, maintaining both security and performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves security enforcement from the application layer to the infrastructure layer (storage virtualization and network isolation). By adding this new dimension of security at the hardware/virtualization level, application performance is not impacted by access control operations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Adaptability or versatility

If physical re-configuration is performed for redeployment of storage devices, then resource flexibility is improved, but cost and time increase

Engineering Contradiction:
Improveresource flexibilityVSAvoidreconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements dynamic resource allocation through storage virtualization, allowing storage resources to be reassigned and reconfigured through software without physical changes. This enables flexible resource management where storage can be dynamically allocated to different customers based on demand without time-consuming physical reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces physical reconfiguration mechanisms with virtualization-based resource allocation. Instead of physically moving or reconfiguring storage devices, the system uses virtualized storage pools and software-controlled allocation, eliminating the need for physical reconfiguration while maintaining resource flexibility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS7500069B2System and method for providing secure access to network logical storage partitions
Publication Date: 2009.03.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7500069B2 patent drawing
  • US7500069B2 patent drawing
  • US7500069B2 patent drawing

AI summary

A method for providing secure access to network secure logical storage partitions is disclosed. The method comprises automatically associating at least one of a plurality of secure logical storage partitions in a storage device in a network with at least one of a plurality of uniquely identified servers in a cell in the network in response to a request for storage over the network. The method also comprises automatically associating the cell with at least one client using network isolation of the cell, and using network isolation of the storage device to restrict access to at least one of the plurality of secure logical storage partitions to the one of the plurality of uniquely identified servers in the cell. In a particular embodiment, the method also comprises determining whether storage capacity is available for the at least one client in response to the request, and automatically creating the cell if the cell does not already exist.