Single Controller Multi-Client Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile designs face challenges in providing a cost-effective security mechanism for multi-client access to a single storage device through a single controller, as conventional approaches either require expensive dedicated secure elements or multiple access controllers.
Innovation Solution
A security mechanism that uses a single host controller to manage access to a storage device by verifying the identity, command, and logical unit number (LUN) of each client, allowing access to specific partitions based on client privileges, with special clients having exclusive access and regular clients sharing access with others.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dedicated secure element is used to ensure storage element is only accessible by a special client, then security is improved, but system cost increases
Solution Approach 1:
The patent merges multiple secure elements and their access controllers into a single storage device with a unified access controller. The controller implements multiple access control lists (ACLs) that manage permissions for different clients, eliminating the need for separate secure elements while maintaining security through software-based access control mechanisms.
Solution Approach 2:
The access controller is designed to serve multiple clients with different security requirements through a universal interface. It implements both special client access (supervisor mode) and regular client access (user mode) within the same controller, allowing a single device to perform functions that previously required multiple dedicated elements.
2Reliability
If multiple storage elements and multiple access controllers are used to provide separate storage for multiple clients, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent combines multiple storage elements into a single storage device and consolidates multiple access controllers into one unified controller. The controller manages multiple clients through different access control lists (ACLs), reducing the number of components while maintaining security through logical separation of access rights.
Solution Approach 2:
While physically consolidating components, the patent segments access control through multiple access control lists (ACLs) that are logically separated. Each ACL manages permissions for specific clients, creating virtual segmentation of access rights without requiring physical separation of storage elements or controllers.
3Device complexity
If a single controller manages access for multiple clients to a single storage device, then device complexity is reduced, but security control capability may be compromised
Solution Approach 1:
The patent changes the parameters of access control by implementing multiple access control lists (ACLs) within the single controller. Each ACL contains different permission sets for different clients, allowing the controller to dynamically adjust access parameters based on client identity and security requirements without compromising control capability.
Data Source
AI summary
Examples and techniques pertaining to a security mechanism for multi-client access to a single storage device through a single controller are described. A controller receives a request from a first client of a plurality of clients to access a storage device which stores data associated with the plurality of clients. The controller determines one or more aspects with respect to the first client. The controller then performs one of a plurality of operations including: (a) granting the first client access the storage device responsive to a positive result of the determining, and (b) rejecting the request responsive to a negative result of the determining. The storage device is divided into a plurality of partitions to store respective data associated with each of the plurality of clients in one or more respective partitions of the plurality of partitions.


