Stealth Drive Group Firmware Isolation for Clone Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional storage systems face challenges in providing adequate security protections for clones or other high-value copies of data, as encryption cannot prevent malicious destruction, leaving them vulnerable to unauthorized access and intentional damage.

Innovation Solution

Implementing stealth drive groups with a firmware-level configuration that securely separates storage devices into production and stealth groups, using distinct configuration processes to protect clones from access and destruction by malicious attackers, ensuring high-security storage through temporary inaccessibility and controlled reconfiguration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If encryption is used to protect clones from unauthorized access, then data confidentiality is improved, but protection against malicious destruction is not achieved

Engineering Contradiction:
Improveunauthorized access protectionVSAvoidprotection against malicious destruction
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The storage system is divided into separate drive groups (production drive group and clone drive group) with distinct firmware-level configurations. This segmentation isolates clones in a dedicated environment, providing both access control and protection against malicious destruction by preventing attackers from accessing or corrupting clone data through the production system interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The firmware-level configuration acts as an intermediary layer between the physical storage devices and the host system. This intermediary enforces access rules and isolation policies at the firmware level, providing security protection that cannot be bypassed by software-level attacks while maintaining reliable protection against malicious destruction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If clones are made accessible within the storage system, then data availability is improved, but vulnerability to malicious attacks increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidmalicious attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

By segmenting the storage system into production and clone drive groups with firmware-level isolation, clones can be made accessible within their dedicated group while remaining invisible and protected from the production system. This resolves the contradiction by providing controlled accessibility without exposing clones to malicious attacks from the production environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security qualities are applied to different parts of the storage system. The clone drive group has restricted access controls and isolation properties, while the production drive group maintains normal accessibility. This local differentiation allows clones to be accessible within their secure context while protecting them from external malicious attacks.

Inventive Principle:
Principle #3Local quality

3Reliability

If firmware-level separation is implemented for stealth drive groups, then security protection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protection levelVSAvoidfirmware configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The firmware-level configuration mechanism serves multiple functions: it provides drive group management, enforces security policies, isolates clones from production systems, and controls access permissions. By making the firmware configuration multi-functional, the system achieves high security protection without proportionally increasing complexity, as the same firmware layer handles multiple security and management tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11893259B2Storage system configured with stealth drive group
Publication Date: 2024.02.06 EMC IP HLDG CO LLC
  • US11893259B2 patent drawing
  • US11893259B2 patent drawing
  • US11893259B2 patent drawing

AI summary

A storage system comprises a plurality of storage devices, and is configured to establish a production drive group comprising a first subset of the storage devices, using a first firmware-level configuration process, and to establish a stealth drive group comprising a second subset of the storage devices, using a second firmware-level configuration process, the storage devices of the stealth drive group thereby being separated at a firmware level of the storage system from the storage devices of the production drive group. The storage system is further configured to copy data of one or more logical storage volumes from the production drive group to the stealth drive group, and responsive to completion of the copying of the data of the one or more logical storage volumes from the production drive group to the stealth drive group, to initiate a firmware-level reconfiguration process for the storage devices of the stealth drive group.