Storage Compute Appliance Internal Data Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In shared data storage environments, existing encryption schemes that use separate encryption keys for each data set complicate multi-user data analysis and increase the risk of inadvertent exposure of underlying data when performing calculations or searches across multiple data sets.

Innovation Solution

A data storage device is configured as a storage compute appliance with a controller circuit and non-volatile memory that internally decrypts and processes encrypted data sets to generate summary results, which are then transferred to an authorized user without revealing the underlying data, using a storage compute appliance key stored internally and not transmitted externally.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate encryption keys are used for each data set, then data security is improved, but device complexity and difficulty of data analysis increase

Engineering Contradiction:
Improvedata securityVSAvoidencryption key management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments encryption keys into two distinct types: data set-specific keys stored by individual users for their own data protection, and a shared storage compute appliance key stored internally in the storage device. This segmentation allows users to maintain security for their individual data while enabling the storage device to perform centralized analysis operations on all encrypted data sets using the shared appliance key.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate encryption keys are used for each data set, then data security is improved, but productivity of multi-user data analysis decreases

Engineering Contradiction:
Improvedata securityVSAvoidmulti-user data analysis efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The storage compute appliance key acts as an intermediary that enables the storage device to decrypt and analyze multiple users' encrypted data sets without requiring direct access to individual user keys. This intermediary mechanism allows centralized data analysis operations to be performed efficiently on all data sets while maintaining the security model where users retain control of their own encryption keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If encrypted data sets are transferred to host for analysis, then data analysis capability is improved, but risk of data exposure increases

Engineering Contradiction:
Improvedata analysis capabilityVSAvoiddata exposure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Instead of transferring encrypted data to the host for decryption and analysis (which would expose data), the system inverts the process by bringing the decryption capability to the storage device itself. The storage compute appliance key enables the storage device to decrypt data locally and perform analysis operations on decrypted data within the secure storage environment, then return only analysis results to the host without exposing the underlying data.

Inventive Principle:
Principle #13The other way round (Inversion)

4Ease of operation

If decrypted data is transferred across host interface, then data accessibility is improved, but security and data protection worsen

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system extracts only the necessary analysis results from the decrypted data while leaving the actual decrypted data sets within the secure storage device. The controller circuit generates summary results data from the decrypted data sets and transfers only these summary results across the host interface to authorized users, preventing exposure of the underlying decrypted data while still providing useful analysis output.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11017127B2Storage compute appliance with internal data encryption
Publication Date: 2021.05.25 SEAGATE TECH LLC
  • US11017127B2 patent drawing
  • US11017127B2 patent drawing
  • US11017127B2 patent drawing

AI summary

Method and apparatus for managing data in a data storage device configured as a storage compute appliance. In some embodiments, the data storage device has a non-volatile memory (NVM) and a controller circuit. The NVM stores a plurality of data sets encrypted by at least one encryption key. The controller circuit performs a storage compute appliance process by locally decrypting the plurality of data sets in a local memory of the data storage device, generating summary results data from the decrypted data sets, and transferring the summary results data across the host interface to an authorized user without a corresponding transfer of any portion of the decrypted data sets across the host interface.