Storage Compute Appliance Internal Data Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In shared data storage environments, existing encryption schemes that use separate encryption keys for each data set complicate multi-user data analysis and increase the risk of inadvertent exposure of underlying data when performing calculations or searches across multiple data sets.
Innovation Solution
A data storage device is configured as a storage compute appliance with a controller circuit and non-volatile memory that internally decrypts and processes encrypted data sets to generate summary results, which are then transferred to an authorized user without revealing the underlying data, using a storage compute appliance key stored internally and not transmitted externally.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate encryption keys are used for each data set, then data security is improved, but device complexity and difficulty of data analysis increase
Solution Approach 1:
The system segments encryption keys into two distinct types: data set-specific keys stored by individual users for their own data protection, and a shared storage compute appliance key stored internally in the storage device. This segmentation allows users to maintain security for their individual data while enabling the storage device to perform centralized analysis operations on all encrypted data sets using the shared appliance key.
2Reliability
If separate encryption keys are used for each data set, then data security is improved, but productivity of multi-user data analysis decreases
Solution Approach 1:
The storage compute appliance key acts as an intermediary that enables the storage device to decrypt and analyze multiple users' encrypted data sets without requiring direct access to individual user keys. This intermediary mechanism allows centralized data analysis operations to be performed efficiently on all data sets while maintaining the security model where users retain control of their own encryption keys.
3Productivity
If encrypted data sets are transferred to host for analysis, then data analysis capability is improved, but risk of data exposure increases
Solution Approach 1:
Instead of transferring encrypted data to the host for decryption and analysis (which would expose data), the system inverts the process by bringing the decryption capability to the storage device itself. The storage compute appliance key enables the storage device to decrypt data locally and perform analysis operations on decrypted data within the secure storage environment, then return only analysis results to the host without exposing the underlying data.
4Ease of operation
If decrypted data is transferred across host interface, then data accessibility is improved, but security and data protection worsen
Solution Approach 1:
The system extracts only the necessary analysis results from the decrypted data while leaving the actual decrypted data sets within the secure storage device. The controller circuit generates summary results data from the decrypted data sets and transfers only these summary results across the host interface to authorized users, preventing exposure of the underlying decrypted data while still providing useful analysis output.
Data Source
AI summary
Method and apparatus for managing data in a data storage device configured as a storage compute appliance. In some embodiments, the data storage device has a non-volatile memory (NVM) and a controller circuit. The NVM stores a plurality of data sets encrypted by at least one encryption key. The controller circuit performs a storage compute appliance process by locally decrypting the plurality of data sets in a local memory of the data storage device, generating summary results data from the decrypted data sets, and transferring the summary results data across the host interface to an authorized user without a corresponding transfer of any portion of the decrypted data sets across the host interface.


