Programmable Storage Controller Logic for Secondary Storage Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies lack a simple and effective method to restrict CPU access to secondary storage, making it vulnerable to viruses and malicious programs, despite existing solutions like partitioning and virtual machines, which are either costly, inconvenient, or inefficient in preventing unauthorized access.
Innovation Solution
An independent programmable storage controller logic is interposed between the CPU and secondary storage, dividing it into virtual areas with customizable access permissions, using closed firmware and software to prevent unauthorized access by acting as a intermediary between the CPU and secondary storage, allowing access only through properly configured permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If partitioning secondary storage using operating system user interface is used, then data can be separated into sensitive and non-sensitive partitions, but the CPU still has access to all partitions and viruses can corrupt data
Solution Approach 1:
The patent introduces a storage controller as an intermediary device between the CPU and secondary storage. This controller enforces access policies by intercepting CPU access requests and granting or denying them based on predefined rules. The controller acts as a mediator that prevents viruses from corrupting critical data while still allowing legitimate CPU operations, thereby resolving the contradiction between data separation and virus protection.
2Reliability
If additional computers are used for secure secondary storage, then sensitive data can be isolated, but the cost and inconvenience increase significantly
Solution Approach 1:
The patent merges the functions of multiple separate storage systems into a single secondary storage device with integrated security controls. By combining sensitive and non-sensitive storage in one physical device while using a storage controller to enforce logical separation and access policies, the system achieves secure isolation without requiring multiple separate computers or storage devices, thereby reducing complexity while maintaining reliability.
3Reliability
If virtual machine software is installed to provide isolated computing environments, then access to logical addresses can be restricted, but CPU processing power requirements increase
Solution Approach 1:
The patent replaces the software-based virtual machine isolation mechanism with a hardware-based storage controller that enforces access policies. Instead of using CPU-intensive virtual machine software to manage access isolation, the system uses dedicated storage controller hardware to intercept and filter access requests at the hardware level. This substitution reduces CPU processing power consumption while maintaining effective access isolation and security.
Data Source
AI summary
Methods and apparatus for restricting access by one or more processors to an area of a secondary storage unit are presented herein. The methods and apparatus may comprise an independent programmable storage controller logic that divides a storage area of the secondary storage unit into at least a first area and a second area and controls usage of the areas as at least two virtual secondary storage units such that the processor(s) access the at least two virtual secondary storage units as if accessing at least two physical secondary storage units by selecting one of the at least two virtual secondary storage units as an active virtual secondary storage unit to provide the processor(s) access to the active virtual secondary storage unit based on a secondary storage unit configuration. Each virtual secondary storage unit may contain at least one region of which an access permission setting is modifiable.


