Programmable Storage Controller Logic for Secondary Storage Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack a simple and effective method to restrict CPU access to secondary storage, making it vulnerable to viruses and malicious programs, despite existing solutions like partitioning and virtual machines, which are either costly, inconvenient, or inefficient in preventing unauthorized access.

Innovation Solution

An independent programmable storage controller logic is interposed between the CPU and secondary storage, dividing it into virtual areas with customizable access permissions, using closed firmware and software to prevent unauthorized access by acting as a intermediary between the CPU and secondary storage, allowing access only through properly configured permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If partitioning secondary storage using operating system user interface is used, then data can be separated into sensitive and non-sensitive partitions, but the CPU still has access to all partitions and viruses can corrupt data

Engineering Contradiction:
Improvedata separation capabilityVSAvoiddata protection against viruses
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a storage controller as an intermediary device between the CPU and secondary storage. This controller enforces access policies by intercepting CPU access requests and granting or denying them based on predefined rules. The controller acts as a mediator that prevents viruses from corrupting critical data while still allowing legitimate CPU operations, thereby resolving the contradiction between data separation and virus protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional computers are used for secure secondary storage, then sensitive data can be isolated, but the cost and inconvenience increase significantly

Engineering Contradiction:
Improvesecure storage isolationVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functions of multiple separate storage systems into a single secondary storage device with integrated security controls. By combining sensitive and non-sensitive storage in one physical device while using a storage controller to enforce logical separation and access policies, the system achieves secure isolation without requiring multiple separate computers or storage devices, thereby reducing complexity while maintaining reliability.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If virtual machine software is installed to provide isolated computing environments, then access to logical addresses can be restricted, but CPU processing power requirements increase

Engineering Contradiction:
Improveaccess isolationVSAvoidCPU processing power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces the software-based virtual machine isolation mechanism with a hardware-based storage controller that enforces access policies. Instead of using CPU-intensive virtual machine software to manage access isolation, the system uses dedicated storage controller hardware to intercept and filter access requests at the hardware level. This substitution reduces CPU processing power consumption while maintaining effective access isolation and security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9372635B2Methods and apparatus for dividing secondary storage
Publication Date: 2016.06.21 ATI TECHNOLOGIES ULC
  • US9372635B2 patent drawing
  • US9372635B2 patent drawing
  • US9372635B2 patent drawing

AI summary

Methods and apparatus for restricting access by one or more processors to an area of a secondary storage unit are presented herein. The methods and apparatus may comprise an independent programmable storage controller logic that divides a storage area of the secondary storage unit into at least a first area and a second area and controls usage of the areas as at least two virtual secondary storage units such that the processor(s) access the at least two virtual secondary storage units as if accessing at least two physical secondary storage units by selecting one of the at least two virtual secondary storage units as an active virtual secondary storage unit to provide the processor(s) access to the active virtual secondary storage unit based on a secondary storage unit configuration. Each virtual secondary storage unit may contain at least one region of which an access permission setting is modifiable.