Storage Controller Hardware Acceleration for Block Certification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In edge computing architectures, validating the origin of storage blocks across different edge locations is challenging, leading to increased total cost of ownership (TCO) and latency due to software stack-based data hashing and signature management.
Innovation Solution
Implementing hardware accelerators to map service private keys to storage blocks, enabling automatic certification and validation of storage blocks at a fine granularity, thereby reducing reliance on the software stack for data signature and validation processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software stack-based data hashing and signature management is used to validate storage blocks, then data origin validation is achieved, but total cost of ownership and latency increase
Solution Approach 1:
The patent replaces software-based hashing and signature management with hardware-based cryptographic processing. The storage controller includes dedicated cryptographic hardware that performs data certification and validation operations in hardware, substituting the software stack's mechanical processing with faster hardware operations. This resolves the contradiction by maintaining data origin validation reliability while significantly reducing the time loss associated with software-based processing.
Solution Approach 2:
The patent introduces a storage controller as an intermediary component between the software stack and storage devices. This controller includes a data certification module that handles cryptographic operations, acting as a mediator that offloads validation tasks from the software stack to dedicated hardware. This intermediary approach maintains the reliability of data origin validation while reducing latency by preventing the software stack from being the bottleneck in validation operations.
2Reliability
If software stack-based signature management is used for data validation, then data certification is achieved, but total cost of ownership increases
Solution Approach 1:
The patent replaces complex software-based signature management with hardware-based cryptographic processing in the storage controller. The dedicated cryptographic hardware performs encryption, decryption, and validation operations that would otherwise require complex software implementations. This substitution maintains data certification reliability while reducing the overall system complexity by moving operations from the software stack to hardware.
Solution Approach 2:
The patent extracts cryptographic processing functions from the software stack and places them in dedicated hardware within the storage controller. By taking out the data certification and validation operations from the software layer and implementing them in hardware, the patent reduces software stack complexity while maintaining the reliability of data certification. The storage controller independently handles cryptographic operations without burdening the software stack.
3Loss of time
If hardware accelerators are used for block-level certification, then latency and TCO are reduced, but system complexity increases
Solution Approach 1:
The patent merges the cryptographic processing functions with the storage controller hardware, combining data certification capabilities directly into the storage management infrastructure. Rather than adding separate hardware accelerator components, the cryptographic functions are integrated into the existing storage controller architecture. This merging approach reduces latency by co-locating certification functions with storage operations while minimizing the increase in system complexity through integration rather than addition.
Solution Approach 2:
The storage controller is designed with multi-functionality, serving both storage management and cryptographic certification functions. The controller handles data I/O operations, data hashing, signature generation, and validation all within a single hardware unit. This universal design reduces latency by eliminating the need for separate hardware accelerators while managing complexity through consolidated functionality rather than distributed components.
Data Source
AI summary
An example apparatus includes a block manager to generate a map by mapping a group of storage blocks to a tenant using at least one of a tenant key identifier or an application key identifier, the group of storage blocks associated with a signature, the signature to validate the group of storage blocks, access a data access request for a first storage block, the data access request from a software stack, and perform a signature validation for the data access request based on the map of the group of storage blocks to the tenant. The example apparatus includes a migration handler to migrate data of the group of storage blocks and corresponding meta-data from a first storage device to a second storage device, the metadata including attestation data of the group of storage blocks.


