Storage Controller Hardware Acceleration for Block Certification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In edge computing architectures, validating the origin of storage blocks across different edge locations is challenging, leading to increased total cost of ownership (TCO) and latency due to software stack-based data hashing and signature management.

Innovation Solution

Implementing hardware accelerators to map service private keys to storage blocks, enabling automatic certification and validation of storage blocks at a fine granularity, thereby reducing reliance on the software stack for data signature and validation processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software stack-based data hashing and signature management is used to validate storage blocks, then data origin validation is achieved, but total cost of ownership and latency increase

Engineering Contradiction:
Improvedata origin validationVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces software-based hashing and signature management with hardware-based cryptographic processing. The storage controller includes dedicated cryptographic hardware that performs data certification and validation operations in hardware, substituting the software stack's mechanical processing with faster hardware operations. This resolves the contradiction by maintaining data origin validation reliability while significantly reducing the time loss associated with software-based processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a storage controller as an intermediary component between the software stack and storage devices. This controller includes a data certification module that handles cryptographic operations, acting as a mediator that offloads validation tasks from the software stack to dedicated hardware. This intermediary approach maintains the reliability of data origin validation while reducing latency by preventing the software stack from being the bottleneck in validation operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software stack-based signature management is used for data validation, then data certification is achieved, but total cost of ownership increases

Engineering Contradiction:
Improvedata certificationVSAvoidsoftware stack complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex software-based signature management with hardware-based cryptographic processing in the storage controller. The dedicated cryptographic hardware performs encryption, decryption, and validation operations that would otherwise require complex software implementations. This substitution maintains data certification reliability while reducing the overall system complexity by moving operations from the software stack to hardware.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent extracts cryptographic processing functions from the software stack and places them in dedicated hardware within the storage controller. By taking out the data certification and validation operations from the software layer and implementing them in hardware, the patent reduces software stack complexity while maintaining the reliability of data certification. The storage controller independently handles cryptographic operations without burdening the software stack.

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of time

If hardware accelerators are used for block-level certification, then latency and TCO are reduced, but system complexity increases

Engineering Contradiction:
ImprovelatencyVSAvoidhardware complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent merges the cryptographic processing functions with the storage controller hardware, combining data certification capabilities directly into the storage management infrastructure. Rather than adding separate hardware accelerator components, the cryptographic functions are integrated into the existing storage controller architecture. This merging approach reduces latency by co-locating certification functions with storage operations while minimizing the increase in system complexity through integration rather than addition.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The storage controller is designed with multi-functionality, serving both storage management and cryptographic certification functions. The controller handles data I/O operations, data hashing, signature generation, and validation all within a single hardware unit. This universal design reduces latency by eliminating the need for separate hardware accelerators while managing complexity through consolidated functionality rather than distributed components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12099636B2Methods, systems, articles of manufacture and apparatus to certify multi-tenant storage blocks or groups of blocks
Publication Date: 2024.09.24 INTEL CORP
  • US12099636B2 patent drawing
  • US12099636B2 patent drawing
  • US12099636B2 patent drawing

AI summary

An example apparatus includes a block manager to generate a map by mapping a group of storage blocks to a tenant using at least one of a tenant key identifier or an application key identifier, the group of storage blocks associated with a signature, the signature to validate the group of storage blocks, access a data access request for a first storage block, the data access request from a software stack, and perform a signature validation for the data access request based on the map of the group of storage blocks to the tenant. The example apparatus includes a migration handler to migrate data of the group of storage blocks and corresponding meta-data from a first storage device to a second storage device, the metadata including attestation data of the group of storage blocks.