Storage Controller Direct Access Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer storage systems with multiple controllers face challenges in enabling direct and secure access control for hosts to shared physical storage spaces, particularly in managing encrypted data and ensuring granular access while maintaining data confidentiality.

Innovation Solution

The system employs control computer devices to manage direct read and write access by transmitting metadata, including physical locations and encryption keys, to host devices, utilizing a key derivation scheme based on base keys and logical block addresses, enabling hosts to decrypt and write data securely within the shared storage space.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If hosts directly access shared physical storage space, then storage system performance is improved, but data security and access control become compromised

Engineering Contradiction:
Improvestorage system performanceVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the storage system into multiple storage controllers, each responsible for specific storage areas. This segmentation allows direct host access to be controlled at the controller level, enabling performance improvement through direct access while maintaining security through distributed control and authorization management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Storage controllers act as intermediaries between hosts and the shared physical storage space. The controllers receive access requests from hosts, verify authorization, and manage data access accordingly. This intermediary role enables hosts to indirectly access storage with improved performance while the controller maintains security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are stored with metadata for direct access, then data confidentiality is improved, but key management complexity increases

Engineering Contradiction:
Improvedata confidentialityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges encryption key management with metadata management in the storage controllers. Keys are stored alongside data metadata, allowing unified management of both data location and decryption information. This combination improves confidentiality by ensuring keys are available only through authorized controller access while managing complexity through integrated rather than separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Different storage controllers have different key management capabilities and responsibilities based on their assigned storage areas. Each controller manages keys locally for its jurisdiction, allowing simplified local key management while maintaining overall system confidentiality through distributed key custody.

Inventive Principle:
Principle #3Local quality

3Reliability

If granular access control is implemented for encrypted data, then data security is improved, but access control mechanism complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements granular access control by segmenting authorization management at the storage controller level. Each controller manages access permissions for its assigned storage areas independently, enabling fine-grained security control without requiring a monolithic complex access control system spanning the entire storage infrastructure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11036652B2Secured access control in a storage system
Publication Date: 2021.06.15 THE SILK TECH ILC LTD
  • US11036652B2 patent drawing
  • US11036652B2 patent drawing
  • US11036652B2 patent drawing

AI summary

The presently disclosed subject matter includes various inventive aspects, which are directed to direct access of a host computer device to a share storage space in a storage system, as well as secured access control of the direct access of the host computer device by a control computer device in the storage system, the direct access including direct read access and direct write access.