Storage Controller Direct Access Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer storage systems with multiple controllers face challenges in enabling direct and secure access control for hosts to shared physical storage spaces, particularly in managing encrypted data and ensuring granular access while maintaining data confidentiality.
Innovation Solution
The system employs control computer devices to manage direct read and write access by transmitting metadata, including physical locations and encryption keys, to host devices, utilizing a key derivation scheme based on base keys and logical block addresses, enabling hosts to decrypt and write data securely within the shared storage space.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If hosts directly access shared physical storage space, then storage system performance is improved, but data security and access control become compromised
Solution Approach 1:
The patent segments the storage system into multiple storage controllers, each responsible for specific storage areas. This segmentation allows direct host access to be controlled at the controller level, enabling performance improvement through direct access while maintaining security through distributed control and authorization management.
Solution Approach 2:
Storage controllers act as intermediaries between hosts and the shared physical storage space. The controllers receive access requests from hosts, verify authorization, and manage data access accordingly. This intermediary role enables hosts to indirectly access storage with improved performance while the controller maintains security controls.
2Reliability
If encryption keys are stored with metadata for direct access, then data confidentiality is improved, but key management complexity increases
Solution Approach 1:
The patent merges encryption key management with metadata management in the storage controllers. Keys are stored alongside data metadata, allowing unified management of both data location and decryption information. This combination improves confidentiality by ensuring keys are available only through authorized controller access while managing complexity through integrated rather than separate systems.
Solution Approach 2:
Different storage controllers have different key management capabilities and responsibilities based on their assigned storage areas. Each controller manages keys locally for its jurisdiction, allowing simplified local key management while maintaining overall system confidentiality through distributed key custody.
3Reliability
If granular access control is implemented for encrypted data, then data security is improved, but access control mechanism complexity increases
Solution Approach 1:
The patent implements granular access control by segmenting authorization management at the storage controller level. Each controller manages access permissions for its assigned storage areas independently, enabling fine-grained security control without requiring a monolithic complex access control system spanning the entire storage infrastructure.
Data Source
AI summary
The presently disclosed subject matter includes various inventive aspects, which are directed to direct access of a host computer device to a share storage space in a storage system, as well as secured access control of the direct access of the host computer device by a control computer device in the storage system, the direct access including direct read access and direct write access.


