Storage Controller Dedicated Interface IaaS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Infrastructure as a Service (IaaS) systems face challenges in providing secure isolation of computing resources across points in time, as vulnerabilities in virtualization technologies and access control protocols can allow malicious customers to access data and processes belonging to other users, and dedicated physical equipment does not ensure isolation across time changes.

Innovation Solution

A computer system with a logic block and a controller that uses a dedicated physical interface to manage storage access, ensuring that only authorized users can read from and write to storage, and the controller can power-up or reset the logic block to maintain secure isolation between users, using a second computer system to identify the current user and manage storage locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtualisation technology is used to provide isolated virtual machines to multiple customers, then resource sharing and isolation at a point in time are improved, but security vulnerabilities may allow malicious customers to access other customers' data and processes

Engineering Contradiction:
Improveresource sharingVSAvoidsecurity isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments storage access by implementing separate dedicated physical interfaces for each logic block, dividing the storage system into isolated access paths. This segmentation ensures that even if one logic block is compromised, other blocks remain secure, resolving the contradiction between resource sharing and security isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The controller acts as an intermediary between logic blocks and storage, mediating all access requests. The controller enforces access control policies and verifies user authorization, preventing direct access that could lead to security vulnerabilities while maintaining efficient resource sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated physical equipment is allocated to each customer to provide stronger isolation, then security isolation at a point in time is improved, but isolation across points in time cannot be ensured as processes may persist

Engineering Contradiction:
Improvesecurity isolationVSAvoidisolation across time
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by resetting logic blocks before allocating them to new customers. This reset operation clears any persistent processes or data from the logic block, ensuring that isolation across time points is maintained. The controller manages this reset process as part of the customer allocation workflow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the controller monitors and tracks the state of logic blocks and storage access. This feedback enables the system to detect and respond to security issues, ensuring that isolation requirements are maintained across time points through continuous verification and control.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If shared storage facility is made accessible from multiple physical equipment, then data accessibility across different equipment is improved, but access control complexity increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidaccess control
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The controller implements a universal access control mechanism that handles multiple logic blocks and storage access scenarios through a single unified interface. This multi-functional approach simplifies access control by providing consistent security enforcement across different customers and equipment, reducing overall system complexity despite the shared storage architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If network storage protocols with access controls are implemented, then data security between customers is improved, but protocol complexity and security vulnerabilities increase

Engineering Contradiction:
Improvedata securityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the access control functionality from complex network storage protocols and implements it directly in the controller's dedicated physical interface layer. This extraction eliminates the need for complex protocol stacks and their associated security vulnerabilities, while maintaining strong data security through hardware-enforced access control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11294581B2Secure sharing of storage resources
Publication Date: 2022.04.05 GARRISON TECH
  • US11294581B2 patent drawing
  • US11294581B2 patent drawing
  • US11294581B2 patent drawing

AI summary

A computer system 100 that allows a storage facility 500 to be shared by multiple different users of an Infrastructure as a Services (IaaS) system while maintaining security separation between the users is provided. A controller 150 configured for use in the computer system and a corresponding method and computer program are also provided. The computer system 100 comprises a logic block 101 that comprises one or more processing units that execute instructions, the logic block 101 configured to issue requests to read from and write to storage over a first interface 102; and a controller 150 that is configured to implement a communications link to storage 500; implement a communications link 300 to a second computer system 200 and to receive information identifying a current user of the logic block 101 from the second computer system 200; and receive the requests to read from and write to storage from the logic block 101 over the first interface 102, and to complete the requests. The first interface 102 is a dedicated physical interface between the logic block 101 and the controller 150, whereby the controller 150 can determine that communications over the first interface 102 are communications with the logic block 101. The controller 150 is configured to complete the requests to read from and write to storage using one or more storage locations of the storage 500 that the current user of the logic block 101 identified by the second computer system 200 is permitted to use.