Storage Controller Metadata Data Protection Directives

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber resiliency measures for enterprise data lack effective techniques to detect malicious and unauthorized access, relying heavily on separate anti-virus software that can impact system performance and are susceptible to interference.

Innovation Solution

Incorporating data protection directives into metadata managed by the storage controller's operating system, which processes these directives to determine whether to allow access to data in cache, thereby preventing malicious access and protecting data from corruption or propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate anti-virus software is deployed to detect malicious access, then detection capability is improved, but system performance deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines data protection directives and access control functionality directly into the metadata management system of the storage controller. By merging security verification into the existing metadata processing path, the system achieves malicious access detection without requiring separate anti-virus software, thus avoiding performance degradation from additional external security layers.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The metadata system is enhanced to serve multiple functions: traditional storage management tasks plus data protection directive enforcement. The metadata now universally handles both operational control and security verification, eliminating the need for dedicated security software while maintaining detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate anti-virus software is used for data protection, then detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security functionality into the existing storage controller metadata system, eliminating the need for separate anti-virus software components. This consolidation reduces device complexity by removing redundant security layers while maintaining detection capability through integrated data protection directives.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If separate anti-virus software is deployed, then detection capability is improved, but susceptibility to interference increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsusceptibility to interference
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By integrating data protection directives into the core metadata management system, the patent creates a unified security architecture that is harder to interfere with. The merged system eliminates attack surfaces associated with separate anti-virus software interfaces and communication protocols, reducing susceptibility to interference while maintaining detection capability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240394420A1Processing data protection directives in metadata to determine whether to allow access to data in cache
Publication Date: 2024.11.28 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20240394420A1 patent drawing
  • US20240394420A1 patent drawing
  • US20240394420A1 patent drawing

AI summary

Provided are a computer program product, system, and method for processing data protection directives in metadata to determine whether to allow access to data in cache. A data protection directive is received, from the host, indicating a data subset, an access request type, and a protective action with respect to the access request type for the data subset. The data protection directive is stored in metadata for the data subset. In response to an access request to a requested data subset, determining a data protection directive in metadata for the requested data subset. Determining whether the access request comprises an access request type in the determined data protection directive. A protective action specified in the determined data protection directive is processed to determine whether to allow the access request access to the requested data subset in response to determining that the access request is of the access request type.