Storage Controller Namespace Exposure Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage devices and systems lack effective security measures to manage data access among multiple users, particularly in ensuring that sensitive data is not exposed to unauthorized users.

Innovation Solution

A storage device and system that utilizes a non-volatile memory with multiple namespaces and a storage controller to manage namespace exposure. The system allows for the setting of namespaces as hidden, preventing exposure to certain users, and includes authentication mechanisms to control access based on user permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If all namespaces are exposed to all users, then data accessibility is improved, but security deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The storage device divides namespaces into multiple categories (first namespaces accessible to all users, second namespaces accessible only to specific users, third namespaces inaccessible to users). This segmentation allows different access levels to be assigned to different data regions, enabling both broad accessibility for general data and restricted access for sensitive data, thus resolving the contradiction between data accessibility and security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If namespace exposure control is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidnamespace management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage device pre-establishes multiple namespace categories with defined access permissions before user operations begin. The namespace classification structure (first, second, and third namespaces) is prepared in advance, allowing the device to automatically apply appropriate access control policies without requiring complex real-time decision-making, thereby improving security while managing complexity through pre-defined rules.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The storage controller acts as an intermediary that automatically manages namespace exposure based on user authentication and namespace category. Instead of requiring complex user-configurable access control settings, the controller mediates all access requests by referencing the pre-defined namespace categories, simplifying the interface while maintaining strong security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication mechanisms are added, then data protection is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The storage device performs automatic authentication and namespace classification without requiring user intervention. When a user connects, the storage controller automatically authenticates the user, determines which namespace category applies, and enforces the appropriate access controls. This self-service approach maintains strong data protection while preserving ease of operation, as users simply need to connect their device without configuring security settings.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250094647A1Storage device and system
Publication Date: 2025.03.20 SAMSUNG ELECTRONICS CO LTD
  • US20250094647A1 patent drawing
  • US20250094647A1 patent drawing
  • US20250094647A1 patent drawing

AI summary

A storage device includes a non-volatile memory including a plurality of namespaces, and a storage controller configured to receive, from an external host, a first namespace identifier of a first namespace from among the plurality of namespaces and a first command requesting to control exposure of the first namespace, and based on the first namespace identifier and the first command, set the first namespace as a hidden namespace, and prevent the first namespace from being exposed to at least one user from among a plurality of users.