Storage System Security via Dual Controller Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional storage systems face inefficiencies in data management and security, particularly in detecting and responding to potential security threats, and in optimizing storage operations across multiple flash drives without redundant processes.

Innovation Solution

The implementation of a storage system architecture that includes dual storage array controllers with primary and secondary status, utilizing non-volatile random access memory (NVRAM) for quick data buffering, and employing erasure coding and mirroring schemes to ensure data redundancy and availability, along with proactive data rebuilding across storage nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional storage systems are used with single controller architecture, then device complexity is lower, but reliability and threat detection capability deteriorate

Engineering Contradiction:
Improvestorage system reliabilityVSAvoidcontroller architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage system is divided into multiple independent controllers (first controller and second controller), each capable of autonomous operation. This segmentation allows the system to maintain functionality even when one controller fails or is compromised, thereby improving reliability without requiring a complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system proactively detects potential security threats and performance issues before they manifest as actual failures. By monitoring metrics such as I/O operations, response times, and error rates in advance, the system can take preventive actions like switching controllers or isolating problematic components, thus improving reliability through early intervention.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If redundant data management processes are implemented across multiple flash drives, then data availability is improved, but productivity and operational efficiency deteriorate

Engineering Contradiction:
Improvedata availabilityVSAvoidstorage operation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Multiple flash drives are merged into a unified storage pool managed by the dual-controller architecture. Data is distributed across these drives using erasure coding, which combines data fragments with parity information. This merging approach provides redundancy and high availability while improving efficiency compared to traditional replication methods, as erasure coding requires less storage overhead and enables more flexible data retrieval.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If proactive threat detection and response mechanisms are implemented, then security reliability is improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage system implements continuous monitoring of operational metrics, error rates, and access patterns to detect potential security threats. The dual-controller architecture enables cross-validation of operations, where each controller can verify the other's actions. This feedback mechanism improves security detection capability while keeping complexity manageable through automated response protocols.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system automatically responds to detected threats without requiring manual intervention. When a security threat or failure is detected, the system can autonomously switch between controllers, isolate compromised components, or initiate data recovery procedures. This self-service capability improves security reliability while minimizing the operational overhead that would otherwise be required for manual threat response.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11755751B2Modify access restrictions in response to a possible attack against data stored by a storage system
Publication Date: 2023.09.12 PURE STORAGE INC
  • US11755751B2 patent drawing
  • US11755751B2 patent drawing
  • US11755751B2 patent drawing

AI summary

An illustrative method includes a data protection system determining that data stored by a storage system is under a possible attack, detecting a modify request with respect to the storage system while the data stored by the storage system is under the possible attack, determining that the modify request may be related to the possible attack, and performing, in response to determining that the modify request may be related to the possible attack, a remedial action with respect to the modify request.