Storage Equipment Trusted Connectivity Using Temporary Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data storage systems face issues with inconsistent and insecure connectivity, leading to communication difficulties, vulnerability to hacking, and limited remote management capabilities.
Innovation Solution
Establishing trusted connectivity between storage equipment and a data center through a registration process using temporary credentials, followed by zero trust connectivity to ensure secure and reliable operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional connectivity is established between storage equipment and remote entities, then basic communication capability is achieved, but security is compromised and communication reliability deteriorates
Solution Approach 1:
The system performs preliminary authentication and credential verification before establishing the connectivity channel. The connectivity client obtains temporary credentials and undergoes authentication with the data center before the actual communication channel is created, ensuring security is built into the foundation of the connection rather than added later.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism using temporary credentials and certificates that mediate between the storage equipment and remote entities. This intermediary layer verifies identities and establishes trusted relationships before allowing direct communication, preventing unauthorized access while enabling legitimate connections.
2Reliability
If consistent and secure connectivity is established through registration and temporary credentials, then security and communication reliability are improved, but system complexity increases
Solution Approach 1:
The connectivity client is designed as a universal component that handles multiple functions including authentication, credential management, and connection establishment within a single integrated module. This multi-functional approach consolidates what could be separate complex processes into one cohesive client that manages the entire connectivity lifecycle.
Solution Approach 2:
The system implements self-service mechanisms where the connectivity client automatically obtains temporary credentials, performs authentication, and establishes connections without requiring manual intervention. The client autonomously manages its own security credentials and connection state, reducing operational complexity despite the sophisticated security protocol.
3Object-affected harmful factors
If trusted connectivity with zero trust architecture is implemented, then security against hacking is significantly improved, but ease of operation decreases
Solution Approach 1:
The zero trust connectivity system operates autonomously through the connectivity client that automatically manages authentication, credential validation, and connection maintenance. This self-service capability eliminates the need for manual security configuration and allows remote entities to manage storage equipment seamlessly without understanding the underlying security complexity.
Solution Approach 2:
The patent uses an intermediary connectivity client that shields remote entities from the complexity of zero trust authentication. The client handles all security protocols, certificate validations, and credential exchanges as an intermediary layer, presenting a simple interface to remote users while implementing robust zero trust security in the background.
Data Source
AI summary
Techniques to operate storage equipment involve, in response to a startup command, registering the storage equipment as an untrusted client at a data center through first connectivity between a connectivity client embedded within the storage equipment and the data center. The connectivity client obtains a set of temporary credentials while registering. The techniques further involve establishing second connectivity between the connectivity client and the data center based on the set of temporary credentials, the second connectivity providing stronger security than the first connectivity. The techniques further involve, after establishing the second connectivity between the connectivity client and the data center, providing trusted communications between the connectivity client and the data center through the second connectivity to manage the storage equipment.


