Customizable Storage Controller Firewall for Zero-Day Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network and PC defensive mechanisms are inadequate in preventing malware infections, as new threats emerge frequently, and existing security technologies cannot reliably prevent zero-day attacks, leading to vulnerabilities in data security and system integrity.

Innovation Solution

An improved storage firewall architecture that provides application and user authentication, monitors storage access requests, encrypts data and software, and manages patches through a secure synchronization link, offering server-based system administration to prevent malware penetration and detect anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network firewalls and anti-virus software are used, then basic network perimeter protection is provided, but they cannot prevent zero-day attacks and malware infections

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidvulnerability to malware and zero-day attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides security protection into multiple layers: network perimeter firewall, host-based storage firewall, and application authentication. Each layer handles specific security tasks, creating a distributed defense architecture that prevents single-point failures and provides comprehensive protection against various attack vectors including zero-day threats

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The storage firewall performs preliminary authentication and authorization checks before allowing storage access operations. Applications must be registered and authenticated in advance, and the storage firewall maintains a whitelist of authorized applications, preventing unauthorized access before malware can execute harmful operations

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive security monitoring and authentication mechanisms are implemented, then security protection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidsecurity system architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage firewall acts as an intermediary layer between applications and the storage subsystem. It intercepts storage access requests, performs authentication and authorization checks, and forwards legitimate requests to the storage device. This mediator approach centralizes security logic and simplifies the overall architecture by providing a single point of control for storage security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The storage firewall provides multiple security functions within a single system: authentication of applications, authorization of storage operations, encryption/decryption of data, and monitoring of storage access patterns. This multi-functional design reduces the need for separate security components and lowers overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9455955B2Customizable storage controller with integrated F+ storage firewall protection
Publication Date: 2016.09.27 FETIK RICHARD
  • US9455955B2 patent drawing
  • US9455955B2 patent drawing
  • US9455955B2 patent drawing

AI summary

A Customizable Storage Controller (CSC) is a software defined storage device controller, a replacement for the ASIC storage controller approach that has been used up to now. The differences from the current storage controllers are that the CSC software will need to be protected from unauthorized modification and provides an excellent place to add additional storage management functionality. The CSC type of storage controller is a good place to integrate the F+ Storage Firewall storage protection technology, fitting the needs of the CSC as well as protecting stored data from unauthorized access. This portion of the larger patent disclosure provides the design of a CSC both with a software version of a F+ Storage Firewall, as well as an improved (more secure) CSC designed with a security co-processor and locked firmware. These designs can be implemented with standard parts such as microprocessors and/or FPGAs (Field Programmable Gate Arrays), RAM (Random Access Memory), and some version of nonvolatile memory as a program store.