Storage Gateway Security Model for Remote Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of managing large-scale computing resources in data centers, particularly in provisioning, administration, and storage solutions, has led to high administrative and hardware costs, necessitating a more efficient and scalable approach for data storage and access.

Innovation Solution

A storage gateway is implemented as a virtual or physical appliance that acts as an interface between a customer's data center and a remote storage service, providing standard data access interfaces, converting data accesses into storage service requests, and transferring data over a network using Web service interfaces, thereby offering scalable and cost-effective remote storage solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share computing resources, then resource efficiency and security are improved, but system complexity increases

Engineering Contradiction:
Improveresource efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

A storage gateway is introduced as an intermediary device between customers' data centers and remote storage services. The gateway handles virtualization complexity internally while presenting simplified interfaces to customers, enabling resource sharing without increasing their operational burden. This mediator approach allows multiple customers to share storage infrastructure while maintaining isolation and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If storage resources are centralized in remote data centers, then hardware costs are reduced, but access latency increases

Engineering Contradiction:
Improvehardware costsVSAvoidaccess latency
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The storage system is segmented into local caching components at the gateway and remote centralized storage. Frequently accessed data is cached locally to reduce latency, while less frequently accessed data is stored remotely to reduce hardware costs. This segmentation allows the system to optimize for different access patterns and cost requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The storage gateway performs preliminary actions by caching frequently accessed data locally before it is needed by applications. This pre-positioning of data reduces access latency when applications need the data, while still maintaining the cost benefits of remote storage for less frequently accessed data.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If storage gateway initiates connections to service provider, then security is improved, but connection establishment complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidconnection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage gateway performs self-service by initiating its own connections to the service provider and managing its own authentication and communication. This self-initiated approach enhances security by ensuring the gateway controls its own communication channels, while the gateway's automated capabilities reduce the complexity burden on administrators.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9203801B1Storage gateway security model
Publication Date: 2015.12.01 AMAZON TECH INC
  • US9203801B1 patent drawing
  • US9203801B1 patent drawing
  • US9203801B1 patent drawing

AI summary

Methods, apparatus, and computer-accessible storage media for implementing a gateway to a remote service provider according to a security model. The gateway serves as an interface between processes on a customer network and the provider, for example to store customer data to a remote data store. The model may include an activation process initiated by the gateway to register with the provider and associate the gateway with a customer account; the gateway is provided with security credentials. The model may also include establishing secure connections to external processes, for example processes of the service provider. The gateway initiates connections; the external processes do not initiate connections. The model may also include the customer managing the gateway through the service provider. The model may also include encrypting communications between the gateway and the provider and the gateway including security credentials in communications to the provider.