Storage System Management Processor Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management server computer's communication with the storage apparatus is vulnerable to external attacks due to its exposure via the communication network.

Innovation Solution

A storage system with a management server computer and a storage apparatus, where the management server generates encrypted messages for I/O processors, which are then decrypted and executed by a management processor to ensure secure communication within the storage apparatus, isolating the I/O processors from external threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the management server computer communicates directly with the storage apparatus via the communication network, then management and control functions can be performed, but the communication is exposed to external attacks

Engineering Contradiction:
Improvemanagement control functionVSAvoidexternal attack exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a management processor as an intermediary component within the storage apparatus that receives encrypted management commands from the management server computer, decrypts them, and then routes them to the appropriate I/O processors. This intermediary layer isolates the I/O processors from direct external communication, allowing management functions to be performed while blocking external attack vectors from reaching the core processing units.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the communication architecture into multiple isolated networks: a first network for management communication between the management server and management processor, and a second network for I/O operations between I/O processors and storage devices. This segmentation separates management traffic from data operations, allowing secure management communication while protecting the I/O processing path from external threats.

Inventive Principle:
Principle #1Segmentation

2Productivity

If the management server computer sends commands directly to I/O processors, then I/O operations can be controlled, but security is compromised

Engineering Contradiction:
ImproveI/O operation controlVSAvoidcommunication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The management processor serves as a mandatory intermediary that all management commands must pass through. It receives encrypted commands from the management server, decrypts them using secure keys, identifies the target I/O processor, and forwards the decrypted command through the isolated second network. This ensures that I/O operations can be controlled efficiently while maintaining security through the intermediary decryption and routing function.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a dimensional layer of security by introducing encryption and decryption operations as a separate processing dimension. Management commands are encrypted in the first network dimension, transmitted securely, then decrypted in the management processor before being routed to I/O processors in the second network dimension. This dimensional transformation ensures security is embedded in the communication architecture itself.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10671555B2Storage system and storage apparatus
Publication Date: 2020.06.02 HITACHI VANTARA LTD
  • US10671555B2 patent drawing
  • US10671555B2 patent drawing
  • US10671555B2 patent drawing

AI summary

A storage system has a management server computer and a storage apparatus. The storage apparatus has a management processor connected to a management server computer via a first network, and a plurality of I/O processors that are connected to the management processor via a second network, that are connected to a storage device, and that conduct I/O with the storage device. The management server computer generates a command for any I/O processor of the plurality of I/O processors. The management server computer encapsulates and encrypts the command to generate an encrypted message, and sends the encrypted message to the management processor. The management processor receives the encrypted message and selects an I/O processor of the plurality of I/O processors as a first address on the basis of the command; and decrypts and undoes the encapsulation of the message to restore the command, and sends the command to the first address.