Out-of-band Storage Security Appliance Configuration Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional storage security appliances fail to intercept and manage control traffic, leading to inefficiencies in updating configurations and encrypting new storage devices, as they are unaware of changes made to storage devices without prior administrator intervention.

Innovation Solution

A data security appliance intercepts out-of-band control traffic, analyzes it, and reconfigures itself according to the commands received, ensuring seamless communication and encryption with storage devices, even when new configurations are introduced.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security appliances only intercept data traffic and not control traffic, then data encryption is maintained, but the security appliance cannot automatically detect storage device configuration changes

Engineering Contradiction:
Improvedata encryptionVSAvoidconfiguration change detection
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security appliance is enhanced to perform multiple functions: it continues to intercept and encrypt data traffic while also intercepting control traffic to detect configuration changes. This multi-functionality allows a single device to maintain both data security and configuration awareness without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security appliance acts as an intermediary between the host and storage device, positioned to monitor both data traffic and control traffic. By intercepting control traffic containing configuration change notifications, the appliance gains awareness of storage device changes while still mediating data encryption, thus resolving the contradiction between maintaining encryption reliability and achieving configuration adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If administrators manually reconfigure security appliances after storage device changes, then configuration accuracy is maintained, but administrative burden and time consumption increase

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidreconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The security appliance implements a feedback mechanism by monitoring control traffic for configuration change notifications from storage devices. When changes are detected, the appliance automatically receives update information and reconfigures itself, eliminating the need for manual administrator intervention. This feedback loop maintains configuration accuracy while dramatically reducing reconfiguration time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The security appliance performs self-reconfiguration by automatically detecting configuration changes through control traffic interception and updating its own configuration parameters. This self-service capability eliminates the need for manual administrator reconfiguration, maintaining precision while reducing time loss to near-zero for automatic detection and update.

Inventive Principle:
Principle #25Self-service

3Productivity

If control traffic flows directly between host and storage device without passing through security appliance, then communication efficiency is improved, but security appliance cannot enforce encryption policies on new storage devices

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidencryption policy enforcement
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The traffic flow is segmented into two paths: control traffic flows through the security appliance for monitoring and detection, while data traffic continues to flow through the appliance for encryption. This segmentation allows control traffic to be inspected for configuration changes without disrupting the efficiency of data communication, while still enabling the appliance to enforce encryption policies on newly detected storage devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security appliance positions itself as an intermediary that control traffic must pass through, allowing it to detect configuration changes and enforce policies. By intercepting control traffic containing configuration change notifications, the appliance maintains awareness of storage device changes and can enforce encryption policies on new devices without significantly impacting communication efficiency, as the interception occurs at the protocol level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8387127B1Storage security appliance with out-of-band management capabilities
Publication Date: 2013.02.26 NETAPP INC
  • US8387127B1 patent drawing
  • US8387127B1 patent drawing
  • US8387127B1 patent drawing

AI summary

A data security appliance intercepts out-of-band control traffic directed to a data storage device, wherein the out-of-band control traffic includes a command to change a configuration of the data storage device. The data security appliance is reconfigured in accordance with the command in order to conform with a new configuration of the data storage device.