Distributed Storage Security Module with Attack Timing Randomization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed data storage systems are vulnerable to third-party attacks, which can compromise security, reliability, and performance due to increased computing capabilities and data flow complexities, necessitating intelligent security measures to mitigate sophisticated threats.

Innovation Solution

An attack module is connected to the distributed data storage system to detect and predict susceptibilities, generating proactive and reactive counter strategies that temporarily randomize execution timing of data access operations to prevent or mitigate third-party attacks, ensuring system security and integrity without degrading performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security measures are implemented to prevent third-party attacks, then system security is improved, but system performance may be degraded

Engineering Contradiction:
Improvesystem securityVSAvoiddata access performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts security measures based on real-time attack detection. When an attack is detected, the system activates enhanced security protocols (proactive action); when no attack is present, normal performance protocols are used. This dynamic adaptation allows the system to maintain high security when needed while preserving optimal performance during normal operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters such as data access timing, sequencing, and execution speed based on security conditions. By randomly adjusting these parameters when attacks are detected, the system prevents predictable attack patterns while maintaining functional correctness. This parameter transformation allows security enhancement without permanent performance loss.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If proactive security actions are taken to prevent attacks, then attack susceptibility is reduced, but system complexity increases

Engineering Contradiction:
Improveattack prevention capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-diagnosis and self-protection through integrated attack detection modules that automatically identify vulnerabilities and execute countermeasures. The attack module monitors system operations, detects attack patterns, and triggers appropriate responses without external intervention. This self-service capability reduces the need for complex external security infrastructure while maintaining high prevention effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security system is designed as a multi-functional integrated module that performs detection, analysis, and response functions within a single framework. The attack module handles multiple tasks including vulnerability identification, attack pattern recognition, and coordination of countermeasures, eliminating the need for separate specialized systems and reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If reactive security measures are implemented to mitigate attack impact, then damage reduction is improved, but response time is increased

Engineering Contradiction:
Improveattack impact mitigationVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system executes preliminary security actions by detecting attack susceptibilities and implementing countermeasures before actual attacks occur. The attack module continuously monitors system state, identifies potential vulnerabilities, and activates preventive protocols in advance. This preliminary action reduces the time needed for reactive response while still providing comprehensive attack impact mitigation capabilities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11736517B2Data storage device with security module
Publication Date: 2023.08.22 SEAGATE TECH LLC
  • US11736517B2 patent drawing
  • US11736517B2 patent drawing
  • US11736517B2 patent drawing

AI summary

A distributed data storage system can consist an attack module connected to distributed data storage system that has at least one host connected to a first data storage device and a second data storage device via a network controller. A susceptibility to a third-party attack in the distributed data storage system may be identified with the attack module, which prompts the generation of an attack counter strategy with the attack module. The attack counter strategy can have at least one proactive action directed at preventing a future third-party attack on the detected susceptibility that is executed prior to a third-party attack to temporarily randomize execution timing of a data access operation of the distributed data storage system.