Storage Server Session Security Bypass for Performance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage systems face a trade-off between security and performance, as the use of third-party antivirus software to prevent malicious operations decreases access performance due to additional operations and network traffic generated for virus detection.

Innovation Solution

A method where a storage server determines, based on client attribute information, whether a session is subjected to antivirus protection, thereby omitting unnecessary virus detection and improving performance while ensuring security by leveraging local antivirus software on the client.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If third-party antivirus software is used to identify and eliminate viruses, then security of the storage system is improved, but access performance of the storage system deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating security handling based on client characteristics. Trusted clients (with attribute information indicating security reliability) bypass antivirus scanning, while untrusted clients undergo full virus detection. This selective approach optimizes performance for reliable clients while maintaining security for potentially malicious ones, resolving the contradiction between universal security and overall system performance.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The storage server performs preliminary verification of client attribute information before processing data access requests. By pre-establishing trust relationships and security credentials, the system can quickly determine whether antivirus scanning is necessary, avoiding repeated security checks and reducing access latency for authenticated clients.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If antivirus scanning is performed on all access requests, then security coverage is improved, but network traffic and processing overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork traffic and processing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system applies different security processing levels to different clients based on their attribute information. Trusted clients receive expedited processing without antivirus scanning, while untrusted clients undergo comprehensive security checks. This differentiated approach reduces overall network traffic and processing overhead while maintaining adequate security coverage through selective scanning.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of applying full antivirus scanning to all clients, the system applies partial action by performing security verification only on untrusted clients. This reduces unnecessary processing overhead and network traffic for clients whose security status is already confirmed through attribute information, while maintaining security coverage for potentially malicious clients.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11595386B2Method, electronic device and computer program product for storage management
Publication Date: 2023.02.28 EMC IP HLDG CO LLC
  • US11595386B2 patent drawing
  • US11595386B2 patent drawing
  • US11595386B2 patent drawing

AI summary

Techniques for storage management involve: receiving, at a storage server, an access request for target data from a client, wherein the access request occurs in a session between the storage server and the client; determining, based on attribute information of the client, security information of the session, wherein the security information indicates whether the session is subjected to antivirus protection; and executing, based on the security information, an access operation specified by the access request on the target data. Therefore, the performance of the storage server can be improved while the security of the storage server is ensured.