Storage Server Session Security Bypass for Performance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage systems face a trade-off between security and performance, as the use of third-party antivirus software to prevent malicious operations decreases access performance due to additional operations and network traffic generated for virus detection.
Innovation Solution
A method where a storage server determines, based on client attribute information, whether a session is subjected to antivirus protection, thereby omitting unnecessary virus detection and improving performance while ensuring security by leveraging local antivirus software on the client.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party antivirus software is used to identify and eliminate viruses, then security of the storage system is improved, but access performance of the storage system deteriorates
Solution Approach 1:
The patent applies local quality by differentiating security handling based on client characteristics. Trusted clients (with attribute information indicating security reliability) bypass antivirus scanning, while untrusted clients undergo full virus detection. This selective approach optimizes performance for reliable clients while maintaining security for potentially malicious ones, resolving the contradiction between universal security and overall system performance.
Solution Approach 2:
The storage server performs preliminary verification of client attribute information before processing data access requests. By pre-establishing trust relationships and security credentials, the system can quickly determine whether antivirus scanning is necessary, avoiding repeated security checks and reducing access latency for authenticated clients.
2Reliability
If antivirus scanning is performed on all access requests, then security coverage is improved, but network traffic and processing overhead increase
Solution Approach 1:
The system applies different security processing levels to different clients based on their attribute information. Trusted clients receive expedited processing without antivirus scanning, while untrusted clients undergo comprehensive security checks. This differentiated approach reduces overall network traffic and processing overhead while maintaining adequate security coverage through selective scanning.
Solution Approach 2:
Instead of applying full antivirus scanning to all clients, the system applies partial action by performing security verification only on untrusted clients. This reduces unnecessary processing overhead and network traffic for clients whose security status is already confirmed through attribute information, while maintaining security coverage for potentially malicious clients.
Data Source
AI summary
Techniques for storage management involve: receiving, at a storage server, an access request for target data from a client, wherein the access request occurs in a session between the storage server and the client; determining, based on attribute information of the client, security information of the session, wherein the security information indicates whether the session is subjected to antivirus protection; and executing, based on the security information, an access operation specified by the access request on the target data. Therefore, the performance of the storage server can be improved while the security of the storage server is ensured.


