Unattended Storage Update via Certificate Authentication and State Machine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional strategies for updating storage facilities require extensive on-site and remote support personnel, leading to high resource expenditures and security concerns in ensuring the integrity and validity of updates.

Innovation Solution

A mechanism for updating storage facilities using a certificate authentication mechanism for security verification and a fixed state machine for safety verification, allowing for unattended updates by minimizing the need for on-site and remote support personnel, and utilizing a management server or direct application of updates to ensure code integrity and protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If conventional update strategies are used, then updates can be performed on storage facilities, but extensive on-site and remote support personnel are required, leading to high resource expenditures

Engineering Contradiction:
Improveupdate automationVSAvoidsupport personnel time
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The storage facility performs self-diagnosis and self-update by automatically detecting updateable elements, verifying update images, and applying updates without requiring on-site or remote support personnel. The system uses its own service processor and management software to manage the entire update process autonomously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Update images are pre-verified and prepared before being deployed to the storage facility. The system performs preliminary verification of update images against the facility's configuration and status before actual installation, ensuring readiness and preventing failures during the update process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If conventional update strategies are used, then updates can be installed, but security concerns arise regarding the integrity and validity of updates

Engineering Contradiction:
Improveupdate securityVSAvoidverification mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a feedback mechanism where the service processor continuously monitors the storage facility's status, compares it against expected states, and verifies update integrity. After each update step, the system feedback-checks the results and can roll back if verification fails, ensuring security without excessive complexity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs beforehand verification of update images against the facility's current configuration and status before applying updates. This preventive verification cushions against potential security issues by ensuring updates are compatible and valid before installation, reducing the need for complex ongoing verification mechanisms.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Productivity

If updates are performed on storage facilities, then new features and fixes are applied, but the update process impacts other servers and computing components

Engineering Contradiction:
Improveupdate efficiencyVSAvoidservice continuity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The update process is segmented into independent updateable elements (disks, enclosures, power supplies, etc.), each with its own update image and verification process. This allows selective updating of individual components without disrupting the entire storage facility or other servers, maintaining service continuity while improving update efficiency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8782413B2Unattended code update of storage facility
Publication Date: 2014.07.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8782413B2 patent drawing
  • US8782413B2 patent drawing
  • US8782413B2 patent drawing

AI summary

Various embodiments for providing an update to at least one storage facility in a computing storage environment are provided. In one embodiment, media is received in one or more updatable elements of one or more components of the at least one storage facility, each of the one or more updatable elements including one or more unique update images and one or more unique update commands, a security verification is performed on the update via a certificate authentication mechanism to confirm a validity of the update, a safety verification is performed on the update to confirm a suitability of the update to the at least one storage facility, the update is installed in the at least one storage facility, and the update in the at least one storage facility is processed by traversing a fixed state machine for each updatable element.