Submission Queue Stream IDs for Virtual Storage Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems using single-root input/output virtualization (SR-IOV) face challenges in managing access control, particularly in environments like gaming ecosystems, where namespace management is complex due to unpredictable data sizes and inefficient storage utilization.

Innovation Solution

Implementing a data storage device that provides access control by associating a submission queue with a stream identifier instead of a namespace, allowing flexible access control based on stream IDs without relying on SR-IOV, and using NVMe functionality to manage virtual functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SR-IOV and namespace management are used for access control, then virtualization and isolation are achieved, but device complexity and management overhead increase

Engineering Contradiction:
Improveaccess controlVSAvoidnamespace management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the access control functionality from the complex SR-IOV namespace management system and implements it through a simpler stream ID-based mechanism. The stream ID is associated directly with the submission queue, bypassing the need for namespace attachment and virtual function configuration, thereby maintaining access control while reducing device complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of attaching virtual functions to namespaces as in traditional SR-IOV, the patent inverts the approach by associating stream IDs directly with submission queues. This reversal eliminates the intermediate namespace layer and virtual function attachment process, simplifying the access control mechanism while maintaining security

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If namespaces are used for storage allocation, then virtual machine isolation is achieved, but storage utilization efficiency decreases due to unpredictable data sizes

Engineering Contradiction:
Improvevirtual machine isolationVSAvoidstorage utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the parameter used for storage allocation from fixed namespace boundaries to dynamic stream ID-based allocation. Submission queues are allocated based on actual data needs rather than predetermined namespace sizes, allowing storage to be dynamically adjusted to match unpredictable data sizes and improving overall storage utilization while maintaining isolation through stream ID verification

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional namespace-based access control is implemented, then security is maintained, but access control flexibility decreases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic access control through stream IDs that can be flexibly assigned and reassigned to different submission queues without requiring namespace recreation or virtual function reconfiguration. The stream ID verification mechanism maintains security while allowing rapid adaptation to changing access requirements, improving flexibility compared to static namespace-based control

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12619384B2Data storage device and method for access control based on a stream identifier of a virtual function
Publication Date: 2026.05.05 SANDISK TECHNOLOGIES LLC
  • US12619384B2 patent drawing
  • US12619384B2 patent drawing
  • US12619384B2 patent drawing

AI summary

A data storage device with access control based on stream identifier for virtual environment is provided. In one embodiment, a method is provided that is performed in a host in communication with a data storage device comprising a memory. The method comprises identifying an available submission queue; deleting the submission queue; recreating the submission queue; assigning the virtual machine to a virtual function; assigning the recreated submission queue with the virtual function; and informing the data storage device that the recreated submission queue is attached to a stream identifier, wherein the stream identifier is associated with a virtual machine. Other embodiments are provided.