Switch-Based Logical Partitioning for Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data storage systems lack effective security mechanisms to prevent unauthorized access and data contamination when service devices diagnose or service the system, potentially disrupting host device operations and introducing malicious data.

Innovation Solution

A method and apparatus that utilize a switch to create isolated communications paths between user and service devices, preventing access and data exchange through a virtual local area network, ensuring secure access and minimizing the risk of data contamination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single access port is used for both host devices and service devices, then device complexity is reduced, but host device access is disrupted when service is required

Engineering Contradiction:
Improveaccess port configurationVSAvoidhost device access continuity
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments the access port functionality by implementing a switch that can create separate communication paths for host devices and service devices. The switch divides the single physical access port into multiple logical paths, allowing simultaneous independent access for both hosts and service personnel without disruption.

Inventive Principle:
Principle #1Segmentation

2Productivity

If two separate access ports are provided for host and service devices, then host device access continuity is maintained, but security risk increases due to potential unauthorized access

Engineering Contradiction:
Improvehost device access continuityVSAvoidunauthorized access and data contamination
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a switch as an intermediary device between host devices and service devices. This intermediary controls and manages communication paths, allowing the service device to access the storage system while preventing direct access to host devices. The switch acts as a security gatekeeper that mediates all communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If no security mechanisms are implemented between ports, then ease of operation is improved for service personnel, but data security and system integrity are compromised

Engineering Contradiction:
Improveservice device accessVSAvoiddata security and system integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic port isolation through the switch, which can adaptively control communication paths based on operational needs. The isolation is not static but dynamically managed, allowing service personnel easy access when needed while automatically enforcing security boundaries to protect data integrity and prevent contamination.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8089903B2Method and apparatus for providing a logical separation of a customer device and a service device connected to a data storage system
Publication Date: 2012.01.03 EMC IP HLDG CO LLC
  • US8089903B2 patent drawing
  • US8089903B2 patent drawing
  • US8089903B2 patent drawing

AI summary

A data storage system includes storage array and a switch that is configurable to create numerous network topologies within the system and to maintain separate communications paths between different computerized devices or networks and the storage array. For example, a user device and a service device, such as a system diagnosis device, can connect to the storage array through the switch. In order to isolate interaction or communication between the user and service devices, the switch can be logically partitioned into two distinct switches to form two distinct, isolated communications paths between the devices and the storage array. With isolated communications pathways established in the switch, in use, the service device is unable to access the user device coupled to the storage array.