Virtual Bands Concentration for Self-Encrypting Drives
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Self-encrypting drives (SEDs) are limited by hardware constraints to a small number of bands, which restricts their performance and makes it difficult for virtual machines to fully utilize storage devices that require thousands of bands for flexible and efficient usage.
Innovation Solution
Implementing a virtual bands concentration method that dynamically generates media encryption keys on a per I/O basis, allowing thousands of virtual data bands to be supported with hardware encryption/decryption, and concentrating multiple virtual bands into a smaller number of real bands, while enabling authentication data to be supplied by the host for each operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the number of bands is increased to support more virtual machines and flexible storage usage, then adaptability and versatility improve, but performance degrades due to constant key swapping and hardware limitations
Solution Approach 1:
The patent segments the LBA space into a limited number of hardware bands (e.g., 16) while allowing the host to create many more virtual bands (e.g., thousands). The virtual band manager divides virtual band identifiers into components that map to hardware bands, enabling many virtual bands to be supported through a limited number of physical bands without constant key swapping.
Solution Approach 2:
The patent introduces a virtual band manager as an intermediary layer between the host and the SED hardware. This mediator translates virtual band identifiers into hardware band identifiers, allowing the host to use many virtual bands while the hardware only needs to manage a limited number of physical bands, thus avoiding performance degradation from excessive key swaps.
2Adaptability or versatility
If the number of active bands exceeds hardware LBA range support, then adaptability improves for virtual machine usage, but performance suffers due to constant key swapping
Solution Approach 1:
The patent implements dynamic band mapping where the virtual band manager can flexibly assign virtual bands to hardware bands based on current workload and usage patterns. This dynamic allocation allows the system to adapt to changing virtual machine requirements while maintaining optimal performance by minimizing key swaps through intelligent band assignment.
Solution Approach 2:
The patent changes the parameter of band identification from a direct one-to-one mapping to a multi-component identifier system. Virtual band identifiers are divided into a hardware band component and a virtual band offset, allowing the same hardware band to serve multiple virtual bands. This parameter transformation enables thousands of virtual bands to map to a limited number of hardware bands without performance penalty.
3Productivity
If a single LBA range is used for data under a single authentication key, then hardware encryption efficiency is maintained, but versatility for multi-tenant virtual machine storage is reduced
Solution Approach 1:
The patent makes the hardware band structure universal by allowing each hardware band to serve multiple virtual bands from different tenants. The virtual band manager enables a single hardware band to be shared across multiple virtual machines with different authentication keys, providing multi-tenant capability while maintaining hardware encryption efficiency through the limited number of physical bands.
Data Source
AI summary
An apparatus includes a storage medium with an opaque key storage and a controller. The controller may be coupled to the storage medium. The controller may be configured to (i) receive from a host device an authentication key, a plurality of I/O requests, and respective virtual media encryption keys associated with a number of the I/O requests, (ii) allow the host device to access the opaque key storage in response to the authentication key received from the host device being authenticated, (iii) generate a first media encryption key for a real band based upon the authentication key from the host device and key material stored on the apparatus, and (iv) generate a number of second media encryption keys for the number of I/O requests based on the first media encryption key and each of the respective virtual media encryption keys associated with each of the number of I/O requests.


