Virtual Storage Instance Isolation for Secure Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud storage systems face challenges in providing secure access to shared storage resources, as they often lack effective isolation between users, making it difficult to protect user data from accidental or intentional intrusion, especially in multi-user environments where physical separation is not guaranteed.

Innovation Solution

The system transforms storage information into virtual storage instances, allowing access on a separate network, enabling modifications, and then transforming these modified instances back into storage information, all while maintaining isolation through hypervisor-based sandboxing to ensure secure access and privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud storage systems provide shared access to storage resources, then accessibility and usability are improved, but security and data isolation deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a virtualization layer as an intermediary between the physical storage system and users. This virtualization layer creates virtual storage instances that act as mediators, allowing users to access storage resources remotely while maintaining isolation. The virtualization layer ensures that users can access shared storage without direct exposure to the underlying physical system, thus improving accessibility while maintaining security through controlled interaction interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the storage system into multiple isolated virtual storage instances, each serving specific users or user groups. By dividing the shared storage resource into separate virtual instances with controlled access, the system enables multiple users to access storage simultaneously while maintaining logical isolation. This segmentation prevents unauthorized access between users while preserving the shared nature of the underlying physical storage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If physical separation is implemented for security, then security is improved, but device complexity and infrastructure requirements worsen

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of storage resources through virtualization, allowing multiple users to access isolated instances that mirror the functionality of physical separate systems. Instead of requiring physically separate storage systems for each user, the virtualization layer creates software-based copies that provide the same security isolation benefits with significantly reduced infrastructure complexity. The virtual storage instances replicate the access control and isolation properties of physical separation without the hardware overhead.

Inventive Principle:
Principle #26Copying

3Ease of operation

If virtualization is used to provide access, then accessibility is improved, but system complexity worsens

Engineering Contradiction:
ImproveaccessibilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent designs the virtualization layer to provide multiple functions through a single unified system. The same virtualization infrastructure that enables remote access also provides security isolation, resource management, and scalability. By making the virtualization system multi-functional, the patent reduces overall system complexity compared to implementing separate systems for each function. The virtual storage instances serve as universal access points that handle multiple operational requirements simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8931054B2Secure access to shared storage resources
Publication Date: 2015.01.06 SANDISK TECHNOLOGIES LLC
  • US8931054B2 patent drawing
  • US8931054B2 patent drawing
  • US8931054B2 patent drawing

AI summary

A method may comprise storing first storage information in a storage device of a computer storage system on a first network. The computer storage system may transform the first storage information into a first virtual storage instance, provide access to the first virtual storage instance on a second network not in communication with the first network and the storage device, and enable over the second network the modification of the first virtual storage instance to create a first modified virtual storage instance. The computer storage system may also transform the first modified storage instance into first modified storage information based on the first modified storage instance, and store on the storage device the first modified storage information.