Zone-Based Security Key Distribution for Storage Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of security keys in storage networks is complicated and error-prone, particularly in large networks, due to the difficulty in generating and distributing secure keys to multiple devices while maintaining secrecy, which is exacerbated by the exponential increase in the number of devices.

Innovation Solution

A central controller provides a Key Discovery Service (KDS) to automatically generate and distribute security keys to devices in a storage network, using client keys for authentication and secure message distribution, ensuring secure communication within defined zones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual key distribution is used in storage networks, then security keys can be distributed to devices, but the complexity and error-proneness increases exponentially with the number of devices

Engineering Contradiction:
Improvesecurity key management reliabilityVSAvoidkey distribution system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A central controller is introduced as an intermediary component to manage security key distribution. The central controller receives zone configuration information, determines device groupings, and automatically distributes appropriate security keys to devices. This intermediary eliminates the need for manual key distribution and provides centralized control over the exponentially growing number of key distribution operations as devices are added to the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Devices automatically receive and store security keys through the key discovery service without requiring manual configuration. The system performs self-service by having devices query the central controller for their required keys based on zone configurations, eliminating human intervention in the key distribution process and reducing errors associated with manual management.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If the number of devices in storage network increases, then network capacity and functionality improve, but the difficulty of maintaining key secrecy and security increases exponentially

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The central controller acts as a secure intermediary that manages key distribution as devices are added to the network. It maintains secrecy by controlling the distribution process centrally, determining which devices receive which keys based on zone configurations, and preventing unauthorized access even as the network scales to accommodate more devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network is segmented into zones with specific access policies, and security keys are distributed selectively based on zone membership. This segmentation allows the network to scale by adding devices to appropriate zones without requiring all devices to share all keys, thereby maintaining security while accommodating network growth.

Inventive Principle:
Principle #1Segmentation

3Productivity

If automated key distribution is implemented, then key management efficiency improves, but the requirement for centralized control and authentication mechanisms increases

Engineering Contradiction:
Improvekey distribution efficiencyVSAvoidcentralized control system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The central controller provides automated key distribution by receiving zone configuration information, determining device groupings, and distributing appropriate security keys. This automation dramatically improves key distribution efficiency compared to manual methods, as the central controller can rapidly process and distribute keys to multiple devices simultaneously based on predefined zone policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements authentication mechanisms where devices authenticate with the central controller before receiving keys, and the central controller verifies zone configurations before distributing keys. This feedback loop ensures security while maintaining automation, as the system continuously verifies device identities and authorization before performing key distribution operations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250293875A1Distribution of security keys in a storage network
Publication Date: 2025.09.18 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20250293875A1 patent drawing
  • US20250293875A1 patent drawing
  • US20250293875A1 patent drawing

AI summary

Example implementations relate to storage networks. In some examples, a controller identifies a set of devices associated with a zone configuration of a storage network, and identifies a set of policies associated with the zone configuration. The controller generates a set of security keys based on the set of devices and the set of policies. The controller distributes the set of security keys to the set of devices via a set of secure messages, where the set of devices receive different subsets of the set of security keys to establish encrypted communications among the set of devices.