Enabling Persistent Access for Security in Storage Devices
By setting audit mode indicators in Fibre Channel environments, the problem of possible connection loss when security is enabled in the prior art is solved, and security enablement without losing access in heterogeneous environments is achieved.
Patent Information
- Application Number
- CN202080063673.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-09-11
- Filing Date
- 2020-09-02
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2040-09-02
AI Technical Summary
In Fibre Channel environments, it is difficult for prior art to enable security without losing connections, especially in heterogeneous environments where there are systems and storage ports that do not support security, resulting in the potential loss of access to storage devices when security is enabled.
By setting an audit mode indicator in the login response, the host port can continue to perform I/O operations even if the authentication or security association negotiation with the storage port cannot be completed successfully, ensuring that the unsafe host can access the storage device.
Enable security without losing access to the storage device, ensuring that in a heterogeneous computing environment, the host can continue to perform secure I/O operations with the storage device.
Smart Images

Figure CN114424176B_ABST
Abstract
Description
Technical Field
[0001] The present invention generally relates to enabling sustained access for security in a storage device. Background Art
[0002] Fiber Channel refers to a set of integrated architecture standards for data transmission developed by the American National Standards Institute (ANSI). The security solution for the Fiber Channel architecture is provided by the Fiber Channel Security Protocol (FC-SP) developed by ANSI. FC-SP provides mechanisms for device authentication, per-message security, policy distribution, etc. in a Fiber Channel environment. Further details of FC-SP are provided in the publication "Fiber Channel Security Protocol-2 (FC-SP-2)" (Revision 2.71) published by ANSI on June 12, 2012.
[0003] FC-LS-4 provides mechanisms for link services in Fiber Channel, and further details are provided in the publication "Fiber Channel Link Services (FC-LS-4)" (Revision 4.04) published by ANSI on July 16, 2019. FC-FS-5 provides mechanisms for framing and signaling in Fiber Channel, and further details are provided in the publication "Fiber Channel Framing and Signaling-5 (FC-FS-5)" (Revision 1.0) published by ANSI on April 3, 2018.
[0004] In a Fiber Channel environment, to provide secure and encrypted communication between nodes in a Fiber Channel architecture, a security association (SA) management transaction is performed between a SA_Initiator and a SA_Responder using a security establishment protocol. The initiator and responder can include ports in adapters in devices in a Fiber Channel network. Separate security associations are established for data transmission and data reception at the port. The completion of the SA establishment transaction results in a set of security associations and associated key material, and the associated key material is used to encrypt / decrypt data communication between the initiator and the responder under the established security associations. An example of a security association protocol is the security association management protocol in FC-SP-2. This protocol includes a pair of messages SA_Init and SA_Init Response to establish a parent association, followed by a pair of messages SA_Auth and SA_Auth Response to perform authentication of entities and establish a security association to protect the data transmitted between the entities.
[0005] A storage controller can control access to the storage of one or more host computing devices, and the host computing devices can be coupled to the storage controller via a Fibre Channel network. A storage management application executed in the storage controller can manage multiple storage devices coupled to the storage controller, such as disk drives, tape drives, flash drives, direct access storage devices (DASDs), etc. The host computing device can send input / output (I / O) commands to the storage controller, and the storage controller can execute the I / O commands to read data from or write data to the storage device. Communication between the host and the storage controller occurs via Fibre Channel ports on adapters located in the host and the storage controller.
[0006] U.S. Patent Publication 20100154053 discusses a storage security mechanism using cryptographic partitioning. U.S. Patent Publication 20190251282 discusses a network security mechanism for transferring data between servers. U.S. Patent Publication 20160139845 discusses storage-level access control of data packet structures. U.S. Patent Publication 20160378691 discusses a mechanism for protecting storage devices from attacks. U.S. Patent 8275950 discusses a Fibre Channel-connected storage controller that can use a login request control table to manage the one-to-one correspondence of ports of a host computer and the storage controller, so as to prevent any unauthorized access attempt from the host computer on a per-port basis, thereby maintaining enhanced security. U.S. Patent 6219771 discusses a data storage device with improved security processing and partition allocation functions. U.S. Patent Publication 20040107342 discusses a secure network file access control system. European Patent Application EP1276034A2 discusses the security of logical units in a storage subsystem. U.S. Patent Publication 20160342798 discusses systems and methods for protected device management. U.S. Patent 8799436 discusses systems and methods for auditing and verifying configuration items in an information technology (IT) configuration management database. Summary of the Invention
[0007] A method, system, and computer program product are provided, wherein a storage port receives a login request. The storage port configures an audit mode indicator as enabled in a login response to a host port to enter an enabled security mode and indicates to the host port that input / output (I / O) operations will be sent from the host port to the storage port, even if the authentication or security association negotiation with the storage port cannot be successfully completed. As a result, an insecure host can perform I / O on the storage device.
[0008] In an additional embodiment, the login response is a first login response, and if the authentication or security association negotiation with the storage port cannot be successfully completed, the storage port configures the audit mode indicator as not enabled in a second login response to the host port to enter a forced security mode to indicate to the host port that I / O operations will not be sent from the host port to the storage port. As a result, an insecure host cannot perform I / O on the storage device.
[0009] In an additional embodiment, the storage port is included in a storage controller, where the storage controller includes a plurality of storage ports, and the plurality of storage ports includes the storage port. The storage controller configures at least one of the plurality of storage ports as the forced security mode. The storage controller configures at least another one of the plurality of storage ports as the enabled security mode. Thus, the enabling of the audit mode indicator is port-based.
[0010] In other embodiments, the storage port is included in a storage controller, and the storage controller includes a first storage array and a second storage array, where the forced security mode is configured for the first storage array, and the enabled security mode is configured for the second storage array. Thus, the enabling of the audit mode indicator is storage-array-based.
[0011] In other embodiments, the storage controller that includes the storage port maintains statistics regarding login counters and login characteristics, and the statistics include: the number of current logins to the storage port; the number of logins with security capabilities to the storage port; and the number of security-enabled logins to the storage port. As a result, in some embodiments, if the forced security mode is configured, the storage controller uses the statistics regarding login counters and login characteristics to determine the impact on I / O access to the host.
[0012] In an additional embodiment, if the host will lose I / O access when switching to the forced security mode, the statistics regarding login counters and login characteristics are used by the storage controller to prevent the switch from the enabled security mode to the forced security mode. As a result, if the host will lose I / O access, the switch to the forced security mode is blocked.
[0013] In other embodiments, the storage controller provides an option to force a switch to the forced security mode regardless of the statistics regarding login counters and login characteristics. As a result, a forced switch to the forced security mode is allowed.
[0014] In some embodiments, the audit mode indicator is enabled via an indication in auxiliary parameter data word 0 bit 23 in a program implementing Fibre Channel link services. As a result, Fibre Channel is enhanced to enhance operations based on the security bits provided by Fibre Channel. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Now refer to the drawings, where like reference numerals always denote corresponding parts:
[0016] Figure 1 A block diagram of a heterogeneous computing environment according to some embodiments is shown, the heterogeneous computing environment including a plurality of hosts communicating with a plurality of storage controllers and / or storage devices via a Fibre Channel fabric;
[0017] Figure 2 A block diagram of a system for maintaining access to a host for security enablement in a heterogeneous computing environment according to some embodiments is shown;
[0018] Figure 3 A block diagram according to some embodiments is shown that depicts security bits for logging into Fibre Channel and enhancements to Fibre Channel via an audit mode indicator;
[0019] Figure 4 A block diagram according to some embodiments is shown that depicts a login and response in Fibre Channel;
[0020] Figure 5 A block diagram according to some embodiments is shown that depicts enhancements to Fibre Channel to provide indications of "mandatory security" and "enabled security" via enabling or disabling an audit mode indicator;
[0021] Figure 6 A flowchart according to some embodiments is shown that depicts the operation of a storage port with mandatory security;
[0022] Figure 7 A flowchart according to some embodiments is shown that depicts the operation of a storage port with enabled security;
[0023] Figure 8 A block diagram according to some embodiments is shown that depicts conditions preventing successful completion of authentication and security association management;
[0024] Figure 9 A block diagram according to some embodiments is shown that depicts multiple host ports logging into a single storage port;
[0025] Figure 10 A flowchart according to some embodiments is shown that depicts operations in a storage device for determining whether to change a storage port to a mandatory security state;
[0026] Figure 11 shows a flowchart illustrating operations for maintaining access for security enabling on a host system;
[0027] Figure 12 shows a flowchart illustrating additional operations for maintaining access for security enabling on a host system;
[0028] Figure 13 shows a flowchart illustrating operations for maintaining access for security enabling in a storage device;
[0029] Figure 14 shows a flowchart illustrating additional operations for maintaining access for security enabling in a storage device;
[0030] Figure 15 shows a block diagram of a cloud computing environment in accordance with certain embodiments;
[0031] Figure 16 shows in accordance with certain embodiments Figure 15 a block diagram of further details of the cloud computing environment; and
[0032] Figure 17 shows a block diagram of a computing system in accordance with certain embodiments, the computing system showing specific units that may be included in a host, a storage controller, and a storage device as described in Figure 1-16 above. DETAILED DESCRIPTION
[0033] In the following description, reference is made to the accompanying drawings which form a part hereof and which show several embodiments. It is to be understood that other embodiments may be utilized and structural and operational changes may be made.
[0034] The standard for encrypting Fibre Channel links (FC-SP-2) includes protocols for mutual authentication of two endpoints (i.e., ports) and a protocol for negotiating encryption keys to be used in a communication session between the two endpoints. The standard provides support for various mechanisms to authenticate the parties involved and mechanisms for providing or developing key material.
[0035] In the FC-SP-2 standard, support for authentication within an endpoint is indicated by the setting of a security bit in the common service parameters passed to the peer during the login process. When set to a value of 1 in a login request, the security bit indicates that the sending port is capable of performing authentication. When the responding port accepts the login request, if the responding port also sets the security bit to 1 in the reply, this indicates that the responding port requires the sender of the login to now perform authentication before granting any further access.
[0036] The FC-SP-2 standard specifies the behavior of a responding endpoint in accepting or rejecting a login request and setting security bits based on the security policy in effect at that endpoint when a request is received. The standard does not specify how to instantiate the policy at the responding endpoint. In an enterprise data center, it is important to protect access to data and provide data security. When enabling security in a heterogeneous environment that includes some systems and storage ports that do not support security (e.g., legacy ports), some embodiments provide a mechanism to ensure connectivity is not lost, in contrast to current standards that do not allow such a mechanism to be provided.
[0037] Some embodiments provide a mechanism to enable security at a host in "audit mode", in which the host's access to data is not lost when security is enabled in a storage device. An indication is provided by setting an audit mode indicator at login, which allows the host port to continue accessing the storage port after security is enabled. Once authentication and enabling of the security mechanism have been verified as having been successfully completed, enabling security can be changed to enforcing the security policy. Enabling security means that I / O can be performed even if authentication and enabling of the security mechanism have not been successfully completed, while enforcing security means that I / O cannot be performed if authentication and enabling of the security mechanism have not been successfully completed. When in audit mode, the host can continue to access the storage device, and tools are provided to audit the security state of the connection.
[0038] Some embodiments provide a mechanism in which the host determines that authentication and / or security association with a storage device cannot be successfully completed, and then uses the audit mode indicator to check if security is not being enforced on the storage port. If the audit mode indicator is set, the host processor continues to send I / O operations to the storage device along the selected port. If the audit mode indicator is not set, the host processor stops I / O operations to the storage device and notifies the host application or operating system to find an alternative path to complete the I / O operation.
[0039] In addition, in Fibre Channel, many host ports can log in (as described in FC-FS-5) to a single storage port. Some of these host ports may support security while some may not. If the port setting is set to enforce security, host ports that do not support security may lose access to the storage port because these host ports are not allowed to log in.
[0040] In some embodiments, the storage device provides information to show the number of logins to each port of the storage device currently. For this number of logins, the storage device provides the number of logins with security capabilities, and the number of logins that are successfully authenticated and security-enabled. Based on this information, it can be determined whether access to the port may be lost if the storage port settings are changed to enforce security. Once it is determined that all logins are secure, the settings can be changed without losing access because all host ports are capable of successfully enabling security. In some embodiments, when it is desired to change the settings to enforce security, the storage device checks the login counter to determine whether access loss may occur (i.e., there are logins that are not successfully authenticated) and blocks the settings from being changed to enforce security.
[0041] Some embodiments provide a storage port that supports enabling security without an enforced setting and provides audit statistics (e.g., login count, login count with security capabilities, and security-enabled login count) to determine the impact of setting security to be enforced. An audit mode indicator is set in the login response to the host port, indicating that I / O can be sent to the storage port even if authentication cannot be successfully completed. The enabling or enforcing of security can be performed on the storage array or on an individual storage port basis.
[0042] In some embodiments, a setting for enforcing security is provided that has an automatic check of the login indicator to prevent the settings from being changed in cases where access loss may occur. An option is also provided to enforce the settings to be security-enforced regardless of the login indicator.
[0043] As a result, in an enhancement to a Fibre Channel-based connectivity environment, the device is improved to maintain connectivity for performing I / O.
[0044] Exemplary embodiments
[0045] Figure 1 FIG. 100 is a block diagram showing a heterogeneous computing environment according to some embodiments, the heterogeneous computing environment including a plurality of hosts 102, 104 communicating with a plurality of storage controllers and / or storage devices 108, 110 via a Fibre Channel fabric 106. Both the storage controllers and the storage devices are shown by reference numerals 108, 110. The hosts 102, 104 may communicate with the storage controllers that control the storage devices, or may communicate with the storage devices without involving any storage controllers. The storage controllers may also be considered a higher type of storage device since it controls and allows one or more hosts to access one or more storage devices.
[0046] Hosts 102, 104 and storage controllers 108, 110 can include any suitable computing device, including those currently known in the art, such as personal computers, workstations, servers, mainframes, handheld computers, palmtop computers, telephone devices, network devices, blade computers, processing devices, controllers, etc. Storage devices can include storage devices currently known in the art, such as hard disk drives, tape drives, solid state drives, etc.
[0047] Hosts 102, 104 and storage devices 108, 110 can be units in any suitable network (e.g., storage area network, wide area network, Internet, intranet). In certain embodiments, hosts 102, 104 and storage devices 108, 110 can be units in a cloud computing environment. The connection between hosts 102, 104 and storage devices 108, 110 in the network and / or cloud computing environment can be through the Fibre Channel fabric 106.
[0048] A host can include one or more host ports. For example, host 102 includes a plurality of host ports 112, and host 104 includes a plurality of host ports 114. A storage device can include a plurality of storage ports. For example, storage device 108 includes a plurality of storage ports 116, and storage device 110 includes a plurality of storage ports 118. Host ports 112, 114 and storage ports 116, 118 can communicate through the Fibre Channel fabric 106.
[0049] In certain embodiments, not all hosts support the security of host ports. For example, some legacy hosts may not support the security of host ports in Fibre Channel, or some legacy adapters in a host may not support the security of host ports in Fibre Channel. For example, host 102 is shown as supporting the security of host ports, while host 104 is shown as not supporting the security of host ports.
[0050] In certain embodiments, some storage devices can enable one or more storage ports to be configured to enable security with enforcement (i.e., I / O cannot occur from a host port to a storage port unless a secure connection has been verified to be completed between the host port and the storage port). In certain embodiments, some storage devices can enable one or more storage ports to be configured to enable security without enforcement (i.e., I / O can occur from a host port to a storage port even if a secure connection has not been verified to be completed between the host port and the storage port). For example, storage device 108 may have enabled security with enforcement for at least one of storage ports 116 (other storage ports in storage device 108 may have enabled security without enforcement). In Figure 1In this case, the storage device 110 may have enabled security without enforcement for at least one of the storage ports 118 (other storage ports in the storage device 110 may have enabled security with enforcement).
[0051] Accordingly, Figure 1 Some embodiments are shown that allow I / O operations to be sent from the host port to the storage port even if the authentication or security association negotiation between the host port and the storage port cannot be successfully completed.
[0052] Figure 2 FIG. 200 is a block diagram of a system for maintaining access to a host 202 for security enablement in a heterogeneous computing environment according to some embodiments.
[0053] The host 202 is communicatively coupled via a Fibre Channel fabric 208 to a plurality of storage devices 204, 206. The storage device 204 has enabled security with enforcement for the storage port 210 of the storage device 204, and the storage device 206 has enabled security without enforcement for the storage port 212 of the storage device 206. In some embodiments, the storage port can be changed from enabling security without enforcement to enabling security with enforcement, and vice versa.
[0054] The host 202 includes a host port 214, where the host port 214 communicates with the storage ports 210, 212. In Figure 2 the illustrated embodiment, even if the authentication or security association negotiation between the host port 214 and the storage port 212 cannot be successfully completed, the host port 214 is able to send I / O to the storage port 212 because the storage port 212 has enabled security without enforcement. However, if the authentication or security association negotiation between the host port 214 and the storage port 210 cannot be successfully completed, then the host port 214 cannot send I / O to the storage port 210 because the storage port 210 has enabled security with enforcement.
[0055] In the case where the host port 214 cannot send an I / O operation to the storage port, the operating system 216 of the host 202 attempts to send the I / O operation via another mechanism.
[0056] Figure 3 FIG. 300 is a block diagram according to some embodiments, which shows the security bits 302 for login in the current Fibre Channel standard and an enhancement to the Fibre Channel via an audit mode indicator 304. The audit mode indicator 304 can be enabled (reference numeral 306) or not enabled (reference numeral 308).
[0057] It should be noted that the audit mode indicator 304 is not found in the existing Fibre Channel standards. Enabling the audit mode indicator 304 allows enabling non-mandatory security to work in cooperation with the configuration of the security bit 302.
[0058] In some embodiments, the audit mode indicator 304 is enabled via an indication in auxiliary parameter data word 0 bit 23 in a program implementing Fibre Channel Link Service (FC-LS-4). In other embodiments, other mechanisms for implementing the audit mode indicator 304 may be provided. The audit mode indicator 304 and the security bit 302 may be part of one or more data structures for performing operations.
[0059] Figure 4 Block diagram 400 showing login and response in Fibre Channel according to some embodiments is shown. The host port 402 sends a login request 404 to the storage port 406. The host port 402 is also referred to as the "sending port", and the storage port 406 is also referred to as the "receiving port".
[0060] In the login request 404 from the host port 402, the security bit 302 is set to 1 to indicate that the sending port (i.e., the host port 402) is capable of performing authentication.
[0061] Upon receiving the login request 404, the storage port 406 sends a response 408 to the host port 402. The response 408 from the storage port 406 may set the security bit 302 to 1 to indicate that the receiving port (i.e., the storage port 406) requires the sending port (i.e., the host port 402) to perform authentication before allowing any further access.
[0062] In some embodiments, even if the security bit 302 is set to 1 in the response, if the audit mode indicator 304 is enabled (i.e., set) to indicate that non-mandatory security is enabled, the requirement to complete authentication before allowing any further access is overridden.
[0063] Figure 5 Block diagram 500 according to some embodiments is shown, which shows an enhancement to Fibre Channel to provide an indication of "mandatory security" and "enabled security" by enabling or disabling the audit mode indicator 304.
[0064] A receiving port (e.g., a storage port in a storage device) provides an indication (as shown by reference numeral 502) in response to a login request issued by a host. The indication can be provided via the configuration of the audit mode indicator 304. The configuration of the enabled audit mode indicator 304 can cause the state of the storage port to change to "security enabled" 504, which means that security is enabled without coercion. The configuration of not enabling the audit mode indicator 304 can cause the state of the storage port to change to "coerced security" 506, which means that security is enabled with coercion.
[0065] Figure 6 A flowchart 600 showing the operation of a storage port indicating coerced security according to some embodiments is shown. Control proceeds to block 604, where authentication and security association management are initiated between a host port and a storage port. Control proceeds to block 606, where it is determined whether the authentication and security association management has been successfully completed between the host port and the storage port. If so ("yes" branch 608), then control proceeds to block 610, where the host port is allowed to start performing I / O through the storage port (at block 610). If not ("no" branch 612), then control proceeds to block 614, where the host port is blocked from performing I / O through the storage port.
[0066] Figure 7 A flowchart 700 showing the operation of a storage port indicating security enabled according to some embodiments is shown.
[0067] Control begins at block 702, where security is enabled for the storage port. Control proceeds to block 704, where authentication and security association management are initiated between the host port and the storage port. The host port is allowed to perform I / O through the storage port (block 706), regardless of whether the authentication and security association management operation is successful or not (at block 708). In different embodiments, the time when I / O is started to be allowed can be different.
[0068] Figure 8 A block diagram 800 showing the conditions that prevent the successful completion of authentication and security association management according to some embodiments is shown.
[0069] The first condition 802 is an incomplete configuration of the security policy, which can prevent the authentication and security association management from being successfully completed. The second condition 804 includes that the key server providing the credentials to access the storage device is inaccessible, which can prevent the authentication and security association management from being successfully completed. The third condition 806 is a failure in the authentication and security association management exchange, which can prevent the authentication and security association management from being successfully completed. All these conditions may cause the authentication and security association management not to be successfully completed in the Figure 6 and 7 operations shown.
[0070] Figure 9 FIG. 900 is a block diagram showing multiple host ports 902, 904, 906 logged into a single storage port 908, according to some embodiments. The single storage port 908 may be included in a storage device or storage controller 910, where the storage device or storage controller 910 may have other storage ports.
[0071] Among Figure 9 them, host ports 902 and 906 support security, while host port 904 does not support security because host port 904 may be included in a legacy adapter or legacy host, or for some other reason (including configuration by an administrator).
[0072] The storage device or storage controller 910 maintains statistics regarding login counters and login characteristics, which are referred to as login indicators (reference numeral 912). The statistics include: the number of current logins to the storage port (reference numeral 914); the number of login counts with security capabilities to the storage port (reference numeral 916); and the number of login counts with security enabled to the storage port (reference numeral 918). Logins with security enabled are those that have been successfully authenticated and have security enabled.
[0073] In some embodiments, if a mandatory security mode is configured, the statistics 912 regarding login counters and login characteristics are used by the storage device or storage controller 910 to determine the impact on I / O access to the host. In additional embodiments, if the host will lose I / O access when switching to the mandatory security mode, the statistics 912 regarding login counters and login characteristics are used by the storage device or storage controller to prevent switching from the enabled security mode to the mandatory security mode.
[0074] In further embodiments, the storage device or storage controller 910 provides an option 920 for forcing a switch to the mandatory security mode regardless of the statistics 912 regarding login counters and login characteristics.
[0075] Figure 10 FIG. 1000 is a flowchart showing operations in a storage device for determining whether to change a storage port to a mandatory security state, according to some embodiments.
[0076] Control begins at block 1002 where the storage device determines that multiple host ports have performed a login to the storage ports of the storage device. The control proceeds to block 1004 where the storage device maintains statistics regarding a login counter and login characteristics. If the settings of the storage port are changed to enforce security, the storage device determines (at block 1006) based on the login counter and login characteristics whether any host ports will lose access to the I / O of the storage device. If so ("Yes" branch 1008), then not all host port logins are secure (i.e., not all host ports have been successfully authenticated), and the control proceeds to block 1010 where the change of the storage port settings to enforce security is blocked.
[0077] If at block 1006, the storage device determines based on the login counter and login characteristics that no host ports will lose access to the I / O of the storage device in the case where the settings of the storage port are changed to enforce security ("No" branch 1012), then all host port logins are secure (i.e., all host ports have been successfully authenticated), and the control proceeds to block 1014 where the change of the storage port settings to enforce security is allowed.
[0078] Figure 11 FIG. 1100 is a flow diagram showing operations for maintaining access for security enablement on a host system according to some embodiments.
[0079] Control begins at block 1102 where the host port is enabled for security. The host port determines (at block 1104) that the authentication or security association negotiation with the storage port cannot be successfully completed.
[0080] In response to the host port determining that the authentication or security association negotiation with the storage port cannot be successfully completed, the host port determines (at block 1106) whether an audit mode indicator has been enabled in the login response from the storage port. The host port maintains input / output (I / O) access to the storage port based on determining whether an audit mode indicator has been enabled in the login response from the storage port. As a result, even if the authentication or security association negotiation with the storage port cannot be successfully completed, the host port can perform I / O via the storage port.
[0081] In response to determining that an audit mode indicator has been enabled in the login response from the storage port ("Yes" branch 1108), the host port performs (at block 1110) I / O to the storage port. Performing I / O to the storage port means sending an I / O operation to the storage port to perform an I / O operation where data is read or written or accessed. As a result, when the audit mode indicator has been enabled, the host port performs I / O via the storage port even if the authentication or security association negotiation with the storage port cannot be successfully completed.
[0082] In response to determining that the audit mode indicator is not enabled in the login response from the storage port ("No" branch 1112), the host port avoids (at block 1114) performing I / O to the storage port. As a result, if the authentication or security association negotiation with the storage port cannot be successfully completed and the audit mode indicator has not been enabled, the host port does not perform I / O via the storage port. Control proceeds from block 1114 to block 1116, where the host port returns the I / O request to the operating system of the host computing device. As a result, if the authentication or security association negotiation with the storage port cannot be successfully completed and the audit mode indicator has not been enabled, an alternative mechanism for performing I / O is attempted.
[0083] Figure 12 FIG. 1200 shows a flowchart illustrating additional operations for maintaining access for security enabling on a host system, in accordance with certain embodiments.
[0084] If the host port cannot access the key server to obtain credentials for authenticating to the storage port, the host port determines (at block 1202) that the authentication or security association negotiation with the storage port cannot be successfully completed. As a result, the host port may take further action to determine the status of the audit indicator to determine whether to send an I / O request to the storage port.
[0085] Control proceeds from block 1202 to block 1204, where, if there is a failure during the process of authentication or security association negotiation with the storage port, the host port determines that the authentication or security association negotiation with the storage port cannot be successfully completed. As a result, the host port may take further action to determine the status of the audit indicator to determine whether to send an I / O request to the storage port.
[0086] Figure 13 FIG. 1300 shows a flowchart illustrating operations for maintaining access for security enabling in a storage device, in accordance with certain embodiments.
[0087] Control begins at block 1302, where the storage port receives a login request. Control may proceed from block 1302 to block 1304 or block 1306.
[0088] In block 1304, the storage port configures the audit mode indicator to be enabled in the login response to the host port to enter the security enabled mode to indicate to the host port that input / output (I / O) operations will be sent from the host port to the storage port even if the authentication or security association negotiation with the storage port cannot be successfully completed. As a result, an insecure host may perform I / O to the storage device.
[0089] In block 1306, if the authentication or security association negotiation with the storage port cannot be successfully completed, the storage port configures the audit mode indicator to not enable entry into the forced security mode in the login response to the host port, to indicate to the host port that I / O operations will not be sent from the host port to the storage port. As a result, an insecure host cannot perform I / O to the storage device.
[0090] Figure 14 FIG. 1400 is a flow diagram showing additional operations for maintaining access for security enablement in a storage device.
[0091] Control begins at block 1402, where a storage controller including the storage port maintains statistics regarding login counters and login characteristics, which include: the number of current logins to the storage port; the number of logins to the storage port having security capabilities; and the number of security-enabled logins to the storage port. As a result, in some embodiments, if the security enforcement mode is configured, the statistics regarding login counters and login characteristics are used by the storage controller to determine the impact of I / O access to the host.
[0092] In additional embodiments, if the host will lose I / O access when switching to the forced security mode, the statistics regarding login counters and login characteristics are used by the storage controller to prevent (at block 1404) switching from the security-enabled mode to the forced security mode. As a result, if the host will lose I / O access, the switch to the forced security mode is blocked.
[0093] In some embodiments, the storage controller provides an option to force a switch to the forced security mode regardless of the statistics regarding login counters and login characteristics.
[0094] In some embodiments, the storage controller configures at least one of the plurality of storage ports to the forced security mode. The storage controller configures at least another of the plurality of storage ports to the security-enabled mode. Thus, the enabling of the audit mode indicator is port-based.
[0095] In further embodiments, the storage ports are included in a storage controller that includes a first storage array and a second storage array, where the forced security mode is configured for the first storage array, and where the security-enabled mode is configured for the second storage array. Thus, the enabling of the audit mode indicator is array-based.
[0096] Thus, Figure 1-14Some embodiments are shown that enforce or do not enforce security based on the configuration of the audit mode indicator to enhance operations based on the configuration of the security bits in Fibre Channel. As a result, even when the security bits are enabled in Fibre Channel, legacy devices can continue I / O in a heterogeneous computing environment.
[0097] Cloud computing environment
[0098] Cloud computing is a model for enabling convenient on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.
[0099] Now refer to Figure 15 , which depicts an illustrative cloud computing environment 50. Security enforcement or enabling is performed in the cloud computing environment 50 (shown via reference numeral 52). As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 with which local computing devices used by cloud consumers can communicate, such as a personal digital assistant (PDA) or cellular phone 54A, desktop computer 54B, laptop computer 54C, and / or in-vehicle computer system 54N. The nodes 10 can communicate with each other. They can be physically or virtually grouped (not shown) in one or more networks, such as a private cloud, community cloud, public cloud, or hybrid cloud or combinations thereof as described above. This allows the cloud computing environment 50 to provide infrastructure, platform, and / or software as a service, and the cloud consumer does not need to maintain resources on a local computing device. It should be understood that Figure 15 the types of computing devices 54A-N shown in are only illustrative, and the computing nodes 10 and the cloud computing environment 50 can communicate with any type of computerized device over any type of network and / or network addressable connection (e.g., using a web browser).
[0100] Now refer to Figure 16 , which shows a set of functional abstraction layers provided by the cloud computing environment 50 ( Figure 15 ). It should be understood in advance that Figure 16 the components, layers, and functions shown in are only illustrative, and embodiments of the present invention are not limited thereto.
[0101] The hardware and software layer 60 includes hardware and software components. Examples of hardware components include mainframes, in one example an IBM ZSERIES* system; servers based on RISC (Reduced Instruction Set Computer) architecture, in one example an IBM PSERIES* system; IBM XSERIES* systems; IBM BLADECENTER* systems; storage devices; and network and networking components. Examples of software components include network application server software, in one example IBM WEBSPHERE* application server software; and database software, in one example IBM DB2* database software.
[0102] The virtualization layer 62 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual servers; virtual storage; virtual networks, including virtual private networks; virtual applications and operating systems; and virtual clients.
[0103] In one example, the management layer 64 can provide the functions described below. Resource provisioning provides dynamic procurement of the computing resources and other resources that are used to perform tasks within the cloud computing environment. Metering and pricing provides cost tracking for utilization of resources within the cloud computing environment, as well as billing or invoicing for consumption of those resources. In one example, these resources can include application software licenses. Security provides authentication for cloud consumers and tasks, as well as protection for data and other resources. The user portal provides access to the cloud computing environment for consumers and system administrators. Service level management provides cloud computing resource allocation and management such that the required service levels are met. Service level agreement (SLA) planning and fulfillment provides pre-arrangement and procurement of cloud computing resources, where future requirements are projected according to the SLA.
[0104] The workload layer 66 provides examples of functions that can utilize the cloud computing environment. Examples of workloads and functions that can be provided from this layer include: mapping and navigation; software development and lifecycle management; virtual classroom education delivery; data analysis processing; transaction processing; and enforcement or enabling of security 68, as Figure 1-15 shown.
[0105] Additional embodiment details
[0106] The operations described can be implemented as a method, apparatus, or computer program product using standard programming and / or engineering techniques to produce software, firmware, hardware, or any combination thereof. Accordingly, aspects of an embodiment may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware aspects, which may herein be collectively referred to as “circuitry,” “module,” or “system.” Additionally, aspects of an embodiment may take the form of a computer program product. A computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to perform aspects of the embodiments of the present invention.
[0107] A computer-readable storage medium may be a tangible device that can retain and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer-readable storage medium includes the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanical encoding device such as a punch card or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be construed as a transitory signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse through an optical fiber cable), or an electrical signal transmitted through a wire.
[0108] The computer-readable program instructions described herein can be downloaded to respective computing / processing devices from a computer-readable storage medium or can be downloaded to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing / processing device.
[0109] The computer-readable program instructions for performing the operations of the embodiments of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Java, Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network connection, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, in order to perform aspects of the embodiments of the present invention, an electronic circuit, including, for example, a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA), may execute the computer-readable program instructions by utilizing the state information of the computer-readable program instructions to personalize the electronic circuit.
[0110] Aspects of the embodiments of the present invention are described herein with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It will be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.
[0111] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine, such that the instructions executed via the processor of the computer or other programmable data processing device create a means for implementing the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium, which may direct a computer, a programmable data processing device, and / or other devices to operate in a particular manner, such that the computer-readable storage medium in which the instructions are stored includes an article of manufacture that includes instructions for implementing aspects of the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0112] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing device, or other device to cause a series of operational steps to be performed on the computer, other programmable device, or other device to produce a computer-implemented process, such that the instructions executed on the computer, other programmable device, or other device implement the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0113] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions, which includes one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the block may not occur in the order noted in the figures. For example, two blocks shown in succession may in fact be executed substantially simultaneously, or these blocks may sometimes be executed in the reverse order, depending on the functions involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by a special hardware-based system that performs the specified functions or acts or a combination of dedicated hardware and computer instructions.
[0114] Figure 17 A block diagram is shown in accordance with certain embodiments, which shows specific units that may be included in Figure 1-16 the computing device, host, storage controller, storage device, or other device shown in. System 1700 may include circuitry 1702, which may include at least a processor 1704 in certain embodiments. System 1700 may also include a memory 1706 (e.g., a volatile storage device) and a storage 1708. The storage 1708 may include a non-volatile storage device (e.g., EEPROM, ROM, PROM, flash memory, firmware, programmable logic, etc.), a disk drive, an optical drive, a tape drive, etc. The storage 1708 may include an internal storage device, an attached storage device, and / or a network-accessible storage device. System 1700 may include program logic 1710, which includes code 1712 that may be loaded into the memory 1706 and executed by the processor 1704 or the circuitry 1702. In certain embodiments, the program logic 1710 including the code 1712 may be stored in the storage 1708. In certain other embodiments, the program logic 1710 may be implemented in the circuitry 1702. One or more components in System 1700 may communicate via a bus or via other coupling or connection 1714. Thus, although Figure 17 the program logic 1710 is shown separated from other units, the program logic 1710 may be implemented in the memory 1706 and / or the circuitry 1702.
[0115] Certain embodiments may relate to a method for deploying computing instructions to a computing system by a human or automated process integrating computer-readable code, wherein the code, in combination with the computing system, is enabled to perform the operations of the described embodiments.
[0116] The terms "embodiment", "embodiments", "the embodiment", "these embodiments", "one or more embodiments", "some embodiments", and "an embodiment" mean "one or more (but not all) embodiments of the present invention" unless otherwise expressly specified.
[0117] The terms "comprise", "comprising", "include", and "including" and variations thereof mean "including but not limited to" unless otherwise expressly specified.
[0118] Unless otherwise expressly specified, a list of items does not imply that any or all of the items are mutually exclusive.
[0119] The articles "a", "an", and "the" mean "one or more" unless otherwise expressly specified.
[0120] Unless otherwise expressly indicated, devices that communicate with each other need not communicate with each other continuously. Additionally, devices that communicate with each other can communicate directly or indirectly through one or more intermediaries.
[0121] The description of an embodiment having several components that communicate with each other does not imply that all such components are required. Instead, various alternative components are described to illustrate various possible embodiments of the present invention.
[0122] Furthermore, although process steps, method steps, algorithms, etc. may be described in a sequential order, such processes, methods, and algorithms can be configured to work in an alternating order. In other words, any order or sequence of steps that can be described does not necessarily indicate a requirement to perform the steps in that order. The steps of the processes described herein can be performed in any feasible order. Additionally, some steps can be performed simultaneously.
[0123] When a single device or product is described herein, it is clear that more than one device / product (whether or not they cooperate) can be used in place of the single device / product. Similarly, where more than one device or product (whether or not they cooperate) are described herein, it will be readily apparent that a single device / product can be used in place of the more than one device or product, or that a different number of devices / products can be used in place of the number of devices or programs shown. The functions and / or features of a device can alternatively be embodied by one or more other devices not expressly described as having such functions / features. Accordingly, other embodiments of the present invention need not include the device itself.
[0124] At least some of the operations shown in the drawings illustrate certain events that occur in a particular order. In alternative embodiments, some operations may be performed, modified, or removed in a different order. Additionally, steps may be added to the above logic and still comply with the described embodiments. Further, the operations described herein may occur sequentially, or some operations may be processed in parallel. Additionally, the operations may be performed by a single processing unit or by distributed processing units.
[0125] For purposes of illustration and description, the above description of various embodiments of the invention has been given. It is not exhaustive and is not intended to limit the invention to the precise form disclosed. Many modifications and variations are possible in light of the above teachings. The scope of the invention is not defined by this detailed description, but by the appended claims. The above description, examples, and data provide a complete description of the manufacture and use of the composition of the invention. Since many embodiments of the invention can be made without departing from the scope of the invention, the invention resides in the appended claims.
Claims
1. A computer-implemented method, comprising: receiving a login request by a storage port, wherein the storage port is included in a storage controller, and wherein the storage controller includes a plurality of storage ports, the plurality of storage ports including the storage port, and configuring, by the storage controller, the storage port to enable a security mode; and configuring, by the storage port, an audit mode indicator to be enabled in a login response to a host port to enter the enabled security mode and indicating to the host port that input / output (I / O) operations will be sent from the host port to the storage port, even if authentication or security association negotiation with the storage port cannot be successfully completed.
2. The method according to claim 1, wherein, the login response is a first login response, and the method further comprises: if authentication or security association negotiation with the storage port cannot be successfully completed, configuring, by the storage port, the audit mode indicator to be not enabled in a second login response to the host port to enter a forced security mode to indicate to the host port that I / O operations will not be sent from the host port to the storage port.
3. The method according to claim 2, the method further comprising: configuring, by the storage controller, at least another storage port among the plurality of storage ports to the forced security mode.
4. The method according to claim 2, wherein, the storage port is included in a storage controller, the storage controller includes a first storage array and a second storage array, wherein the forced security mode is configured for the first storage array, and wherein the enabled security mode is configured for the second storage array.
5. The method according to claim 2, wherein, a storage controller including the storage port maintains statistics regarding a login counter and login characteristics, the statistics including: a number of current logins to the storage port; a number of logins with security capabilities to the storage port; and a number of security-enabled logins to the storage port.
6. The method according to claim 5, wherein, if entering the forced security mode, the statistics regarding the login counter and login characteristics are used by the storage controller to determine an impact on I / O access to a host.
7. The method according to claim 5, wherein, if a host will lose I / O access when switching to the forced security mode, the statistics regarding the login counter and login characteristics are used by the storage controller to prevent a switch from the enabled security mode to the forced security mode.
8. The method according to claim 5, wherein, the storage controller provides an option to force a switch to the forced security mode regardless of the statistics regarding the login counter and login characteristics.
9. The method according to claim 1, wherein, the audit mode indicator is enabled via an indication in auxiliary parameter data word 0 bit 23 in a program implementing Fibre Channel link services.
10. A computer system, comprising: a memory; and a processor coupled to the memory, wherein the processor performs operations including: receiving a login request by a storage port, wherein the storage port is included in a storage controller, and wherein the storage controller includes a plurality of storage ports including the storage port, and configuring, by the storage controller, the storage port to enable a security mode; and configuring, by the storage port, an audit mode indicator to be enabled in a login response to a host port to enter the enabled security mode and indicating to the host port that input / output (I / O) operations will be sent from the host port to the storage port even if authentication or security association negotiation with the storage port cannot be successfully completed.
11. The computer system according to claim 10, wherein, the login response is a first login response, and the operations further include: if authentication or security association negotiation with the storage port cannot be successfully completed, configuring, by the storage port, the audit mode indicator to be not enabled in a second login response to the host port to enter a forced security mode to indicate to the host port that I / O operations will not be sent from the host port to the storage port.
12. The computer system according to claim 11, the operations further include: configuring, by the storage controller, at least another storage port among the plurality of storage ports to the forced security mode.
13. The computer system according to claim 11, wherein, the storage port is included in a storage controller, the storage controller includes a first storage array and a second storage array, wherein the forced security mode is configured for the first storage array, and wherein the enabled security mode is configured for the second storage array.
14. The computer system according to claim 11, wherein, a storage controller including the storage port maintains statistics regarding a login counter and login characteristics, the statistics including: a number of current logins to the storage port; a number of logins to the storage port having security capabilities; and a number of security-enabled logins to the storage port.
15. The computer system according to claim 14, wherein, if entering the forced security mode, the statistics regarding the login counter and login characteristics are used by the storage controller to determine an impact on I / O access to a host.
16. The computer system according to claim 14, wherein, if a host will lose I / O access when switching to the forced security mode, the statistics regarding the login counter and login characteristics are used by the storage controller to prevent a switch from the enabled security mode to the forced security mode.
17. The computer system according to claim 14, wherein, the storage controller provides an option to force a switch to the forced security mode regardless of the statistics regarding the login counter and login characteristics.
18. A computer program product, the computer program product including computer-readable program code configured to perform operations, the operations including: receiving a login request by a storage port, wherein the storage port is included in a storage controller, and wherein the storage controller includes a plurality of storage ports, the plurality of storage ports including the storage port, and configuring, by the storage controller, the storage port to enable a security mode; and configuring, by the storage port, an audit mode indicator to be enabled in a login response to a host port to enter the enabled security mode and indicating to the host port that input / output (I / O) operations will be sent from the host port to the storage port even if authentication or security association negotiation with the storage port cannot be successfully completed.
19. The computer program product according to claim 18, wherein, the login response is a first login response, and the operations further include: if authentication or security association negotiation with the storage port cannot be successfully completed, configuring, by the storage port, the audit mode indicator to be not enabled in a second login response to the host port to enter a forced security mode to indicate to the host port that I / O operations will not be sent from the host port to the storage port.
20. The computer program product according to claim 19, the operations further including: configuring, by the storage controller, at least another storage port among the plurality of storage ports to the forced security mode.
21. The computer program product according to claim 19, wherein, the storage port is included in a storage controller, the storage controller including a first storage array and a second storage array, wherein the forced security mode is configured for the first storage array, and wherein the enabled security mode is configured for the second storage array.
22. The computer program product according to claim 19, wherein, the storage controller including the storage port maintains statistics on login counters and login characteristics, the statistics including: the number of current logins to the storage port; the number of logins with security capabilities to the storage port; and the number of security-enabled logins to the storage port.
23. The computer program product according to claim 22, wherein, if entering the forced security mode, the statistics on login counters and login characteristics are used by the storage controller to determine the impact on I / O access to the host.
24. The computer program product according to claim 22, wherein, if the host will lose I / O access when switching to the forced security mode, the statistics on login counters and login characteristics are used by the storage controller to prevent the switch from the enabled security mode to the forced security mode.
25. The computer program product according to claim 22, wherein, The storage controller provides an option to force a switch to the forced security mode regardless of the statistics regarding the login counter and login characteristics.
Citation Information
Patent Citations
Security for logical unit in storage subsystem
EP1276034A2
Secure network file access control system
US20040107342A1
Storage security using cryptographic splitting
US20100154053A1
Storage level access control for data grouping structures
US20160139845A1
Protected device management
US20160342798A1