Cloud-Based Authentication for Flash Storage Array Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage array technologies face complexity in providing secure and efficient access and administration due to the need for robust authorization and authentication mechanisms in cloud-based environments, especially in multi-user data centers with diverse access privileges.
Innovation Solution
A cloud-based security module receives user credentials, authenticates them, identifies authorized access privileges, generates a token, and provides it to a client-side array services module, which then determines access requests to storage array services based on these privileges, enabling secure and efficient access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication mechanisms are used for storage array access in multi-user data centers, then security can be maintained, but system complexity and authentication overhead increase significantly
Solution Approach 1:
The patent introduces a cloud-based security module as an intermediary between users and storage arrays. This module handles authentication and authorization centrally, receiving user credentials, verifying them against stored authentication data, and returning authorization tokens. This mediates the complex authentication process, allowing individual storage arrays to maintain security without implementing complex authentication mechanisms themselves.
Solution Approach 2:
The cloud-based security module serves multiple storage arrays and multiple users through a single centralized system. Rather than each storage array implementing its own authentication mechanism, the universal security module provides authentication services to all arrays, reducing overall system complexity while maintaining security consistency across the entire storage network.
2Reliability
If robust authorization mechanisms are implemented for each storage array service, then access security is improved, but the time required for authentication and access management increases
Solution Approach 1:
The system performs preliminary authentication by verifying user credentials against the cloud-based security module before access is granted to storage arrays. The module pre- validates user identity and generates authorization tokens in advance, so that when users need to access storage services, the authentication process is already complete and they can proceed with their operations without repeated verification delays.
Solution Approach 2:
Instead of repeatedly verifying user credentials against the original authentication data for each access request, the system creates and distributes copies of authorization information in the form of tokens. These tokens contain the necessary authorization data and can be presented multiple times without requiring re-authentication, significantly reducing authentication time while maintaining security.
3Productivity
If centralized cloud-based authentication is implemented, then authentication efficiency is improved, but network dependency and potential single point of failure risks increase
Solution Approach 1:
The authentication system is segmented into modular components: the cloud-based security module handles central authentication logic, while individual storage arrays and client devices maintain local capability to validate and use authorization tokens independently. This segmentation allows the system to maintain high authentication efficiency through centralized processing while distributing the actual access control functionality across multiple independent points, reducing single points of failure.
Data Source
AI summary
Providing authorization and authentication in a cloud for a user of a storage array includes: receiving, by a storage array access module from a client-side array services module, a token representing authentication of user credentials and authorized access privileges defining one or more storage array services accessible by the user, where the token is generated by a cloud-based security module upon authentication of the user credentials and identification of authorized access privileges for the user; receiving, by the storage array access module from the user, a user access request to one or more storage array services; and determining, by the storage array access module, whether to grant the user access request in dependence upon the authorized access privileges represented by the token.


