Cloud-Based Security Module for Storage Array Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage array technologies face complexity in providing secure and efficient access and administration due to the need for multiple authentication and authorization systems across various users and services in data centers, which can lead to inefficiencies and security vulnerabilities.
Innovation Solution
A cloud-based system that integrates a cloud-based security module for authorization and authentication, allowing single sign-on through a client-side array services module and an identity provider, using protocols like SAML or OAUTH, to manage user credentials and access privileges, enabling seamless access to storage array services while maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple authentication and authorization systems are implemented across various users and services in data centers, then security is improved, but system complexity increases
Solution Approach 1:
The patent combines multiple authentication and authorization systems into a single unified cloud-based security module. This consolidation maintains comprehensive security coverage while reducing the overall system complexity by eliminating redundant authentication mechanisms and centralizing security management functions.
Solution Approach 2:
The cloud-based security module provides universal authentication and authorization services that can handle multiple users, services, and data center environments through a single system. This multi-functional approach allows the same security infrastructure to serve diverse authentication needs without requiring separate specialized systems.
2Reliability
If multiple authentication systems are implemented, then security coverage is improved, but ease of operation deteriorates
Solution Approach 1:
The unified security module provides universal access credentials that work across all services and data centers, eliminating the need for users to manage multiple separate authentication systems. This maintains comprehensive security coverage while significantly improving ease of operation through consistent, centralized authentication.
Solution Approach 2:
The cloud-based security module acts as an intermediary that manages authentication credentials centrally, allowing users to access multiple services through a single authentication interface. This mediator approach maintains security coverage while simplifying the user experience by abstracting away the complexity of multiple authentication systems.
3Ease of operation
If centralized cloud-based authentication is implemented, then ease of operation is improved, but device complexity increases
Solution Approach 1:
The patent extracts authentication and authorization functions from individual data center systems and relocates them to a centralized cloud-based security module. This extraction simplifies local system operations while consolidating complexity into a dedicated cloud service that can be managed independently.
Solution Approach 2:
The cloud-based security module serves as an intermediary layer between users and data center services, handling authentication complexity centrally. This mediator approach improves ease of operation at the user interface while containing system complexity within the cloud service infrastructure rather than distributing it across multiple local systems.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
It is not handy for a user if he has to reauthenticate himself when he wants to access different arrays in a cloud storage. Therefor authorization and authentication is provided in a cloud for a user of a storage array. The following steps are executed: receiving, by a cloud-based security module from a client-side array services module, user credentials; authenticating, by the cloud-based security module, the user credentials; identifying, by the cloud-based security module, authorized access privileges defining one or more storage array services accessible by the user; generating, by the cloud-based security module, a. token representing the authentication of the user credentials and the authorized access privileges; and providing, by the cloud-based security module to the client-side array services module, the token.