Cloud-Based Security Module for Storage Array Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage array technologies face complexity in providing secure and efficient access and administration due to the need for multiple authentication and authorization systems across various users and services in data centers, which can lead to inefficiencies and security vulnerabilities.

Innovation Solution

A cloud-based system that integrates a cloud-based security module for authorization and authentication, allowing single sign-on through a client-side array services module and an identity provider, using protocols like SAML or OAUTH, to manage user credentials and access privileges, enabling seamless access to storage array services while maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication and authorization systems are implemented across various users and services in data centers, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication and authorization systems into a single unified cloud-based security module. This consolidation maintains comprehensive security coverage while reducing the overall system complexity by eliminating redundant authentication mechanisms and centralizing security management functions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cloud-based security module provides universal authentication and authorization services that can handle multiple users, services, and data center environments through a single system. This multi-functional approach allows the same security infrastructure to serve diverse authentication needs without requiring separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication systems are implemented, then security coverage is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidease of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The unified security module provides universal access credentials that work across all services and data centers, eliminating the need for users to manage multiple separate authentication systems. This maintains comprehensive security coverage while significantly improving ease of operation through consistent, centralized authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The cloud-based security module acts as an intermediary that manages authentication credentials centrally, allowing users to access multiple services through a single authentication interface. This mediator approach maintains security coverage while simplifying the user experience by abstracting away the complexity of multiple authentication systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If centralized cloud-based authentication is implemented, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveaccess simplicityVSAvoidcloud system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts authentication and authorization functions from individual data center systems and relocates them to a centralized cloud-based security module. This extraction simplifies local system operations while consolidating complexity into a dedicated cloud service that can be managed independently.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud-based security module serves as an intermediary layer between users and data center services, handling authentication complexity centrally. This mediator approach improves ease of operation at the user interface while containing system complexity within the cloud service infrastructure rather than distributing it across multiple local systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3304845B1Authorization and authentication in a cloud-based storage array
Publication Date: 2020.07.22 PURE STORAGE INC
  • EP3304845B1 patent drawingFigure 1
  • EP3304845B1 patent drawingFigure 2
  • EP3304845B1 patent drawingFigure 3

AI summary

It is not handy for a user if he has to reauthenticate himself when he wants to access different arrays in a cloud storage. Therefor authorization and authentication is provided in a cloud for a user of a storage array. The following steps are executed: receiving, by a cloud-based security module from a client-side array services module, user credentials; authenticating, by the cloud-based security module, the user credentials; identifying, by the cloud-based security module, authorized access privileges defining one or more storage array services accessible by the user; generating, by the cloud-based security module, a. token representing the authentication of the user credentials and the authorized access privileges; and providing, by the cloud-based security module to the client-side array services module, the token.