Composite Host Identifier for Storage Area Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data storage systems face challenges in securely managing host identities and access control, particularly when hardware components are moved or replaced, leading to potential security breaches and improper access permissions.
Innovation Solution
A method is introduced that generates a host identifier using a combination of a software-generated portion and a hardware-based non-deterministic component, which includes a unique hardware property, such as a MAC address, to uniquely identify hosts in a storage area network, and updates access control tables automatically or with user approval based on connectivity changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a software-generated host identifier is used, then host identification is simple and flexible, but security is compromised when system images are cloned
Solution Approach 1:
The patent combines software-generated host identifiers with hardware-based identifiers (such as HBA WWNs) to create a composite identification system. This merging allows the system to benefit from both the flexibility of software-generated IDs and the uniqueness/security of hardware-based IDs, preventing unauthorized access while maintaining ease of operation.
2Reliability
If hardware-based host identifier is used, then unique identification is achieved, but access control issues arise when hardware is moved or replaced
Solution Approach 1:
The patent implements a dynamic access control system that can adapt when hardware changes are detected. The system monitors hardware identifier changes and automatically updates access control permissions, allowing legitimate hardware moves while maintaining security. This dynamic approach resolves the contradiction between unique identification and adaptability.
Solution Approach 2:
The system performs preliminary actions by pre-configuring access control rules that account for potential hardware changes. When hardware identifiers are registered, the system proactively establishes access permissions that can accommodate future legitimate hardware moves, preventing both unauthorized access and improper denial of service.
3Reliability
If manual access control updates are required, then security is maintained, but system productivity decreases
Solution Approach 1:
The patent implements a self-service access control system that automatically detects hardware changes, validates them against security policies, and updates access control tables without manual intervention. This automation maintains security while eliminating the productivity loss associated with manual updates, as the system serves itself in managing access control.
Solution Approach 2:
The system employs feedback mechanisms where access control permissions are continuously monitored and automatically adjusted based on detected hardware changes. This closed-loop approach ensures security is maintained while eliminating manual intervention, as the system uses feedback from hardware identifier monitoring to self-correct access control settings.
Data Source
AI summary
Described is a technique for providing a host identifier for a host. A first portion associated with a characteristic of said host is received. A second portion including a non-deterministic component is received. The host identifier is formed using the first portion and the second portion. The host identifier is used to uniquely identify the host in a storage area network.


