Composite Host Identifier for Storage Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage systems face challenges in securely managing access, particularly when software-generated host identifiers are cloned or hardware components are moved or replaced, leading to security issues and improper access permissions.

Innovation Solution

A method is introduced that combines a software-generated identifier with a hardware property-based identifier to uniquely identify hosts in a storage area network, using a first portion generated from the system image and a second portion based on hardware properties, such as a network interface card's MAC address, to form a host identifier. This method processes management requests to determine the degree of correspondence with existing access control table entries and performs actions based on identified differences, updating the table as necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a software-generated host identifier is used, then ease of operation is improved, but security and reliability deteriorate due to cloning issues

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines a software-generated identifier (first portion) with a hardware-based identifier (second portion) to form a composite host identifier. This merging allows the system to retain the ease of software generation while incorporating the uniqueness and security of hardware properties, thereby resolving the contradiction between operational ease and security reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The host identifier is constructed as a composite entity with two distinct portions: a software-generated component and a hardware-derived component. This composite structure leverages the advantages of both software flexibility and hardware uniqueness, preventing identifier cloning while maintaining operational simplicity.

Inventive Principle:
Principle #40Composite materials

2Reliability

If a hardware property-based identifier is used, then security and reliability are improved, but adaptability deteriorates due to hardware replacement issues

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically evaluates the relationship between the first and second portions of the host identifier to determine the appropriate action. When hardware changes occur, the system can adapt by detecting the mismatch and triggering reconfiguration procedures, thereby maintaining security while accommodating hardware replacements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent allows the host identifier parameters to change based on hardware status. When hardware properties change, the second portion of the identifier is updated, and the system adjusts access permissions accordingly. This enables the system to adapt to hardware replacements while maintaining security through controlled parameter changes.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a composite host identifier is used, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The host identifier is segmented into two distinct portions with clear functional separation. The first portion (software-generated) and second portion (hardware-based) are processed independently, allowing the system to manage complexity through modular handling of each component rather than treating the identifier as an indivisible complex entity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism that compares the first and second portions of the host identifier to detect mismatches. This intermediary comparison process simplifies the overall system by providing a clear decision point for determining whether hardware changes have occurred, thereby managing complexity through a structured intermediate evaluation step.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If hardware changes are detected, then security is improved by revoking improper access, but loss of time occurs during access control updates

Engineering Contradiction:
ImprovesecurityVSAvoidtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary comparison of the first and second portions of the host identifier as part of the access control process. By proactively detecting hardware changes before they result in unauthorized access, the system can preemptively update access permissions, thereby reducing the time loss associated with reactive security measures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the comparison result of the host identifier portions feeds back into the access control decision process. When a mismatch is detected, the system receives feedback indicating hardware changes and automatically triggers access permission updates, creating a closed-loop system that minimizes time loss through automated responsive action.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8185639B2Server identification in storage networks
Publication Date: 2012.05.22 EMC IP HLDG CO LLC
  • US8185639B2 patent drawing
  • US8185639B2 patent drawing
  • US8185639B2 patent drawing

AI summary

Described are techniques for providing a host identifier for a host. A first portion including a first identifier associated with a system for the host is received. A second portion including a second identifier generated in accordance with a hardware property of the host is received. The host identifier is formed using the first and second portions. The host identifier is used to uniquely identify the host in a storage area network.