Composite Host Identifier for Storage Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data storage systems face challenges in securely managing access, particularly when software-generated host identifiers are cloned or hardware components are moved or replaced, leading to security issues and improper access permissions.
Innovation Solution
A method is introduced that combines a software-generated identifier with a hardware property-based identifier to uniquely identify hosts in a storage area network, using a first portion generated from the system image and a second portion based on hardware properties, such as a network interface card's MAC address, to form a host identifier. This method processes management requests to determine the degree of correspondence with existing access control table entries and performs actions based on identified differences, updating the table as necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a software-generated host identifier is used, then ease of operation is improved, but security and reliability deteriorate due to cloning issues
Solution Approach 1:
The patent combines a software-generated identifier (first portion) with a hardware-based identifier (second portion) to form a composite host identifier. This merging allows the system to retain the ease of software generation while incorporating the uniqueness and security of hardware properties, thereby resolving the contradiction between operational ease and security reliability.
Solution Approach 2:
The host identifier is constructed as a composite entity with two distinct portions: a software-generated component and a hardware-derived component. This composite structure leverages the advantages of both software flexibility and hardware uniqueness, preventing identifier cloning while maintaining operational simplicity.
2Reliability
If a hardware property-based identifier is used, then security and reliability are improved, but adaptability deteriorates due to hardware replacement issues
Solution Approach 1:
The system dynamically evaluates the relationship between the first and second portions of the host identifier to determine the appropriate action. When hardware changes occur, the system can adapt by detecting the mismatch and triggering reconfiguration procedures, thereby maintaining security while accommodating hardware replacements.
Solution Approach 2:
The patent allows the host identifier parameters to change based on hardware status. When hardware properties change, the second portion of the identifier is updated, and the system adjusts access permissions accordingly. This enables the system to adapt to hardware replacements while maintaining security through controlled parameter changes.
3Reliability
If a composite host identifier is used, then security and reliability are improved, but device complexity increases
Solution Approach 1:
The host identifier is segmented into two distinct portions with clear functional separation. The first portion (software-generated) and second portion (hardware-based) are processed independently, allowing the system to manage complexity through modular handling of each component rather than treating the identifier as an indivisible complex entity.
Solution Approach 2:
The patent introduces an intermediary mechanism that compares the first and second portions of the host identifier to detect mismatches. This intermediary comparison process simplifies the overall system by providing a clear decision point for determining whether hardware changes have occurred, thereby managing complexity through a structured intermediate evaluation step.
4Reliability
If hardware changes are detected, then security is improved by revoking improper access, but loss of time occurs during access control updates
Solution Approach 1:
The system performs preliminary comparison of the first and second portions of the host identifier as part of the access control process. By proactively detecting hardware changes before they result in unauthorized access, the system can preemptively update access permissions, thereby reducing the time loss associated with reactive security measures.
Solution Approach 2:
The patent implements a feedback mechanism where the comparison result of the host identifier portions feeds back into the access control decision process. When a mismatch is detected, the system receives feedback indicating hardware changes and automatically triggers access permission updates, creating a closed-loop system that minimizes time loss through automated responsive action.
Data Source
AI summary
Described are techniques for providing a host identifier for a host. A first portion including a first identifier associated with a system for the host is received. A second portion including a second identifier generated in accordance with a hardware property of the host is received. The host identifier is formed using the first and second portions. The host identifier is used to uniquely identify the host in a storage area network.


