FC Switch Fine Granularity Authorization Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The conventional two-stage authorization process in Fibre Channel (FC) storage area networks adds complexity and latency to IO operations, as it separately enforces port zoning and logical partition masking, requiring duplicative efforts and complicating VM mobility and security.

Innovation Solution

Combining port zoning and NSID masking into a single-step authorization procedure within the FC fabric, extending it to include VM credentials for a fully-qualified tuple authorization, and using Target Driven Zoning (TDZ) to automate zoning configuration, thereby eliminating the need for explicit zoning configuration in the FC fabric.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-stage authorization is used (port zoning at FC switch + logical partition masking at storage array), then authorization enforcement is distributed across different entities, but device complexity and authorization latency increase

Engineering Contradiction:
Improveauthorization enforcementVSAvoidauthorization process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines port zoning and logical partition masking into a single unified authorization stage implemented at the FC switch. The FC switch now performs both zoning rules and LUN/NSID masking in one pass, eliminating the need for separate enforcement stages at different devices. This merging reduces the complexity of the authorization process while maintaining comprehensive security enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The FC switch is enhanced to perform multiple authorization functions simultaneously - it now handles both port zoning and logical partition masking that were previously distributed across multiple devices. This multi-functionality consolidates the authorization role at a single point in the data path, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If two-stage authorization is used (port zoning at FC switch + logical partition masking at storage array), then authorization is enforced at multiple points, but IO operation latency increases

Engineering Contradiction:
Improveauthorization enforcementVSAvoidIO operation latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges port zoning and logical partition masking into a single authorization stage at the FC switch. By combining these operations that were previously performed in sequence at different devices, the total time required for authorization is reduced, directly decreasing IO operation latency while maintaining comprehensive security checks.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The FC switch performs all necessary authorization checks (both zoning and logical partition masking) in a single preliminary stage before IO operations proceed to the storage array. This preliminary consolidation of authorization actions prevents multiple sequential checks, thereby reducing the time loss associated with multi-stage authorization.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual port zoning configuration is used in FC fabric, then zoning rules can be explicitly defined, but configuration complexity and manual effort increase

Engineering Contradiction:
Improvezoning rule enforcementVSAvoidzoning configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The storage array automatically generates and pushes port zoning rules to the FC switch fabric using Target Driven Zoning (TDZ). This self-service mechanism eliminates the need for manual configuration of zoning rules by administrators, as the system automatically derives and distributes the necessary zoning information based on logical partition masking requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback loop where the storage array communicates zoning requirements back to the FC switch fabric through TDZ. The FC switch receives and applies these zoning rules automatically, creating a closed-loop system that reduces manual configuration effort while ensuring zoning rules are properly enforced according to storage array requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10708309B2Fine granularity authorization control in FC-NVMe storage area network
Publication Date: 2020.07.07 CISCO TECHNOLOGY INC
  • US10708309B2 patent drawing
  • US10708309B2 patent drawing
  • US10708309B2 patent drawing

AI summary

A method is performed at a Fibre Channel (FC) switch of an FC switch fabric through which servers connected to the FC switch fabric access logical partitions of a storage array connected to the FC switch fabric. The FC switch receives from the storage array information indicative of port zoning rules and logical partition masking that collectively define which server ports are permitted access to which storage array ports and to which logical partitions of the storage array. The FC switch generates from the information authorization rules for enforcing the port zoning rules and the logical partition masking, and programs the authorization rules into memory. The FC switch receives FC frames from the server ports. The FC frames convey respective input-output (IO) operations destined for the logical partitions. The FC switch authorizes each IO operation based on a lookup of the programmed authorization.