FC Switch Fine Granularity Authorization Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The conventional two-stage authorization process in Fibre Channel (FC) storage area networks adds complexity and latency to IO operations, as it separately enforces port zoning and logical partition masking, requiring duplicative efforts and complicating VM mobility and security.
Innovation Solution
Combining port zoning and NSID masking into a single-step authorization procedure within the FC fabric, extending it to include VM credentials for a fully-qualified tuple authorization, and using Target Driven Zoning (TDZ) to automate zoning configuration, thereby eliminating the need for explicit zoning configuration in the FC fabric.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two-stage authorization is used (port zoning at FC switch + logical partition masking at storage array), then authorization enforcement is distributed across different entities, but device complexity and authorization latency increase
Solution Approach 1:
The patent combines port zoning and logical partition masking into a single unified authorization stage implemented at the FC switch. The FC switch now performs both zoning rules and LUN/NSID masking in one pass, eliminating the need for separate enforcement stages at different devices. This merging reduces the complexity of the authorization process while maintaining comprehensive security enforcement.
Solution Approach 2:
The FC switch is enhanced to perform multiple authorization functions simultaneously - it now handles both port zoning and logical partition masking that were previously distributed across multiple devices. This multi-functionality consolidates the authorization role at a single point in the data path, reducing overall system complexity while maintaining security.
2Reliability
If two-stage authorization is used (port zoning at FC switch + logical partition masking at storage array), then authorization is enforced at multiple points, but IO operation latency increases
Solution Approach 1:
The patent merges port zoning and logical partition masking into a single authorization stage at the FC switch. By combining these operations that were previously performed in sequence at different devices, the total time required for authorization is reduced, directly decreasing IO operation latency while maintaining comprehensive security checks.
Solution Approach 2:
The FC switch performs all necessary authorization checks (both zoning and logical partition masking) in a single preliminary stage before IO operations proceed to the storage array. This preliminary consolidation of authorization actions prevents multiple sequential checks, thereby reducing the time loss associated with multi-stage authorization.
3Reliability
If manual port zoning configuration is used in FC fabric, then zoning rules can be explicitly defined, but configuration complexity and manual effort increase
Solution Approach 1:
The storage array automatically generates and pushes port zoning rules to the FC switch fabric using Target Driven Zoning (TDZ). This self-service mechanism eliminates the need for manual configuration of zoning rules by administrators, as the system automatically derives and distributes the necessary zoning information based on logical partition masking requirements.
Solution Approach 2:
The system implements a feedback loop where the storage array communicates zoning requirements back to the FC switch fabric through TDZ. The FC switch receives and applies these zoning rules automatically, creating a closed-loop system that reduces manual configuration effort while ensuring zoning rules are properly enforced according to storage array requirements.
Data Source
AI summary
A method is performed at a Fibre Channel (FC) switch of an FC switch fabric through which servers connected to the FC switch fabric access logical partitions of a storage array connected to the FC switch fabric. The FC switch receives from the storage array information indicative of port zoning rules and logical partition masking that collectively define which server ports are permitted access to which storage array ports and to which logical partitions of the storage array. The FC switch generates from the information authorization rules for enforcing the port zoning rules and the logical partition masking, and programs the authorization rules into memory. The FC switch receives FC frames from the server ports. The FC frames convey respective input-output (IO) operations destined for the logical partitions. The FC switch authorizes each IO operation based on a lookup of the programmed authorization.


