Fibre Channel Switch Traffic Sampling for Soft Zoning Violation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Soft zoning in Fibre Channel (FC) networks is vulnerable to unauthorized access and network instability due to its reliance on an honor system, leading to potential security breaches and bandwidth wastage, as access restrictions can be easily circumvented.

Innovation Solution

Implementing a method where the FC switch samples traffic to identify unauthorized access attempts and enforces access restrictions by configuring ACL entries to deny permissions, shutting down ports of endpoint devices that send traffic outside their assigned zones, and replicating zoning information for redundancy to maintain security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If soft zoning is implemented to provide security against unauthorized access, then network security is improved, but network stability deteriorates due to violations causing instability and bandwidth reduction

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent implements a feedback mechanism where the FC switch monitors traffic between endpoint devices and detects soft zoning violations. When a violation is detected (traffic outside assigned zones), the system automatically responds by isolating the violating endpoint device through port shutdown or ACL configuration, thereby maintaining network stability while preserving security.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service by allowing the FC switch to autonomously detect violations and enforce isolation without requiring manual intervention. The switch automatically configures ACL entries or shuts down ports based on detected zoning violations, making the system self-regulating and maintaining stability automatically.

Inventive Principle:
Principle #25Self-service

2Device complexity

If soft zoning relies on an honor system to restrict access, then device complexity is reduced, but security deteriorates as access restrictions can be easily circumvented

Engineering Contradiction:
Improvezoning enforcement complexityVSAvoidaccess restriction security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent replaces the mechanical/trust-based honor system with an automated monitoring and enforcement mechanism. Instead of relying on endpoint devices to honor zoning rules, the FC switch actively monitors traffic patterns and automatically enforces restrictions through ACL configuration or port shutdown, substituting trust with technical control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If endpoint devices are allowed to access any target device, then ease of operation is improved, but security deteriorates due to unauthorized access and bandwidth wastage

Engineering Contradiction:
Improvedevice accessibilityVSAvoidunauthorized access prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies partial action by allowing endpoint devices to access only their assigned zones while automatically blocking access to unauthorized zones. This selective enforcement maintains ease of operation for legitimate access while preventing unauthorized access, applying restrictions only where necessary rather than universally.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11729116B2Violation detection and isolation of endpoint devices in soft zoning environment
Publication Date: 2023.08.15 DELL PROD LP
  • US11729116B2 patent drawing
  • US11729116B2 patent drawing
  • US11729116B2 patent drawing

AI summary

Systems and methods for handling soft zoning violations comprise assigning a first target device and an endpoint device that is coupled to a switch port of a Fibre Channel (FC) switch to a zone(s). In embodiments, in response to the endpoint device logging into the FC switch, sampled traffic that originates at the endpoint device and ingresses at the switch port may be obtained. In response to determining that the sampled traffic comprises a second traffic that is intended for a second target device that has not been assigned to the zone(s), some action to restrict the second traffic may be performed such as to restrict the non-assigned traffic and prevent devices from sending potentially harmful traffic to other devices that are not assigned to a same zone.