Fibre Channel Peer Zoning for Storage Fabric Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Fibre Channel zoning schemes require the creation of numerous zones to prevent host device-to-host device communication, leading to management complexities in automated storage provisioning environments, as they allow all devices within a zone to communicate with each other, necessitating the definition of multiple two-member zones.

Innovation Solution

The introduction of a peer zone definition that allows multiple initiator host devices to communicate with a target device while preventing communication among themselves, utilizing a new zone attribute and simplified commands (AAPZ, RAPZ, and GAPZ) to manage peer zones within the Fibre Channel Fabric, enabling efficient and restrictive access control without the need for numerous two-member zones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional Fibre Channel zoning schemes are used to prevent host device-to-host device communication, then security is improved, but the number of zones required increases significantly, leading to management complexity

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple two-member zones into a single peer zone that contains multiple initiators and one target. This consolidation reduces the total number of zones required while maintaining the same security function of preventing initiator-to-initiator communication. The peer zone attribute enables this merging by specifying that the zone contains peer initiators that cannot communicate with each other.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The peer zone serves multiple functions simultaneously: it allows multiple initiators to access a single target, prevents initiator-to-initiator communication, and reduces management complexity. This multi-functionality is achieved through the peer zone attribute that defines the zone's restrictive nature, eliminating the need for separate zones for each initiator-target pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple two-member zones are created to restrict communication, then access control is improved, but the number of zone definitions increases, reducing productivity

Engineering Contradiction:
Improveaccess controlVSAvoidzoning management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines multiple access control rules into a single peer zone definition. Instead of creating separate zones for each initiator-target relationship, a single peer zone can accommodate multiple initiators while maintaining restrictive access control. This merging dramatically reduces the number of zone definitions required and improves zoning management efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The invention introduces a new zone attribute called 'peer zone' that changes the fundamental parameters of zone behavior. This attribute enables the zone to restrict communication between initiators while allowing access to the target, fundamentally altering how access control is implemented and reducing the number of zone definitions needed.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If conventional zoning is used to allow multiple initiators to access a target, then connectivity is improved, but all initiators can communicate with each other, reducing security

Engineering Contradiction:
Improveinitiator access capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by creating different communication permissions for different pairs of devices within the same zone. The peer zone attribute enables initiators to have access to the target while simultaneously restricting their ability to communicate with each other. This localized control of communication permissions achieves both connectivity and security requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of allowing all communication within a zone and then restricting specific paths, the peer zone inverts the approach by defaulting to restrictive communication and allowing specific authorized paths. The peer zone attribute establishes that initiators cannot communicate with each other unless explicitly permitted, reversing the conventional permissive zone model.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS9871864B2Fibre channel peer zoning
Publication Date: 2018.01.16 CISCO TECHNOLOGY INC
  • US9871864B2 patent drawing
  • US9871864B2 patent drawing
  • US9871864B2 patent drawing

AI summary

Techniques are provided for the creation of a peer zone definition for use in a Fibre Channel (FC) Fabric. The peer zone definition defines a peer zone in which two or more initiator host devices are each permitted to communicate with a target device, but the two or more initiator host devices are prevented from communicating with each other. In accordance with one example, a target device and of two or more initiator host devices connected to the FC Fabric are received. A peer zone definition is created, and the peer zone definition is transmitted to the switches composing the FC Fabric for enforcement.