Host Connectivity Authentication via Registration Table

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems face challenges in securely establishing connectivity between hosts and data storage systems, particularly due to manual and error-prone processes in defining initiator groups, port groups, and storage groups, which can lead to inefficient authentication and access control.

Innovation Solution

A method and system for automatically determining initiator groups, port groups, and storage groups by processing login commands with a registration table, using a key or secret string for authentication, and creating masking views to control access and service I/O operations, thereby enhancing security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual processes are used to define initiator groups, port groups, and storage groups, then flexibility in configuration is maintained, but error rate increases and authentication efficiency decreases

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidauthentication automation
Core Design Contradiction:
Manufacturing precisionVSExtent of automation

Solution Approach 1:

The system performs self-service by automatically defining initiator groups, port groups, and storage groups based on login command processing. The registration table enables the system to autonomously authenticate hosts and establish connectivity without manual intervention, thereby reducing errors while maintaining configuration flexibility through programmatic logic.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-defining groups and authentication parameters before actual data storage operations begin. The registration table is prepared in advance with host authentication information, allowing rapid and accurate authentication when hosts initiate connections, thus improving both accuracy and efficiency.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication information is verified for every login command, then security is improved, but processing time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidlogin processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication information is verified in advance during the login command processing stage, and authenticated hosts are recorded in the registration table. This preliminary authentication ensures security while enabling faster subsequent access, as the system has already validated host credentials before establishing connectivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of authentication information in the registration table after successful verification. This copied authentication data allows the system to quickly reference previously validated host credentials without re-verifying every single login attempt, thus maintaining security while reducing processing time for repeated connections.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11068581B1Techniques for establishing host connectivity
Publication Date: 2021.07.20 EMC IP HLDG CO LLC
  • US11068581B1 patent drawing
  • US11068581B1 patent drawing
  • US11068581B1 patent drawing

AI summary

Techniques for establishing connectivity may include receiving a first login command from an initiator port at a target port; and determining whether the first login command includes valid login authentication information for the initiator port that sent the first login command, and whether the initiator port identifier of the initiator port that sent the first login command includes a key. If the first login command does not include valid login authentication information and the initiator port identifier includes the key, first processing may be performed including: recording first information about the first login command in a registration table; and rejecting the first login command. A second login command may be received from the initiator port at the target port. If the second login command includes valid login authentication information for the initiator port, the second login command may be successfully processed to log the initiator port into the target port.