Host Connectivity Authentication via Registration Table
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems face challenges in securely establishing connectivity between hosts and data storage systems, particularly due to manual and error-prone processes in defining initiator groups, port groups, and storage groups, which can lead to inefficient authentication and access control.
Innovation Solution
A method and system for automatically determining initiator groups, port groups, and storage groups by processing login commands with a registration table, using a key or secret string for authentication, and creating masking views to control access and service I/O operations, thereby enhancing security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If manual processes are used to define initiator groups, port groups, and storage groups, then flexibility in configuration is maintained, but error rate increases and authentication efficiency decreases
Solution Approach 1:
The system performs self-service by automatically defining initiator groups, port groups, and storage groups based on login command processing. The registration table enables the system to autonomously authenticate hosts and establish connectivity without manual intervention, thereby reducing errors while maintaining configuration flexibility through programmatic logic.
Solution Approach 2:
The system performs preliminary actions by pre-defining groups and authentication parameters before actual data storage operations begin. The registration table is prepared in advance with host authentication information, allowing rapid and accurate authentication when hosts initiate connections, thus improving both accuracy and efficiency.
2Reliability
If authentication information is verified for every login command, then security is improved, but processing time increases
Solution Approach 1:
Authentication information is verified in advance during the login command processing stage, and authenticated hosts are recorded in the registration table. This preliminary authentication ensures security while enabling faster subsequent access, as the system has already validated host credentials before establishing connectivity.
Solution Approach 2:
The system creates a copy of authentication information in the registration table after successful verification. This copied authentication data allows the system to quickly reference previously validated host credentials without re-verifying every single login attempt, thus maintaining security while reducing processing time for repeated connections.
Data Source
AI summary
Techniques for establishing connectivity may include receiving a first login command from an initiator port at a target port; and determining whether the first login command includes valid login authentication information for the initiator port that sent the first login command, and whether the initiator port identifier of the initiator port that sent the first login command includes a key. If the first login command does not include valid login authentication information and the initiator port identifier includes the key, first processing may be performed including: recording first information about the first login command in a registration table; and rejecting the first login command. A second login command may be received from the initiator port at the target port. If the second login command includes valid login authentication information for the initiator port, the second login command may be successfully processed to log the initiator port into the target port.


