Host-Enabled Storage Management via Segmented Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mass storage systems require human administrator intervention for storage resource management, which is slow, error-prone, and not suitable for large-scale operations, as they lack automated access to the management layer for hosts.

Innovation Solution

A method that allows hosts to access the storage management layer through a management communication interface, with access information provided by the system, including authentication and usage restrictions, enabling hosts to perform management commands traditionally handled by administrators, such as volume creation and snapshot management, while ensuring secure and controlled access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If human administrators manually manage storage resources through CLI or web interfaces, then security and control are maintained, but operational speed and accessibility deteriorate

Engineering Contradiction:
Improvestorage management speedVSAvoidadministrator involvement requirement
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The host is enabled to autonomously perform storage management operations by directly accessing the management layer. The host can create, delete, and manage storage volumes without requiring administrator intervention, effectively making the system self-serving for management tasks. This is achieved by providing the host with access information including authentication credentials and usage parameters.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The access information is segmented into multiple components: authentication information for security verification, usage information for operational parameters, and restrictions information for access control. This segmentation allows the system to provide granular control over host capabilities while enabling automated operations.

Inventive Principle:
Principle #1Segmentation

2Extent of automation

If hosts are granted direct access to the management layer, then automation and scalability improve, but system security and access control complexity worsen

Engineering Contradiction:
Improvehost-enabled management capabilityVSAvoidaccess control mechanism
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

Different hosts are provided with different access information tailored to their specific needs and authorization levels. Each host receives authentication information, usage information, and restrictions information that is customized to its role and permissions. This local differentiation allows automation while maintaining precise access control without requiring a completely complex centralized authorization system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The management layer acts as an intermediary between hosts and storage resources. Instead of hosts directly manipulating storage hardware, all management operations are routed through the management layer which enforces access control policies, validates authentication information, and applies usage restrictions. This intermediary approach simplifies security implementation while enabling host automation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If manual administrator intervention is required for storage management, then access control is simplified, but operational efficiency and error rates worsen

Engineering Contradiction:
Improvestorage operation efficiencyVSAvoidhuman error susceptibility
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The host autonomously performs storage management operations including volume creation, deletion, and modification without human intervention. The host uses provided authentication information to securely access the management layer and execute operations based on its usage information and within defined restrictions. This eliminates human errors associated with manual CLI or web interface operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system provides structured feedback mechanisms where the management layer validates host requests against authentication information, usage information, and restrictions information. This feedback loop ensures that automated operations conform to security policies and usage parameters, maintaining reliability while enabling automation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9087201B2System and methods for host enabled management in a storage system
Publication Date: 2015.07.21 INFINIDAT LTD
  • US9087201B2 patent drawing
  • US9087201B2 patent drawing
  • US9087201B2 patent drawing

AI summary

A storage system that includes a management communication interface coupled to a storage management layer and further includes a data communication interface. Upon receiving a request for accessing the storage management layer, from the host, via the data communication interface, the management layer sends to the host, access information necessary for allowing access of the host to the storage management layer via the management communication interface; and upon receiving a management command, from the host via the management communication interface, the host is provided with access to the storage management layer, in cases where the management command conforms to the access information.