Automated Host Migration to Authenticated Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual reconfiguration of host servers and storage arrays to use endpoint authentication is slow, error-prone, and impractical due to the need for configuring unique authentication credentials across multiple initiator-target paths in large data centers.

Innovation Solution

An automated method and apparatus that generate unique authentication credentials, select uncredentialed paths, pause data access, and provide these credentials to host servers and storage nodes for non-disruptive reconfiguration using endpoint authentication protocols like CHAP.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual reconfiguration of host servers and storage arrays is performed to use endpoint authentication, then security is improved, but reconfiguration time and error rate increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidreconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-service through automated credential generation and distribution. The management appliance automatically generates unique authentication credentials, distributes them to host servers and storage arrays, and manages the reconfiguration process without requiring manual administrator intervention for each device, thereby reducing reconfiguration time while maintaining security improvements

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A management appliance acts as an intermediary between host servers and storage arrays. This intermediary automatically manages credential generation, distribution, and reconfiguration across the entire storage network, eliminating the need for administrators to manually configure each device individually, thus significantly reducing reconfiguration time and errors

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual reconfiguration is performed across hundreds or thousands of host servers with multiple paths each, then endpoint authentication is implemented, but the complexity and impracticality of the task increases

Engineering Contradiction:
Improveendpoint authentication implementationVSAvoidreconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The management appliance provides universal functionality by automatically managing credential generation and distribution across diverse host servers and storage arrays regardless of the number of paths or devices. This multi-functional system handles the entire reconfiguration process uniformly, making the complex task of authenticating hundreds or thousands of devices practical and manageable

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automates the complex credential management process through self-service mechanisms. The management appliance automatically generates unique credentials for each initiator-target path, distributes them appropriately, and manages reconfiguration without requiring administrators to manually handle the complexity of configuring each device and path individually

Inventive Principle:
Principle #25Self-service

3Reliability

If unique authentication credentials are configured for each initiator-target path as required by standards, then security compliance is achieved, but the number of required reconfigurations becomes impractical

Engineering Contradiction:
Improvesecurity complianceVSAvoidease of reconfiguration
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The management appliance performs self-service by automatically generating unique authentication credentials for each initiator-target path in compliance with iSCSI standards. It then automatically distributes these credentials to the appropriate host servers and storage arrays, eliminating the need for administrators to manually configure each path while maintaining full security compliance

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The management appliance serves as an intermediary that automates the creation and distribution of unique authentication credentials for each initiator-target path. This intermediary handles the complex task of generating and managing credentials across the entire storage network, making security compliance achievable and practical rather than impractical

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11747999B1Automated non-disruptive migration of hosts to an authenticated storage array connection
Publication Date: 2023.09.05 DELL PROD LP
  • US11747999B1 patent drawing
  • US11747999B1 patent drawing
  • US11747999B1 patent drawing

AI summary

A management appliance communicates with host servers and a storage array to determine per-path loading. Based on the loading, the management appliance selects a host server with an uncredentialed path for reconfiguration. Unique endpoint authentication credentials are sent from the management appliance to the selected host server and the storage array. The uncredentialed path is placed in standby mode and the selected host server and the storage array are updated with the unique endpoint authentication credentials, which are then used to reactivate the path with endpoint authentication. Tight coupling between the MPIO software management appliance, storage array, and MPIO drivers on the host servers enables reconfiguration to be automated and based on host server loading, storage array loading, and loading of uncredentialed paths.