Automated Host Migration to Authenticated Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manual reconfiguration of host servers and storage arrays to use endpoint authentication is slow, error-prone, and impractical due to the need for configuring unique authentication credentials across multiple initiator-target paths in large data centers.
Innovation Solution
An automated method and apparatus that generate unique authentication credentials, select uncredentialed paths, pause data access, and provide these credentials to host servers and storage nodes for non-disruptive reconfiguration using endpoint authentication protocols like CHAP.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual reconfiguration of host servers and storage arrays is performed to use endpoint authentication, then security is improved, but reconfiguration time and error rate increase significantly
Solution Approach 1:
The system performs self-service through automated credential generation and distribution. The management appliance automatically generates unique authentication credentials, distributes them to host servers and storage arrays, and manages the reconfiguration process without requiring manual administrator intervention for each device, thereby reducing reconfiguration time while maintaining security improvements
Solution Approach 2:
A management appliance acts as an intermediary between host servers and storage arrays. This intermediary automatically manages credential generation, distribution, and reconfiguration across the entire storage network, eliminating the need for administrators to manually configure each device individually, thus significantly reducing reconfiguration time and errors
2Reliability
If manual reconfiguration is performed across hundreds or thousands of host servers with multiple paths each, then endpoint authentication is implemented, but the complexity and impracticality of the task increases
Solution Approach 1:
The management appliance provides universal functionality by automatically managing credential generation and distribution across diverse host servers and storage arrays regardless of the number of paths or devices. This multi-functional system handles the entire reconfiguration process uniformly, making the complex task of authenticating hundreds or thousands of devices practical and manageable
Solution Approach 2:
The system automates the complex credential management process through self-service mechanisms. The management appliance automatically generates unique credentials for each initiator-target path, distributes them appropriately, and manages reconfiguration without requiring administrators to manually handle the complexity of configuring each device and path individually
3Reliability
If unique authentication credentials are configured for each initiator-target path as required by standards, then security compliance is achieved, but the number of required reconfigurations becomes impractical
Solution Approach 1:
The management appliance performs self-service by automatically generating unique authentication credentials for each initiator-target path in compliance with iSCSI standards. It then automatically distributes these credentials to the appropriate host servers and storage arrays, eliminating the need for administrators to manually configure each path while maintaining full security compliance
Solution Approach 2:
The management appliance serves as an intermediary that automates the creation and distribution of unique authentication credentials for each initiator-target path. This intermediary handles the complex task of generating and managing credentials across the entire storage network, making security compliance achievable and practical rather than impractical
Data Source
AI summary
A management appliance communicates with host servers and a storage array to determine per-path loading. Based on the loading, the management appliance selects a host server with an uncredentialed path for reconfiguration. Unique endpoint authentication credentials are sent from the management appliance to the selected host server and the storage array. The uncredentialed path is placed in standby mode and the selected host server and the storage array are updated with the unique endpoint authentication credentials, which are then used to reactivate the path with endpoint authentication. Tight coupling between the MPIO software management appliance, storage array, and MPIO drivers on the host servers enables reconfiguration to be automated and based on host server loading, storage array loading, and loading of uncredentialed paths.


