Host Port Audit Mode for Storage Security Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Fibre Channel environments, existing security protocols do not provide mechanisms to maintain access for host systems when authentication or security association negotiation with storage ports cannot be completed successfully, particularly in heterogeneous computing environments with legacy systems that do not support security.

Innovation Solution

The introduction of an audit mode indicator allows host ports to preserve I/O access to storage ports even if authentication or security association negotiation fails, by enabling security without enforcement, thus ensuring continuous connectivity for I/O operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security association negotiation is enforced, then security reliability is improved, but system compatibility deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements partial security enforcement by introducing an audit mode that allows the system to operate with security negotiations attempted but not strictly enforced. This enables legacy systems without security support to maintain connectivity while newer systems can still attempt security associations, thus resolving the contradiction between security reliability and system compatibility.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the enforcement parameter of security association negotiation by introducing a new operational mode (audit mode) that modifies the strictness of security requirements. This parameter change allows the system to flex between enforced security and permissive compatibility, resolving the technical contradiction.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication is required, then security is improved, but access continuity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The audit mode implements partial authentication enforcement by allowing I/O operations to continue even when security associations fail to establish. This partial approach maintains access continuity while still attempting security negotiations, resolving the contradiction between security and access continuity.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system prepares for potential authentication failures by implementing an audit mode that acts as a cushion or fallback mechanism. This allows the system to absorb security negotiation failures without losing access continuity, thus resolving the technical contradiction.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If security enforcement is implemented, then security reliability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent manages system complexity by changing the operational parameter from strict enforcement to audit mode. This parameter change simplifies the system state by allowing security negotiations to be attempted without requiring complex fallback mechanisms for failed authentications, thus resolving the contradiction between security reliability and system complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12326966B2Maintenance of access for security enablement on a host system
Publication Date: 2025.06.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12326966B2 patent drawing
  • US12326966B2 patent drawing
  • US12326966B2 patent drawing

AI summary

A host port is enabled for security. In response to a determination by the host port that authentication or security association negotiation with a storage port cannot be completed successfully, the host port determines whether an audit mode indicator has been enabled in a login response from the storage port. The host port preserves input/output (I/O) access to the storage port based on determining whether the audit mode indicator has been enabled in the login response from the storage port.