Host Storage Authentication via Signed Credential Packets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage area network security methods are complex, costly, or protocol-specific, and may be vulnerable to spoofing or misconfiguration, particularly in multi-tenant environments where strong security and isolation are necessary.
Innovation Solution
A host authentication method that embeds credentials into a block storage protocol data packet, which is cryptographically signed by a trusted certificate authority and interleaved into the data path between the host and storage system, allowing for validation by the storage manager using enrollment credentials and a certificate authority certificate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional storage area network security methods are used, then security protection is provided, but the system becomes complex and costly
Solution Approach 1:
The patent introduces a certificate authority as an intermediary that issues digital certificates to hosts. This mediator enables security verification through standardized cryptographic protocols rather than complex custom security implementations, reducing system complexity while maintaining strong security protection.
Solution Approach 2:
The patent replaces mechanical security configurations (such as manual access control list management and physical security setups) with cryptographic authentication mechanisms. Digital certificates and cryptographic signatures automate security verification, eliminating complex manual security management while providing robust protection.
2Reliability
If traditional storage area network security methods are used, then security protection is provided, but implementation costs increase
Solution Approach 1:
The patent implements a universal authentication mechanism using digital certificates that can be applied across different storage area network configurations and protocols. This single approach replaces multiple specialized security implementations, reducing overall implementation costs while providing consistent security protection throughout the system.
Solution Approach 2:
The patent changes the security verification parameter from complex configuration-based authentication to certificate-based cryptographic authentication. This parameter change simplifies the authentication process and reduces implementation costs by using standardized cryptographic libraries rather than custom security software.
3Reliability
If protocol-specific security methods are used, then security is provided for specific protocols, but the solution lacks adaptability to different protocols
Solution Approach 1:
The patent creates a universal authentication framework using digital certificates that works across multiple storage protocols (FC, iSCSI, FCoE, AoE). The certificate-based authentication mechanism is protocol-agnostic, providing the same security level regardless of which protocol is used, thereby achieving both security and adaptability.
Solution Approach 2:
The patent separates the authentication function from the data transfer protocol. The certificate verification process is segmented as a distinct authentication phase that occurs independently of the specific storage protocol being used. This segmentation allows the same authentication mechanism to work with different protocols without requiring protocol-specific security implementations.
Data Source
AI summary
Example implementations may relate to a host and a storage system that communicate by a block storage protocol. For example, the host may embed host credentials in a data packet of the block storage protocol, and the data packet of host credentials may be cryptographically signed by a certificate authority trusted by a user of the host to generate a signed credential packet. The signed credential packet may be transmitted in a data path between the host and the storage system. The storage system may validate the signed credential packet using enrollment credentials and a certificate authority certificate and may authenticate the host to a logical unit.


