iSCSI Ether Zoning via VLAN and ACL Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The iSCSI protocol lacks effective zoning capabilities in Ethernet fabrics, which compromises security and efficiency, especially in enterprise-level data center configurations, where complete zoning solutions are absent.

Innovation Solution

The introduction of 'Ether Zoning' enables zoning at the frame level by configuring VLANs and ACLs between iSCSI initiators and targets, using in-band commands and automated zone group creation, allowing for secure and efficient segregation of devices within the Ethernet fabric.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If iSCSI protocol is used in Ethernet fabric without zoning, then ease of operation is improved, but security is compromised

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements frame-level zoning by segmenting the Ethernet fabric into distinct zones using VLANs and ACLs. Each zone isolates specific iSCSI initiators and targets, allowing security policies to be applied at the frame level rather than requiring complete protocol redesign. This segmentation enables security enforcement while preserving iSCSI operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary zoning mechanism between iSCSI initiators and targets at the Ethernet switch level. This intermediary layer uses VLANs and ACLs to control frame forwarding decisions, acting as a mediator that enforces security policies without requiring changes to the iSCSI protocol itself or significant infrastructure modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If frame-level zoning is implemented in iSCSI fabric, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages existing multi-functional capabilities of Ethernet switches by utilizing their built-in VLAN and ACL features for iSCSI zoning. Rather than introducing dedicated zoning hardware or protocol modifications, the solution repurposes universal Ethernet switching functions to provide frame-level security, thereby avoiding additional device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables the existing Ethernet infrastructure to serve the zoning function through self-configuration using standard VLAN and ACL mechanisms. The Ethernet switches use their own native security features to enforce iSCSI zoning policies, allowing the system to self-manage security without requiring external specialized devices or complex additional infrastructure.

Inventive Principle:
Principle #25Self-service

3Reliability

If complete zoning solution is implemented, then security is improved, but infrastructure changes are required

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure changes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary zoning mechanism between iSCSI initiators and targets at the Ethernet switch level. This intermediary layer uses VLANs and ACLs to control frame forwarding decisions, acting as a mediator that enforces security policies without requiring changes to the iSCSI protocol itself or significant infrastructure modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements zoning by changing parameters of existing Ethernet frames (VLAN tags, ACL rules) rather than requiring fundamental infrastructure changes. By modifying frame-level parameters and utilizing existing switch configurations, the solution achieves complete zoning functionality while minimizing changes to the overall infrastructure.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11283804B2Group zoning and access control over a network
Publication Date: 2022.03.22 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11283804B2 patent drawing
  • US11283804B2 patent drawing
  • US11283804B2 patent drawing

AI summary

Example implementations relate to hard zoning capabilities for devices using Internet small computer system interface (iSCSI) protocol. For example, a method includes creating a virtual local area network (VLAN) at an Ethernet switch between an initiator and target adapter. The method includes assigning an access control list (ACL) to the VLAN, The method includes segregating a device of a plurality of devices connected to the SAN into a zone group. The method also includes controlling access of a zone group based on the ACL and frame filtering.