iSCSI Name Forwarding for Security Appliance Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network environments, inserting a security appliance between clients and storage systems without proper iSCSI name mapping can render the environment inoperable, requiring complex and costly reconfiguration of multiple iSCSI names.

Innovation Solution

An iSCSI name forwarding technique that allows a security appliance to intercept and manage iSCSI names by extracting the initiator name from client requests, querying the storage system for target names, and populating an internal mapping table to forward these names, enabling the appliance to assume client and storage system names without reconfiguration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security appliance is inserted between clients and storage systems, then security functionality is improved, but the system becomes inoperable due to iSCSI name conflicts

Engineering Contradiction:
Improvesecurity functionalityVSAvoidsystem operability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security appliance acts as an intermediary that intercepts iSCSI discovery requests from clients, extracts initiator names, queries the storage system for target names, and maintains an internal mapping table to forward names. This mediator approach allows the appliance to assume client and storage system names without reconfiguration, resolving the operability issue while maintaining security functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If iSCSI name mapping is configured manually, then name conflicts are resolved, but device complexity and reconfiguration requirements increase

Engineering Contradiction:
Improvename conflict resolutionVSAvoidreconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security appliance performs self-service by automatically extracting initiator names from client requests, querying the storage system for target names, and populating its internal mapping table without manual configuration. This eliminates the need for administrators to manually configure iSCSI name mappings, reducing complexity while ensuring reliable name conflict resolution.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If multiple iSCSI names are managed manually, then name mapping accuracy is improved, but management time and complexity increase

Engineering Contradiction:
Improvename mapping accuracyVSAvoidmanagement time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The security appliance performs preliminary actions by automatically extracting initiator names from discovery requests before they reach the storage system, querying for target names in advance, and pre-populating the internal mapping table. This preliminary processing ensures accurate name mapping without requiring manual intervention or time-consuming configuration tasks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8181011B1iSCSI name forwarding technique
Publication Date: 2012.05.15 NETAPP INC
  • US8181011B1 patent drawing
  • US8181011B1 patent drawing
  • US8181011B1 patent drawing

AI summary

An iSCSI name forwarding technique allows a security appliance to assume iSCSI names of one or more clients and one or more storage systems in a network. The security appliance is coupled between each client and storage system, and is configured to intercept a data access request issued by the client that is destined for the storage system. Each iSCSI name of the storage system is an iSCSI target name associated with secure storage, i.e., a cryptainer, served by the storage system, whereas the iSCSI name of the client is an iSCSI initiator name of the network entity, i.e., the client, which initiates the data access request to access data stored on the cryptainer.