iSNS Server Automates iSCSI Credential Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The iSCSI protocol is vulnerable to attacks due to static authentication secrets, which do not meet government regulations requiring regular key changes, leading to significant manual effort and potential downtime.
Innovation Solution
An Internet Storage Name Service (iSNS) server sends notifications to iSCSI target devices to update login credentials, ensuring both client and target devices have synchronized, regularly updated credentials, addressing the vulnerability by automating the process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static authentication secrets are used in iSCSI protocol, then authentication simplicity is maintained, but security compliance and vulnerability resistance deteriorate
Solution Approach 1:
The system enables self-service through automated credential distribution and updating. The iSCSI target device automatically receives updated authentication secrets from the iSNS server and propagates them to client devices, eliminating the need for manual administrative intervention in credential management while maintaining security compliance
Solution Approach 2:
The patent implements feedback mechanisms where the iSCSI target device monitors for credential updates from the iSNS server and automatically triggers propagation to client devices. This closed-loop feedback system ensures credentials are updated systematically without manual intervention, resolving the contradiction between security compliance and management complexity
2Reliability
If manual credential updates are performed, then security compliance can be achieved, but operational downtime and effort increase
Solution Approach 1:
The system performs preliminary actions by pre-establishing the automated update propagation mechanism before credential changes are needed. The iSCSI target device is pre-configured to automatically receive updates from the iSNS server and propagate them to clients, so when security updates are required, the process executes immediately without manual intervention or operational downtime
Solution Approach 2:
The patent ensures continuity of useful action by maintaining persistent automated update propagation between the iSCSI target device and client devices. The system continuously monitors for credential updates and automatically propagates them, ensuring uninterrupted authentication security compliance without operational downtime
3Device complexity
If static credentials are used, then system simplicity is maintained, but vulnerability to attacks increases
Solution Approach 1:
The patent transforms the static credential system into a dynamic one where authentication secrets automatically update. The iSCSI target device dynamically receives updated credentials from the iSNS server and propagates them to client devices, ensuring the system adapts to security requirements without increasing operational complexity
Solution Approach 2:
The iSCSI target device serves as an intermediary between the iSNS server and client devices. It receives updated authentication secrets from the iSNS server and automatically propagates them to clients, simplifying the security update process while eliminating attack vulnerabilities associated with static credentials
Data Source
AI summary
Examples relate to updating login credentials of an iSCSI client in a Storage Area Network (SAN). In an example, an iSNS server may send a target notification to an iSCSI target device, the target notification including an instruction for the target device to update a target-side record of login credentials for an iSCSI client. iSNS server may receive a first target response message from iSCSI target device. In response, iSNS server may provide updated login credentials for the iSCSI client to the iSCSI target device. iSNS server may receive a second target response message. In response, iSNS server may send a client notification to iSCSI client to update a client-side record of login credentials. iSNS server may receive a first client response message. In response, iSNS server may provide the updated login credentials to the iSCSI client.


