iSNS Server Automates iSCSI Credential Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The iSCSI protocol is vulnerable to attacks due to static authentication secrets, which do not meet government regulations requiring regular key changes, leading to significant manual effort and potential downtime.

Innovation Solution

An Internet Storage Name Service (iSNS) server sends notifications to iSCSI target devices to update login credentials, ensuring both client and target devices have synchronized, regularly updated credentials, addressing the vulnerability by automating the process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static authentication secrets are used in iSCSI protocol, then authentication simplicity is maintained, but security compliance and vulnerability resistance deteriorate

Engineering Contradiction:
Improvesecurity complianceVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service through automated credential distribution and updating. The iSCSI target device automatically receives updated authentication secrets from the iSNS server and propagates them to client devices, eliminating the need for manual administrative intervention in credential management while maintaining security compliance

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback mechanisms where the iSCSI target device monitors for credential updates from the iSNS server and automatically triggers propagation to client devices. This closed-loop feedback system ensures credentials are updated systematically without manual intervention, resolving the contradiction between security compliance and management complexity

Inventive Principle:
Principle #23Feedback

2Reliability

If manual credential updates are performed, then security compliance can be achieved, but operational downtime and effort increase

Engineering Contradiction:
Improveauthentication securityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-establishing the automated update propagation mechanism before credential changes are needed. The iSCSI target device is pre-configured to automatically receive updates from the iSNS server and propagate them to clients, so when security updates are required, the process executes immediately without manual intervention or operational downtime

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuity of useful action by maintaining persistent automated update propagation between the iSCSI target device and client devices. The system continuously monitors for credential updates and automatically propagates them, ensuring uninterrupted authentication security compliance without operational downtime

Inventive Principle:
Principle #20Continuity of useful action

3Device complexity

If static credentials are used, then system simplicity is maintained, but vulnerability to attacks increases

Engineering Contradiction:
Improvecredential management simplicityVSAvoidattack vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the static credential system into a dynamic one where authentication secrets automatically update. The iSCSI target device dynamically receives updated credentials from the iSNS server and propagates them to client devices, ensuring the system adapts to security requirements without increasing operational complexity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The iSCSI target device serves as an intermediary between the iSNS server and client devices. It receives updated authentication secrets from the iSNS server and automatically propagates them to clients, simplifying the security update process while eliminating attack vulnerabilities associated with static credentials

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10461929B2Updating login credentials of an iSCSI client in a storage area network
Publication Date: 2019.10.29 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10461929B2 patent drawing
  • US10461929B2 patent drawing
  • US10461929B2 patent drawing

AI summary

Examples relate to updating login credentials of an iSCSI client in a Storage Area Network (SAN). In an example, an iSNS server may send a target notification to an iSCSI target device, the target notification including an instruction for the target device to update a target-side record of login credentials for an iSCSI client. iSNS server may receive a first target response message from iSCSI target device. In response, iSNS server may provide updated login credentials for the iSCSI client to the iSCSI target device. iSNS server may receive a second target response message. In response, iSNS server may send a client notification to iSCSI client to update a client-side record of login credentials. iSNS server may receive a first client response message. In response, iSNS server may provide the updated login credentials to the iSCSI client.