SAN Management Station for Encrypted LUN Path Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data-at-rest encryption solutions in Storage Area Networks (SANs) face challenges with multipath I/O and encryption key management, leading to potential data corruption due to mismatched encryption policies and keys across different paths, especially when multiple hosts access the same storage unit.
Innovation Solution
A management station is introduced to identify and manage encryption devices in SANs, comparing encryption policies and keys across paths to ensure consistency, simplifying the setup of encrypted Logical Units (LUNs) and multipath I/O operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption capabilities are added to the SAN to secure data at rest, then data security is improved, but multipath I/O management becomes complicated and encryption key mismatches may occur
Solution Approach 1:
The patent introduces a management station as an intermediary component that mediates between multiple hosts and encryption devices in the SAN. This management station maintains a database of encryption keys and policies, and automatically manages key distribution and policy enforcement across multiple paths, eliminating the need for manual coordination of encryption settings across multipath I/O configurations.
Solution Approach 2:
The patent enforces homogeneous encryption policies across all paths to a LUN by requiring that the same encryption key and policy be applied consistently regardless of which path is used. The management station ensures that all HBAs and storage ports use identical encryption parameters, eliminating variability that causes key mismatches in multipath environments.
2Adaptability or versatility
If multiple hosts are allowed to access the same storage unit and LUN, then resource sharing is improved, but encryption policy mismatches and data corruption risks increase
Solution Approach 1:
The patent creates a universal encryption management system that serves multiple hosts simultaneously. The management station acts as a central authority that provides encryption services to all hosts accessing the same LUN, ensuring that regardless of which host accesses the storage, the same encryption policies and keys are applied, enabling secure multi-host access.
Solution Approach 2:
The patent implements a feedback mechanism where the management station monitors and tracks encryption key usage and policy application across all hosts and paths. The system maintains a database that records which keys are assigned to which LUNs and verifies that the correct keys are being used, providing continuous feedback to ensure encryption consistency across multiple hosts.
3Reliability
If manual coordination of encryption keys across multiple paths is attempted, then encryption security is maintained, but setup time and administrative overhead increase significantly
Solution Approach 1:
The patent implements self-service automation where the management station automatically performs key generation, distribution, and policy enforcement without requiring manual coordination. When a LUN is created or existing LUNs are assigned to multiple paths, the system automatically ensures that the appropriate encryption keys and policies are applied consistently across all paths, eliminating time-consuming manual configuration.
Data Source
AI summary
A management station which manages the encryption devices in a SAN to set up encrypted LUNs. In setting up the encryption, the source and target ports are identified, along with the target LUN. LUN serial numbers used to identify unique LUNs. As paths to a given LUN are defined, the management station compares the path to existing paths and provides an indication if there is a mismatch in the encryption policies or keys being applied to the LUN over the various paths. This allows the administrator to readily identify when there is a problem with the paths to an encrypted LUN and then take steps to cure the problem. By determining the paths and then comparing them, the management station greatly simplifies setting up multipath I/O to an encrypted LUN or access by multiple hosts to an encrypted LUN.


