SAN Management Station for Encrypted LUN Path Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data-at-rest encryption solutions in Storage Area Networks (SANs) face challenges with multipath I/O and encryption key management, leading to potential data corruption due to mismatched encryption policies and keys across different paths, especially when multiple hosts access the same storage unit.

Innovation Solution

A management station is introduced to identify and manage encryption devices in SANs, comparing encryption policies and keys across paths to ensure consistency, simplifying the setup of encrypted Logical Units (LUNs) and multipath I/O operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption capabilities are added to the SAN to secure data at rest, then data security is improved, but multipath I/O management becomes complicated and encryption key mismatches may occur

Engineering Contradiction:
Improvedata securityVSAvoidmultipath I/O management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a management station as an intermediary component that mediates between multiple hosts and encryption devices in the SAN. This management station maintains a database of encryption keys and policies, and automatically manages key distribution and policy enforcement across multiple paths, eliminating the need for manual coordination of encryption settings across multipath I/O configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enforces homogeneous encryption policies across all paths to a LUN by requiring that the same encryption key and policy be applied consistently regardless of which path is used. The management station ensures that all HBAs and storage ports use identical encryption parameters, eliminating variability that causes key mismatches in multipath environments.

Inventive Principle:
Principle #33Homogeneity

2Adaptability or versatility

If multiple hosts are allowed to access the same storage unit and LUN, then resource sharing is improved, but encryption policy mismatches and data corruption risks increase

Engineering Contradiction:
Improveresource sharingVSAvoidencryption consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a universal encryption management system that serves multiple hosts simultaneously. The management station acts as a central authority that provides encryption services to all hosts accessing the same LUN, ensuring that regardless of which host accesses the storage, the same encryption policies and keys are applied, enabling secure multi-host access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements a feedback mechanism where the management station monitors and tracks encryption key usage and policy application across all hosts and paths. The system maintains a database that records which keys are assigned to which LUNs and verifies that the correct keys are being used, providing continuous feedback to ensure encryption consistency across multiple hosts.

Inventive Principle:
Principle #23Feedback

3Reliability

If manual coordination of encryption keys across multiple paths is attempted, then encryption security is maintained, but setup time and administrative overhead increase significantly

Engineering Contradiction:
Improveencryption securityVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service automation where the management station automatically performs key generation, distribution, and policy enforcement without requiring manual coordination. When a LUN is created or existing LUNs are assigned to multiple paths, the system automatically ensures that the appropriate encryption keys and policies are applied consistently across all paths, eliminating time-consuming manual configuration.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9491040B2Determination and display of LUN encryption paths
Publication Date: 2016.11.08 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US9491040B2 patent drawing
  • US9491040B2 patent drawing
  • US9491040B2 patent drawing

AI summary

A management station which manages the encryption devices in a SAN to set up encrypted LUNs. In setting up the encryption, the source and target ports are identified, along with the target LUN. LUN serial numbers used to identify unique LUNs. As paths to a given LUN are defined, the management station compares the path to existing paths and provides an indication if there is a mismatch in the encryption policies or keys being applied to the LUN over the various paths. This allows the administrator to readily identify when there is a problem with the paths to an encrypted LUN and then take steps to cure the problem. By determining the paths and then comparing them, the management station greatly simplifies setting up multipath I/O to an encrypted LUN or access by multiple hosts to an encrypted LUN.