SAN Manager Mediates Security Tokens for Fabric-Attached Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed storage-area networks (SANs), security is a challenge as data access occurs directly between client computing devices and storage drives without the involvement of a central SAN manager, making it difficult to centralize security like in non-distributed SANs, where a storage controller acts as a gatekeeper.

Innovation Solution

The solution involves storage drives creating and managing security tokens for drive volumes, which are then sent to a SAN manager and subsequently to client computing devices, allowing secure access to logical volumes by ensuring only authorized access is permitted through the use of access security tokens or administrator security tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If storage drives directly connect to fabric for distributed access, then access speed and decentralization are improved, but security control deteriorates

Engineering Contradiction:
Improvedata access speedVSAvoidsecurity control
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces SAN manager as an intermediary component that mediates between client computing devices and storage drives. The SAN manager receives security tokens from storage drives and distributes them to authorized clients, providing centralized security control without interfering with the direct fabric connections that enable high-speed data access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security control function from the data access path. Security tokens are separated into distinct administrative and access tokens, allowing security management to be handled independently through the SAN manager while data operations proceed directly through fabric connections between clients and storage drives.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If security tokens are centralized in SAN manager, then security management is simplified, but access efficiency deteriorates

Engineering Contradiction:
Improvesecurity managementVSAvoidaccess efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements preliminary action by having storage drives create and issue security tokens in advance, before actual data access operations begin. The SAN manager distributes these pre-created tokens to client devices, so that when data access is needed, the tokens are already available and no additional security verification delays the actual data operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating multiple instances of security tokens that can be distributed to multiple client devices simultaneously. The SAN manager can copy and distribute the same security token or different tokens to various clients, enabling efficient multi-client access without requiring each client to obtain tokens sequentially from the storage drive.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If administrator tokens are used for direct access, then access flexibility is improved, but security vulnerability increases

Engineering Contradiction:
Improveaccess flexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by creating different types of security tokens with different properties for different purposes. Administrator security tokens are designed with specific properties for provisioning and mounting operations, while access security tokens have different properties for actual data access. This differentiation ensures that even if one token type is compromised, the other remains secure.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary anti-action by having the SAN manager validate and control the distribution of administrator tokens before they can be used for any operations. The SAN manager verifies the authenticity and appropriateness of administrator tokens before allowing them to be used for provisioning drive volumes or mounting logical volumes, preventing unauthorized or malicious use.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10296247B2Security within storage area network having fabric-attached storage drives, SAN agent-executing client devices, and SAN manager
Publication Date: 2019.05.21 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US10296247B2 patent drawing
  • US10296247B2 patent drawing
  • US10296247B2 patent drawing

AI summary

A storage-area network (SAN) system includes one or more storage drives directly connected to a fabric. Each storage drive provisions and operates a drive volume, and creates a security token for the drive volume. The system includes a client computing device directly connected to the fabric, and that executes a SAN software agent to create, mount, and use a logical volume realized by drive volumes of the storage drives. The client computing device accesses each drive volume using the security token for the drive volume. The system includes a SAN manager directly connected to the fabric that manages the drive volumes of the storage drives, manages the logical volume that the SAN software agent operates, receives from each storage drive the security token for the drive volume of the storage drive, and sends the security token for the drive volume of each storage drive to the SAN software agent.