SAN Manager Mediates Security Tokens for Fabric-Attached Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In distributed storage-area networks (SANs), security is a challenge as data access occurs directly between client computing devices and storage drives without the involvement of a central SAN manager, making it difficult to centralize security like in non-distributed SANs, where a storage controller acts as a gatekeeper.
Innovation Solution
The solution involves storage drives creating and managing security tokens for drive volumes, which are then sent to a SAN manager and subsequently to client computing devices, allowing secure access to logical volumes by ensuring only authorized access is permitted through the use of access security tokens or administrator security tokens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If storage drives directly connect to fabric for distributed access, then access speed and decentralization are improved, but security control deteriorates
Solution Approach 1:
The patent introduces SAN manager as an intermediary component that mediates between client computing devices and storage drives. The SAN manager receives security tokens from storage drives and distributes them to authorized clients, providing centralized security control without interfering with the direct fabric connections that enable high-speed data access.
Solution Approach 2:
The patent segments the security control function from the data access path. Security tokens are separated into distinct administrative and access tokens, allowing security management to be handled independently through the SAN manager while data operations proceed directly through fabric connections between clients and storage drives.
2Ease of operation
If security tokens are centralized in SAN manager, then security management is simplified, but access efficiency deteriorates
Solution Approach 1:
The patent implements preliminary action by having storage drives create and issue security tokens in advance, before actual data access operations begin. The SAN manager distributes these pre-created tokens to client devices, so that when data access is needed, the tokens are already available and no additional security verification delays the actual data operations.
Solution Approach 2:
The patent uses copying by creating multiple instances of security tokens that can be distributed to multiple client devices simultaneously. The SAN manager can copy and distribute the same security token or different tokens to various clients, enabling efficient multi-client access without requiring each client to obtain tokens sequentially from the storage drive.
3Adaptability or versatility
If administrator tokens are used for direct access, then access flexibility is improved, but security vulnerability increases
Solution Approach 1:
The patent applies local quality by creating different types of security tokens with different properties for different purposes. Administrator security tokens are designed with specific properties for provisioning and mounting operations, while access security tokens have different properties for actual data access. This differentiation ensures that even if one token type is compromised, the other remains secure.
Solution Approach 2:
The patent implements preliminary anti-action by having the SAN manager validate and control the distribution of administrator tokens before they can be used for any operations. The SAN manager verifies the authenticity and appropriateness of administrator tokens before allowing them to be used for provisioning drive volumes or mounting logical volumes, preventing unauthorized or malicious use.
Data Source
AI summary
A storage-area network (SAN) system includes one or more storage drives directly connected to a fabric. Each storage drive provisions and operates a drive volume, and creates a security token for the drive volume. The system includes a client computing device directly connected to the fabric, and that executes a SAN software agent to create, mount, and use a logical volume realized by drive volumes of the storage drives. The client computing device accesses each drive volume using the security token for the drive volume. The system includes a SAN manager directly connected to the fabric that manages the drive volumes of the storage drives, manages the logical volume that the SAN software agent operates, receives from each storage drive the security token for the drive volume of the storage drive, and sends the security token for the drive volume of each storage drive to the SAN software agent.


