SAN Switch Exclusion List Automation for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional storage area network (SAN) systems lack effective access control capabilities, particularly in ongoing management and post-installation scenarios, requiring significant manual intervention and being inadequate during failures, which compromises security and efficiency.

Innovation Solution

A method involving a SAN switch that maintains a list of connected devices and automatically updates access permissions based on periodic queries, allowing for dynamic control of access and easy reconfiguration, including during failures, using a combination of primary and backup memory devices and user interfaces for exclusion list management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional SAN systems provide access control capability, then security is improved, but device complexity and manual intervention requirements increase

Engineering Contradiction:
Improveaccess control capabilityVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The SAN switch automatically performs access control by autonomously maintaining exclusion lists and querying devices to determine access permissions, eliminating the need for manual configuration and reducing system complexity while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures exclusion lists with device identifiers before access issues occur, and automatically applies these lists when devices connect to the SAN, preventing unauthorized access without requiring real-time manual intervention

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual access control configuration is implemented, then access security is improved, but time consumption and operator effort increase

Engineering Contradiction:
Improveaccess securityVSAvoidsetup and reconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The SAN switch automatically queries connected devices, retrieves their identifiers, and updates exclusion lists without human intervention, reducing setup and reconfiguration time while maintaining access security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously queries the SAN to detect new device connections and automatically updates access control lists based on current system state, enabling dynamic security management without manual reconfiguration

Inventive Principle:
Principle #23Feedback

3Reliability

If access control is implemented in conventional SAN systems, then security is improved, but capability to control access on ongoing basis after installation is limited

Engineering Contradiction:
Improveaccess control capabilityVSAvoidongoing access control flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The exclusion lists are dynamically updated based on current SAN device connections rather than being static pre-configurations, allowing the system to adapt access control to ongoing changes in the network environment

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The SAN switch continuously queries the network to detect device connection changes and automatically updates access control lists in real-time, providing ongoing flexibility to control access as devices are added or removed from the SAN

Inventive Principle:
Principle #23Feedback

4Device complexity

If conventional SAN systems lack access control capability, then device complexity is reduced, but security and confidentiality are compromised

Engineering Contradiction:
Improvesystem configuration simplicityVSAvoidsecurity and confidentiality
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The SAN switch autonomously maintains and enforces exclusion lists without requiring external access control hardware or software, providing security through the switch's built-in intelligence while keeping the overall system simple

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The SAN switch performs multiple functions including data switching, device identification, and access control enforcement through exclusion lists, eliminating the need for separate access control systems while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7917712B2Method and system for governing access to storage device on SAN
Publication Date: 2011.03.29 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7917712B2 patent drawing
  • US7917712B2 patent drawing
  • US7917712B2 patent drawing

AI summary

The present invention in at least some embodiments relates to improved methods and systems for governing access to SAN data storage devices (or simply “SAN devices”) employed in SAN systems. In some embodiments, the method involves storing a list at a SAN device. The list can be an exclusion list identifying devices that are not allowed to access the SAN device. During normal operation, the SAN device automatically contacts the SAN (or a component of the SAN, such as a SAN switch) to determine the identities of new devices that have entered into communication with the SAN. The SAN device then automatically updates the exclusion list to include those new devices such that, without further instructions, the SAN device is not accessible by those new devices. The method further can relate to the setup and failure recovery of SAN devices employed in SAN systems.