Secured Switch Dynamic ACL Management for iSCSI SAN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Internet Small Computer System Interface (iSCSI) storage area networks face challenges in securing data transfers and managing access control lists (ACLs) automatically, leading to potential security breaches and inefficiencies in managing changing network conditions without manual intervention.

Innovation Solution

Implementing secured switches within the iSCSI storage area networks that automatically modify access control lists based on log-in and log-out events of servers, and utilizing Internet Storage Name Service (iSNS) switches to manage ACLs dynamically, ensuring only authorized frame traffic is permitted and unauthorized traffic is dropped, without requiring continuous system administrator intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual management of access control lists is used in iSCSI storage area networks, then system administrators have full control over security policies, but continuous manual intervention is required leading to inefficiency and potential security breaches

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The secured switch automatically monitors iSCSI session events (log-in/log-out) and modifies ACLs without human intervention. The system self-manages security policies by detecting session changes and updating access control lists accordingly, eliminating the need for continuous administrator involvement while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback mechanism where the secured switch continuously monitors network session status and automatically adjusts ACLs based on detected log-in and log-out events. This closed-loop approach ensures ACLs remain synchronized with actual network conditions, improving both security and efficiency

Inventive Principle:
Principle #23Feedback

2Reliability

If access control lists are not automatically updated, then system configuration remains stable, but security breaches occur due to unauthorized traffic from servers that log out or log in dynamically

Engineering Contradiction:
Improveaccess control securityVSAvoidresponse to changing network conditions
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The ACLs transition from static to dynamic configuration. The secured switch automatically detects session changes and updates ACLs in real-time, allowing the access control policy to adapt dynamically to network conditions. This ensures authorized servers maintain access while automatically revoking access for logged-out servers

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system proactively updates ACLs before security breaches can occur. By monitoring session events and preemptively modifying access control lists when servers log in or log out, the system prevents unauthorized access attempts before they can compromise network security

Inventive Principle:
Principle #10Preliminary action

3Productivity

If secured switches automatically modify ACLs based on session events, then network security is enhanced and management efficiency improves, but switch complexity increases

Engineering Contradiction:
Improvenetwork management efficiencyVSAvoidswitch functionality
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The secured switch integrates multiple functions into a single device: it acts as both a network switch and an automated ACL management system. By combining session monitoring, event detection, and automatic ACL modification capabilities within the switch itself, the system eliminates the need for separate management systems while improving efficiency

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9575926B2System and method for optimizing secured internet small computer system interface storage area networks
Publication Date: 2017.02.21 DELL PROD LP
  • US9575926B2 patent drawing
  • US9575926B2 patent drawing
  • US9575926B2 patent drawing

AI summary

A network device includes a port coupled to a device, another port coupled to another device, and an access control list with an access control entry that causes the network device to permit log in frames to be forwarded from the first device to the second device. The network device receives a frame addressed to the second device and determines the frame type. If the frame type is a log in frame, then the frame is forwarded to the second device and another access control entry is added to the access control list. The second access control entry causes the network device to permit data frames to be forwarded from the first device to the second device. If not, then the frame is dropped based upon the first access control entry.