SES Device Server Authorization for SCSI Initiator Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SCSI Enclosure Services (SES) systems lack methods for prioritizing and securing commands from different SCSI initiators, leading to potential system instability and vulnerabilities to malicious initiators that can cause overheating or power loss.

Innovation Solution

Implementing an SES device server with a frontend interface to receive and process SES commands, a control unit to determine authorized initiators, and a backend interface to manage peripheral devices, ensuring only authorized commands are executed and unauthorized commands are rejected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SES device servers process all received SES commands without authorization checks, then command processing simplicity is maintained, but system security and stability deteriorate due to potential malicious or conflicting commands

Engineering Contradiction:
Improvecommand processing simplicityVSAvoidsystem stability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authorization checks before command execution. The SES device server maintains an authorized initiator list and performs verification prior to processing any SES command, preventing malicious or unauthorized commands from affecting system stability while maintaining straightforward command processing for authorized initiators

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If SES device servers process all received SES commands without prioritization, then command processing simplicity is maintained, but system security deteriorates due to inability to prevent malicious initiator interference

Engineering Contradiction:
Improvecommand processing simplicityVSAvoidmalicious initiator interference
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authorization checks before command execution. The SES device server maintains an authorized initiator list and performs verification prior to processing any SES command, preventing malicious or unauthorized commands from affecting system stability while maintaining straightforward command processing for authorized initiators

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If no authorization tracking is implemented, then device complexity is reduced, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveauthorization mechanism complexityVSAvoidaccess security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces an intermediary authorization tracking mechanism between the SES initiator and the command execution. The SES device server maintains an authorized initiator list that acts as a mediator, verifying each initiator's identity before allowing command processing, thus securing access without requiring complex authorization infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8898772B2Methods and structure for implementing security in systems that utilize small computer system interface enclosure services
Publication Date: 2014.11.25 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8898772B2 patent drawing
  • US8898772B2 patent drawing
  • US8898772B2 patent drawing

AI summary

Methods and structure are provided for implementing security features in SCSI Enclosure Services (SES) systems. The system comprises an SES device server, which includes a frontend interface, control unit, and backend interface. The frontend interface is operable to receive SES commands generated by Small Computer System Interface (SCSI) devices, and the backend interface is operable to manage operations of at least one peripheral device communicatively coupled with the SES device server based on received SES commands. The control unit is operable to determine whether a SCSI initiator that generated an SES command is an authorized device. The control unit is further operable to perform the SES command in response to determining that the SCSI initiator is an authorized device, and is further operable to reject the SES command in response to determining that the SCSI initiator is not an authorized device.