Storage Access Control via Automatic Path Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage systems require manual and error-prone configuration of storage access control at the per-path level, which is tedious and prone to data unavailability due to changes in SAN connectivity, such as hardware replacements or additions/removals of target ports.

Innovation Solution

Implementing a method to configure storage access control at the initiator or host level of granularity, allowing automatic definition and updating of allowable paths using wildcard indicators to encompass all target ports, eliminating the need for explicit path specification and enabling dynamic adaptation to changes in the data storage system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual configuration of storage access control at per-path level is implemented, then access control precision is improved, but configuration complexity and error probability increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidconfiguration complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system automatically discovers SAN connectivity and generates access control configurations without manual intervention. The storage system self-identifies initiators, target ports, and paths, then automatically creates the appropriate access control rules, eliminating the need for administrators to manually configure each path while maintaining precise control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary automatic configuration of access control rules before actual data access operations begin. By pre-discovering the SAN topology and pre-generating access control configurations, the system eliminates the need for manual per-path configuration while ensuring precise access control from the outset.

Inventive Principle:
Principle #10Preliminary action

2Manufacturing precision

If manual configuration of storage access control is implemented, then access control precision is improved, but time consumption and administrative effort increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The storage system automatically performs service discovery and generates access control configurations without administrator intervention. The system self-identifies initiators, target ports, and available paths, then automatically creates access control rules, reducing configuration time from hours of manual work to automatic generation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors SAN connectivity changes and automatically updates access control configurations in response. When changes are detected in the SAN topology (such as new initiators, target ports, or paths), the system automatically adjusts access control rules to maintain precision while requiring no additional administrative time.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If explicit path specification is required, then access control precision is improved, but adaptability to infrastructure changes deteriorates

Engineering Contradiction:
Improveaccess control precisionVSAvoidadaptability to changes
Core Design Contradiction:
Manufacturing precisionVSAdaptability or versatility

Solution Approach 1:

The system continuously monitors SAN connectivity and automatically detects changes in initiators, target ports, and paths. When changes are detected, the system automatically updates access control configurations to include new paths or adjust existing ones, maintaining precise access control while adapting to infrastructure changes without manual reconfiguration.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access control configuration is made dynamic rather than static. The system automatically discovers and adapts to changes in SAN topology, dynamically generating and updating access control rules to reflect current connectivity. This allows the system to maintain precise access control while being highly adaptable to infrastructure changes such as hardware replacements or topology modifications.

Inventive Principle:
Principle #15Dynamics

4Manufacturing precision

If per-path access control configuration is implemented, then access control precision is improved, but system resilience to connectivity changes deteriorates

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem resilience
Core Design Contradiction:
Manufacturing precisionVSReliability

Solution Approach 1:

The system continuously monitors SAN connectivity and automatically detects changes. When connectivity changes occur (such as new paths becoming available or existing paths failing), the system automatically updates access control configurations to maintain data availability. This feedback mechanism ensures both precise access control and high resilience to connectivity changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access control system is made dynamic to automatically adapt to connectivity changes. Rather than requiring manual reconfiguration when SAN topology changes, the system dynamically discovers new paths and automatically updates access control rules to maintain data availability, thereby improving resilience while maintaining precision.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9054945B1Configuring storage access control
Publication Date: 2015.06.09 EMC IP HLDG CO LLC
  • US9054945B1 patent drawing
  • US9054945B1 patent drawing
  • US9054945B1 patent drawing

AI summary

Described are techniques for configuring storage access control. A set of inputs including a first identifier of an initiator port and a device set devices in a data storage system is received. Responsive to receiving the set of inputs, an allowable path set is automatically defined for the initiator in accordance with an initiator-level of granularity. Each device in the device set is accessible by the initiator over each path in the allowable path set. The allowable path set includes paths between the initiator port and each target port of the data storage system. A set of target ports is either specified using a wildcard indicator denoting all target ports of the data storage system, or the set of target ports is otherwise determined implicitly as all target ports of the data storage system.