Storage Array Host Access Control via Compromise Likelihood Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems face challenges in detecting and preventing malicious access to storage arrays, particularly when a compromised host system can still access and potentially breach data, leading to theft, modification, or encryption of data.

Innovation Solution

An information handling system is configured to determine the likelihood of compromise for each host system and take remedial actions, such as restricting access to physical storage resources, by using a management controller to assess factors like unauthorized software, security vulnerabilities, and unusual traffic patterns, and enforcing access policies through a Multipath I/O driver.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the storage array allows broad host access for shared data operations, then data availability and system productivity are improved, but security vulnerability and risk of malicious access increase

Engineering Contradiction:
Improvedata availabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The storage array performs preliminary assessments of host systems before granting access. The array evaluator component evaluates hosts against security criteria and maintains an allowlist of approved hosts. This preliminary action prevents compromised hosts from accessing the storage array in the first place, resolving the contradiction by establishing security checks before data operations can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary evaluation mechanism between the host system and storage array. The array evaluator acts as a mediator that assesses host security posture and determines whether to permit access. This intermediary layer enables broad access for legitimate hosts while blocking malicious ones, thus maintaining productivity without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the storage array implements comprehensive security monitoring and host evaluation, then security reliability is improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security evaluation function is segmented into a separate array evaluator component distinct from the main storage array operations. This segmentation allows comprehensive security monitoring to be performed by a dedicated module without complicating the core storage functions. The evaluator maintains an allowlist and performs assessments independently, then communicates access decisions to the storage array, thus improving security reliability while managing system complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the storage array restricts access for compromised hosts, then data protection and integrity are improved, but loss of legitimate access and operational disruption occur

Engineering Contradiction:
Improvedata protectionVSAvoidoperational continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements feedback mechanisms where the array evaluator continuously monitors host systems and updates access permissions based on current security posture. When a host is compromised, the evaluator detects the change and revokes access permissions, preventing data theft while allowing legitimate hosts to maintain uninterrupted access. This feedback loop ensures data protection is improved without causing operational disruption for authorized users.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Access permissions are made dynamic rather than static. The storage array can adjust access rights in real-time based on the security evaluation of each host. Legitimate hosts enjoy continuous access (maintaining productivity), while compromised hosts have access dynamically revoked (improving data protection). This dynamic approach resolves the contradiction by making access control adaptive to current security conditions rather than fixed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11841940B2Preemptive protection against malicious array access
Publication Date: 2023.12.12 DELL PROD LP
  • US11841940B2 patent drawing

AI summary

An information handling system may include at least one processor; a plurality of physical storage resources; and a network interface configured to communicatively couple the information handling system to a plurality of host systems; wherein the information handling system is configured to: determine a likelihood of compromise for each of the plurality of host systems; and in response to the likelihood of compromise for a particular host system exceeding a threshold likelihood, carry out a remedial action with respect to the particular host system, wherein the remedial action includes restricting access from the particular host system to the plurality of physical storage resources.