Storage Management Interface Access Via Dynamic Adapter Identity Lists

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage systems face challenges in securely managing access to management interfaces due to issues such as spoofing of host device identities, manual configuration complexities, and the need for frequent updates as host devices undergo changes, which can lead to vulnerabilities like ransomware attacks.

Innovation Solution

Implementing a system that uses network adapter information, including cryptographic identities, to create allow-lists and deny-lists for managing access to storage system management interfaces, with dynamic updates based on changes detected by management controllers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration of management interface access is used, then ease of operation is improved, but device complexity and vulnerability to spoofing increase

Engineering Contradiction:
Improveease of configurationVSAvoidaccess management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system automatically manages access control by having host devices present their network adapter information and cryptographic identities to the storage system. The storage system autonomously creates allow-lists and deny-lists based on the presented credentials, eliminating the need for manual configuration while reducing complexity through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary verification of network adapter information and cryptographic identities before allowing access to the management interface. By pre-establishing allow-lists and deny-lists based on authenticated identities, the system prevents spoofing attempts before they can succeed, improving security without requiring complex manual configurations.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If frequent updates of host device information are performed, then adaptability is improved, but loss of time and operational overhead increase

Engineering Contradiction:
Improveadaptability to host changesVSAvoidtime for updates
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system continuously monitors and receives feedback about changes in network adapter information and cryptographic identities from host devices. When changes are detected, the storage system automatically updates the allow-lists and deny-lists, enabling rapid adaptation to host device changes without requiring manual intervention or causing operational delays.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access control mechanism is dynamic rather than static. The system automatically adjusts access permissions in real-time based on the current state of host device identities and network adapter information, allowing the management interface access to adapt flexibly to changing conditions without time-consuming manual updates.

Inventive Principle:
Principle #15Dynamics

3Reliability

If network adapter information and cryptographic identities are verified, then security is improved, but device complexity and authentication overhead increase

Engineering Contradiction:
Improvesecurity against spoofingVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses network adapter information and cryptographic identities as intermediary elements to verify the authenticity of host devices. These intermediaries serve as trusted credentials that mediate between the host device and the storage system, enabling secure authentication without requiring complex manual verification processes or exposing the system to spoofing attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If allow-lists and deny-lists are automatically maintained, then productivity is improved, but loss of information about manual configuration requirements increases

Engineering Contradiction:
Improveaccess management efficiencyVSAvoidinformation about manual configuration needs
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system maintains access control lists autonomously by automatically verifying network adapter information and cryptographic identities. Host devices themselves provide the necessary information for inclusion in allow-lists or deny-lists, eliminating the need for manual configuration while preserving all necessary access control information through automated processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250240298A1Management interface access in storage systems
Publication Date: 2025.07.24 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20250240298A1 patent drawing
  • US20250240298A1 patent drawing
  • US20250240298A1 patent drawing

AI summary

Examples described herein relate to configuring access to management interface of a storage system. Examples may obtain network adapter information of the host devices coupled to the storage system using credentials of a management controller of the host devices. Examples may create an allow-list or deny-list containing the network adapter information of the host devices. Examples may allow or deny connections to the management interface from the host devices based on the allow-list or deny-list. Examples may allow dynamic updating of the allow-list and deny-list based on a change in a network adapter of the host device.