Unified Storage Object Model for Multi-User Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current monitoring and control tools for storage networks fail to provide adequate logical separation of storage entities, limiting client devices' access to resources and requiring separate management software for administrators and clients, which complicates independent management and monitoring.
Innovation Solution
A storage management computing device generates a storage object model that associates physical and logical storage entities, providing administrator-level and user authentication to access corresponding information, and a dashboard to display data based on authentication levels, enabling multi-level control and monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If separate management software is used for administrators and client devices, then independent management and monitoring is enabled, but device complexity and system complexity increase
Solution Approach 1:
The patent combines administrator-level and user-level management interfaces into a single unified management software platform. The system integrates multiple object models (administrator-level object model and user-level object model) within one application, allowing both administrators and clients to manage their respective storage entities through the same software interface rather than requiring separate applications.
Solution Approach 2:
The patent segments the unified management software into distinct operational layers through authentication mechanisms. When an administrator logs in, the system presents the administrator-level object model; when a client logs in, the system presents the user-level object model. This segmentation allows independent management capabilities for different user types while maintaining a unified software base.
2Device complexity
If unified management software is used for administrators and client devices, then device complexity is reduced, but logical separation of storage entities is insufficient
Solution Approach 1:
The patent creates distinct object models segmented by user type. The administrator-level object model includes all storage entities (physical and logical) for comprehensive management. The user-level object model contains only the subset of logical storage entities assigned to that specific client, ensuring proper logical separation and data security while using the same software platform.
Solution Approach 2:
The system applies local quality by customizing the information presentation based on user type. Each user receives a tailored view of storage entities appropriate to their role and permissions. Clients see only their assigned logical storage resources, while administrators see the complete picture including physical infrastructure, all within the unified software interface.
3Productivity
If client devices access physical storage entities directly, then access to resources is improved, but security and logical separation are compromised
Solution Approach 1:
The patent introduces the user-level object model as an intermediary layer between client devices and physical storage entities. Clients interact with their assigned logical storage entities through this intermediate model, which then maps to the underlying physical storage infrastructure. This intermediary approach enables efficient resource access while maintaining security boundaries and logical separation.
Solution Approach 2:
The system segments access rights by creating distinct user-level object models for each client, containing only the logical storage entities assigned to that client. This segmentation prevents clients from directly accessing or viewing physical storage entities or other clients' resources, thereby maintaining security and logical separation while allowing efficient access to authorized resources.
Data Source
AI summary
Data identifying server storage devices and logical storage entities is received. A storage object model based on the received data is generated. A first user type is associated with the server storage devices and logical storage entities. A second user type is associated with the logical storage entities. A first user is allowed to access data associated with the sever storage devices and the logical storage entities in response to determining that the first user is identified as the first user type. A second user is allowed to access data associated with the logical storage entities and not allowed to access data associated with the server storage devices in response to determining that the second user is identified as the second user type.


