Storage System Peer Zoning via Login Pattern Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Storage Area Networks (SANs), existing configurations for host access to storage arrays are cumbersome and insecure, particularly when multiple fabrics connect hosts to storage systems, leading to unauthorized access due to forgotten zones and improper zone configurations.

Innovation Solution

A method where the storage system autonomously manages access permissions by receiving configuration information, sending access requests to switches, and revoking permissions if a host fails to follow a predefined login pattern, ensuring secure and automatic zone configuration across multiple switches and fabrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual zoning configuration is performed by system administrators, then access permissions can be configured, but the configuration becomes cumbersome and insecure due to human error and forgotten zones

Engineering Contradiction:
Improveaccess permission securityVSAvoidzoning configuration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The storage system autonomously performs zoning configuration by receiving LUN mapping information and automatically generating peer zone configurations in Fibre Channel switches, eliminating the need for manual administrator configuration and reducing human error

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system monitors login patterns of host computer ports and uses this feedback to dynamically revoke access permissions when abnormal patterns are detected, continuously maintaining security without manual intervention

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If access permissions are granted to multiple host ports, then host access to storage is enabled, but unauthorized access may occur if hosts do not follow proper login patterns

Engineering Contradiction:
Improvehost access flexibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The storage system continuously monitors login/logout patterns of host computer ports and compares them against expected patterns, using this feedback to detect and revoke unauthorized access in real-time

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Access permissions are dynamically adjusted based on observed login patterns, allowing legitimate hosts to access storage while automatically revoking permissions from hosts that exhibit unauthorized access behavior

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If automatic peer zone configuration is implemented, then zoning management is simplified, but security may be compromised without monitoring login patterns

Engineering Contradiction:
Improvezoning configuration automationVSAvoidaccess permission security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system combines automatic zone configuration with continuous monitoring of login patterns, using feedback from login events to dynamically revoke permissions when unauthorized access is detected, maintaining both automation and security

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9811358B2Securing peer zoning
Publication Date: 2017.11.07 INFINIDAT LTD
  • US9811358B2 patent drawing
  • US9811358B2 patent drawing
  • US9811358B2 patent drawing

AI summary

A method that may include receiving, by a storage system, storage system configuration information that is indicative of access permissions of multiple host computer ports to storage logical units that are associated with a certain set of storage system ports; sending, by the storage system, in response to the storage system configuration information and to at least a first switch of a group of switches that is coupled to the storage system, access permission requests for allowing the multiple host computer ports to access the certain set of storage system ports; determining, by the storage system, to revoke an access permission from a certain host computer port of the multiple host computer hosts, when the certain host computer port failed to follow a predefined login pattern; and sending, by the storage system and to at least a second switch of the group of switches, a request to revoke the access permission of the certain host computer port.