Storage System Peer Zoning via Login Pattern Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Storage Area Networks (SANs), existing configurations for host access to storage arrays are cumbersome and insecure, particularly when multiple fabrics connect hosts to storage systems, leading to unauthorized access due to forgotten zones and improper zone configurations.
Innovation Solution
A method where the storage system autonomously manages access permissions by receiving configuration information, sending access requests to switches, and revoking permissions if a host fails to follow a predefined login pattern, ensuring secure and automatic zone configuration across multiple switches and fabrics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual zoning configuration is performed by system administrators, then access permissions can be configured, but the configuration becomes cumbersome and insecure due to human error and forgotten zones
Solution Approach 1:
The storage system autonomously performs zoning configuration by receiving LUN mapping information and automatically generating peer zone configurations in Fibre Channel switches, eliminating the need for manual administrator configuration and reducing human error
Solution Approach 2:
The system monitors login patterns of host computer ports and uses this feedback to dynamically revoke access permissions when abnormal patterns are detected, continuously maintaining security without manual intervention
2Adaptability or versatility
If access permissions are granted to multiple host ports, then host access to storage is enabled, but unauthorized access may occur if hosts do not follow proper login patterns
Solution Approach 1:
The storage system continuously monitors login/logout patterns of host computer ports and compares them against expected patterns, using this feedback to detect and revoke unauthorized access in real-time
Solution Approach 2:
Access permissions are dynamically adjusted based on observed login patterns, allowing legitimate hosts to access storage while automatically revoking permissions from hosts that exhibit unauthorized access behavior
3Ease of operation
If automatic peer zone configuration is implemented, then zoning management is simplified, but security may be compromised without monitoring login patterns
Solution Approach 1:
The system combines automatic zone configuration with continuous monitoring of login patterns, using feedback from login events to dynamically revoke permissions when unauthorized access is detected, maintaining both automation and security
Data Source
AI summary
A method that may include receiving, by a storage system, storage system configuration information that is indicative of access permissions of multiple host computer ports to storage logical units that are associated with a certain set of storage system ports; sending, by the storage system, in response to the storage system configuration information and to at least a first switch of a group of switches that is coupled to the storage system, access permission requests for allowing the multiple host computer ports to access the certain set of storage system ports; determining, by the storage system, to revoke an access permission from a certain host computer port of the multiple host computer hosts, when the certain host computer port failed to follow a predefined login pattern; and sending, by the storage system and to at least a second switch of the group of switches, a request to revoke the access permission of the certain host computer port.


