Trusted Disk Group Selection via IHS Trust Ranking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In data center environments, administrators face challenges in identifying and selecting the most suitable external disk groups for addition to storage systems, especially when no disk groups are available within the local cluster, and there is a need to ensure the trustworthiness of external disk groups to prevent system compromise.
Innovation Solution
The system detects requests for additional disk groups, identifies and classifies external Information Handling Systems (IHSs) based on trust parameters such as BIOS settings, TPM usage, and network devices, ranks them, and selects the top-ranked disk group for use, utilizing remote access controllers for trust parameter collection and management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If external disk groups are added to expand storage capacity, then storage capacity is improved, but system security and reliability deteriorate due to unknown trustworthiness of external IHSs
Solution Approach 1:
The system performs preliminary trust assessments on external IHSs before allowing disk group integration. Trust parameters including BIOS settings, TPM status, and network device configurations are evaluated in advance, and only IHSs meeting predetermined trust thresholds are permitted to contribute disk groups to the distributed storage system, thus preventing security compromises while enabling capacity expansion
Solution Approach 2:
A trust assessment mechanism acts as an intermediary between external IHSs and the distributed storage system. This intermediary evaluates trust parameters of external IHSs and determines whether they meet security requirements before allowing integration, thereby mediating between the need for expanded storage capacity and the requirement for system security
2Reliability
If administrators manually evaluate external IHSs for disk group selection, then security control is improved, but time consumption and operational complexity worsen
Solution Approach 1:
The system implements automated self-service trust assessment functionality that independently evaluates external IHSs based on predefined trust parameters. The distributed storage system automatically collects trust information, assesses external IHSs, and integrates qualified disk groups without requiring manual administrator intervention for each evaluation, thereby maintaining security control while eliminating time-consuming manual processes
Solution Approach 2:
The system establishes feedback mechanisms where trust parameters of external IHSs are automatically collected, assessed, and used to determine integration eligibility. This automated feedback loop provides continuous security evaluation without manual intervention, reducing time consumption while maintaining reliable security control through systematic assessment of trust criteria
3Reliability
If comprehensive trust parameters are evaluated for external IHSs, then system security is improved, but assessment complexity and resource requirements worsen
Solution Approach 1:
The trust assessment process is segmented into distinct evaluation components focusing on specific trust parameters such as BIOS settings, TPM status, and network device configurations. Each parameter is assessed independently through dedicated evaluation routines, allowing comprehensive security assessment to be broken down into manageable segments that can be processed systematically without overwhelming complexity
Solution Approach 2:
The assessment system applies different evaluation criteria and thresholds tailored to specific trust parameters rather than using a uniform assessment approach. Each trust parameter (BIOS, TPM, network devices) has its own quality standards and evaluation methods, allowing the system to maintain high security requirements for each aspect while managing overall assessment complexity through localized evaluation strategies
Data Source
AI summary
In data storage systems, pooled storage resources may be organized into logical disk groups. Adding an additional disk group to such data storage systems requires identifying a suitable disk group from numerous candidates that may be available to the data storage system via a network. Embodiments identify IHSs (Information Handling Systems), such as rack-mounted servers installed within a data center, that include available disk groups. The servers with available disk groups are classified based on various trust parameters, such as their security settings and their hardware and software configurations. Based on the number of trust parameters with which the servers are classified, the servers are ranked, thus indicating their suitability for providing trusted disk groups to the storage system. Available disk groups from the top ranked server may be designated for use by the storage system.


