Virtual Machine SAN Access Validation via Switch Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing access of virtual machines to storage area networks (SANs) is challenging when they need to be flexibly deployed and moved across physical servers or cloud nodes, as ensuring consistent access to storage resources with unique port names is complex due to zoning and LUN masking restrictions.
Innovation Solution
A method and system that utilize switches to validate access by sending port names and logical unit names as part of a validate access command, ensuring that virtual machines can access target ports and logical units, returning success or fail information to maintain access consistency across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtual machines are flexibly deployed and moved across physical servers to improve adaptability, then adaptability is improved, but ensuring consistent access to storage resources becomes more complex due to zoning and LUN masking restrictions
Solution Approach 1:
The patent introduces a validation mechanism that acts as an intermediary between virtual machines and storage resources. Before allowing access, the system validates whether the virtual machine's port names have proper access rights to the target storage ports and logical units through zoning and LUN masking configurations. This intermediary validation step simplifies access management by providing a clear yes/no determination rather than requiring complex manual configuration tracking.
Solution Approach 2:
The patent performs access validation in advance before the virtual machine actually accesses storage resources. By pre-validating port name associations with target ports and logical units, the system ensures that when virtual machines are moved or deployed, their storage access rights are already confirmed, preventing access issues before they occur and simplifying deployment procedures.
2Reliability
If strict zoning and LUN masking restrictions are enforced to maintain security and access control, then reliability is improved, but flexibility in deploying and moving virtual machines deteriorates
Solution Approach 1:
The patent implements a feedback mechanism where the system validates and confirms whether virtual machine port names have proper access rights to storage resources before allowing connections. This feedback loop provides explicit confirmation of access validity, allowing the system to maintain strict zoning and LUN masking controls while enabling virtual machine mobility - if validation succeeds, the VM can move; if it fails, access is blocked. This resolves the contradiction by providing clear guidance on when mobility is permitted under security constraints.
3Ease of operation
If port names are assigned to virtual machines for storage access, then ease of operation is improved, but ensuring consistent access across multiple nodes becomes more difficult
Solution Approach 1:
The patent enables the system to automatically validate and verify port name associations with storage resources across multiple nodes without requiring manual intervention. The validation mechanism self-checks whether virtual machine port names have proper access rights to target ports and logical units, ensuring consistent access behavior across the distributed environment while maintaining operational simplicity for users.
Data Source
AI summary
A method for managing access of virtual machines executed by a host computer system to storage area networks, the storage area networks connecting the host computer system with storage systems via switches, where the host computer system includes one or more host ports to connect with a switch each, and where one or more port names are assigned to each virtual machine. The method includes, for each storage area network connected with the host computer system, sending the port names of a virtual machine and a target port name as part of a validate access command to the respective switch; and when receiving the validate access command by the switch, the switch returning success information to the sending host computer system in case all received virtual machine port names have access to a target port assigned to the received target port name, otherwise returning a fail information.


